Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.9 CVE-2026-73294 Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controll… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.9 CVE-2026-73263 Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp au… No fix yet Fix from $5,7502026-08-12 HIGH 8.8 CVE-2026-11325 Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execu… No fix yet Fix from $4,9002026-08-12 CRITICAL 9.6 CVE-2026-5917 libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that all… No fix yet Fix from $5,7502026-08-11 HIGH 8.8 CVE-2026-14863 FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote cod… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-73224 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP … No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-73222 Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --stud… No fix yet Fix from $4,9002026-08-11 HIGH 8.7 CVE-2026-73081 Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline builds the on-disk path for a… No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-70335 Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unautho… Visual Studio Code 1.132.1+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-69320 Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to e… Visual Studio Code 1.132.1+ Fix from $4,9002026-08-11 HIGH 7.7 CVE-2026-48385 ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could resu… Coldfusion No fix yet Fix from $4,9002026-08-11 CRITICAL 10.0 CVE-2026-48362 ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could resu… Coldfusion No fix yet Fix from $5,7502026-08-11 HIGH 8.4 CVE-2026-73077 Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.v… No fix yet Fix from $4,9002026-08-11 HIGH 8.4 CVE-2026-67180 Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evide… No fix yet Fix from $4,9002026-08-11 HIGH 8.7 CVE-2026-72767 n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node. Authenticated users w… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.9 CVE-2026-72603 An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by inje… No fix yet Fix from $5,7502026-08-11 HIGH 8.8 CVE-2026-72556 A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission ch… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-72551 A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute arbitrary OS commands by exp… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-58236 SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal cod… No fix yet Fix from $4,0002026-08-11 HIGH 8.6 CVE-2025-30241 Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to sy… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.3 CVE-2026-72904 Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in … No fix yet Fix from $5,7502026-08-10 HIGH 8.7 CVE-2026-72884 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/utils/builders/compose.ts onl… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.9 CVE-2026-72901 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbi… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.9 CVE-2026-72902 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands o… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.6 CVE-2026-72877 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell com… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.6 CVE-2026-72878 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline constructs shell commands by d… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.4 CVE-2026-72879 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/clust… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.9 CVE-2026-72880 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/cer… No fix yet Fix from $5,7502026-08-10 MEDIUM 6.4 CVE-2026-72881 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders in packages/server/src/… No fix yet Fix from $4,0002026-08-10 CRITICAL 9.9 CVE-2026-72882 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for … No fix yet Fix from $5,7502026-08-10