Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2026-34797 Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi.… Firewall Community after 3.3.25 Fix from $1,9502026-04-02 HIGH 8.8 CVE-2026-34794 Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. … Firewall Community after 3.3.25 Fix from $1,9502026-04-02 HIGH 8.8 CVE-2026-34795 Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. … Firewall Community after 3.3.25 Fix from $1,9502026-04-02 HIGH 8.8 CVE-2026-34792 Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cg… Firewall Community after 3.3.25 Fix from $1,9502026-04-02 HIGH 8.8 CVE-2026-34793 Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.… Firewall Community after 3.3.25 Fix from $1,9502026-04-02 HIGH 8.8 CVE-2026-34791 Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi… Firewall Community after 3.3.25 Fix from $1,9502026-04-02 HIGH 7.8 CVE-2026-33641 Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which subst… Glances 4.5.3+ Fix from $1,9502026-04-02 HIGH 8.8 CVE-2026-3692 In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the repo… Flowmon 12.5.8+ Fix from $1,9502026-04-02 HIGH 8.8 CVE-2026-2701EPSS 57% Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. Sharefile Storage Zones Controller 5.12.4+ Fix from $1,9502026-04-02 HIGH 8.8 CVE-2026-33613 Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpAr… Mbconnect24 after 2.19.4 Fix from $1,9502026-04-02 HIGH 7.3 CVE-2026-1345 IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces… Security Verify Access after 11.0.2.0 Fix from $1,9502026-04-01 MEDIUM 6.8 CVE-2026-24154 NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments. A … Jetson Linux 35.6.4 / 36.5+ Fix from $1,6002026-03-31 CRITICAL 9.8 CVE-2026-34243 wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Action… Wenxian after 0.3.1 Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-30312 DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism comple… Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-30314 Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism compl… Auto Approval Module after 0.1.1 Fix from $2,3002026-03-31 HIGH 7.8 CVE-2026-30309 InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist security mechanism completely… Infcode after 1.3.1 Fix from $1,9502026-03-31 CRITICAL 9.8 CVE-2026-30311 Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism compl… Auto Approval Module after 0.1.1 Fix from $2,3002026-03-31 HIGH 7.8 CVE-2026-0596 A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into… Mlflow No fix yet Fix from $1,9502026-03-31 CRITICAL 9.8 CVE-2026-32917 OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute … Openclaw 2026.3.13+ Fix from $2,3002026-03-31 HIGH 8.3 CVE-2025-14213 Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attacker with access to the Socket … Mitigation only Fix from $1,9502026-03-31 CRITICAL 9.8 CVE-2026-30880 baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue … Basercms 5.2.3+ Fix from $2,3002026-03-31 HIGH 7.2 CVE-2026-21861 baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update funct… Basercms 5.2.3+ Fix from $1,9502026-03-31 HIGH 7.2 CVE-2026-30877 baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due … Basercms 5.2.3+ Fix from $1,9502026-03-31 HIGH 8.6 CVE-2026-34714 Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injectio… Vim 9.2.0272+ Fix from $1,9502026-03-30 MEDIUM 5.3 CVE-2026-5125 A vulnerability was detected in raine consult-llm-mcp up to 2.5.3. Affected by this vulnerability is the function child_process.execSync of the file … Patch available Fix from $1,6002026-03-30 CRITICAL 9.9 CVE-2026-33030 Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) … Nginx Ui after 2.3.3 Fix from $2,3002026-03-30 CRITICAL 9.8 CVE-2025-15379 A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to… Mlflow after 3.8.1 Fix from $2,3002026-03-30 HIGH 8.8 CVE-2026-5101 A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the file /cgi-bin/cstecgi.cgi of the… A3300r Firmware No fix yet Fix from $1,9502026-03-29 HIGH 8.8 CVE-2026-4946 Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary comm… Ghidra 12.0.3+ Fix from $1,9502026-03-29 HIGH 8.8 CVE-2026-34005 In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the Ho… Mitigation only Fix from $1,9502026-03-29