Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.8 CVE-2026-40032 UAC (Unix-like Artifacts Collector) before 3.3.0-rc1 contains a command injection vulnerability in the placeholder substitution and command execution… Patch available Fix from $1,9502026-04-08 HIGH 7.3 CVE-2026-5802 A vulnerability was identified in idachev mcp-javadc up to 1.2.4. Impacted is an unknown function of the component HTTP Interface. Such manipulation … Mitigation only Fix from $1,9502026-04-08 HIGH 8.8 CVE-2026-39862 Tophat is a mobile applications testing harness. Prior to 2.5.1, Tophat is affected by remote code execution via crafted tophat:// or http://localhos… Tophat 2.5.1+ Fix from $1,9502026-04-08 HIGH 8.0 CVE-2026-30815 An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system c… Archer Ax53 Firmware 1.7.1+ Fix from $1,9502026-04-08 HIGH 8.0 CVE-2026-30818 An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrar… Archer Ax53 Firmware 1.7.1+ Fix from $1,9502026-04-08 HIGH 7.8 CVE-2026-27806 Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local u… Fleet 4.81.1+ Fix from $1,9502026-04-08 HIGH 7.2 CVE-2026-5208 Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary code as root via injected bash… Coolercontrold after 4.0.0 Fix from $1,9502026-04-08 HIGH 7.3 CVE-2026-5741 A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_… Mitigation only Fix from $1,9502026-04-07 CRITICAL 9.3 CVE-2026-39382 dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. Inside th… Patch available Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-4631EPSS 15% Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitizati… Mitigation only Fix from $2,3002026-04-07 HIGH 7.2 CVE-2026-35581 Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the Executrix utility class constructed shell commands by concatenating configu… Emissary after 8.38.0 Fix from $1,9502026-04-07 HIGH 7.2 CVE-2026-35585 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.0.0 u… Filebrowser after 2.63.1 Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-35517 FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL en… Ftldns after 6.5 Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-35518 FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL en… Ftldns after 6.5 Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-35519 FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL en… Ftldns after 6.5 Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-35520 FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL en… Ftldns after 6.5 Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-35521 FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL en… Ftldns after 6.5 Fix from $1,9502026-04-07 HIGH 8.0 CVE-2025-24817 Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in … Mantaray Nm 25r1-nm+ Fix from $1,9502026-04-07 HIGH 8.8 CVE-2026-35463 pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTIONS protection mechanism restri… Pyload Ng after 0.5.0b3.dev96 Fix from $1,9502026-04-07 CRITICAL 9.8 CVE-2021-4473EPSS 6% Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoint that allows unauthenticated… Tianxin Internet Behavior Management System 4.0.0.7_20210716.180815+ Fix from $2,3002026-04-07 HIGH 8.8 CVE-2026-34197 KEVEPSS 97% Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach… Activemq 5.19.4 / 6.2.3+ Fix from $1,9502026-04-07 HIGH 7.3 CVE-2026-5692 A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi. The m… Mitigation only Fix from $1,9502026-04-07 HIGH 7.3 CVE-2026-5691 A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setFirewallType of the file /cgi-bin/cstecgi.cgi. … Mitigation only Fix from $1,9502026-04-06 HIGH 7.3 CVE-2026-5690 A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi. E… Mitigation only Fix from $1,9502026-04-06 HIGH 7.3 CVE-2026-5689 A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setNtpCfg of the file /cgi-bin/cstecgi.cg… Mitigation only Fix from $1,9502026-04-06 HIGH 7.3 CVE-2026-5688 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setDdnsCfg of the file /cgi-bin/cstecgi… Mitigation only Fix from $1,9502026-04-06 HIGH 8.8 CVE-2026-5707 Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through … Research And Engineering Studio 2026.03+ Fix from $1,9502026-04-06 HIGH 8.8 CVE-2026-5709 Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authent… Research And Engineering Studio 2026.03+ Fix from $1,9502026-04-06 MEDIUM 5.5 CVE-2026-5679 A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /… Mitigation only Fix from $1,6002026-04-06 HIGH 7.3 CVE-2026-5677 A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi. P… Mitigation only Fix from $1,9502026-04-06