Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2026-4611 A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file … X6000r Firmware Mitigation only Fix from $1,9502026-03-23 HIGH 7.2 CVE-2026-23882 Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creation function allows specifying… Blinko 1.8.4+ Fix from $1,9502026-03-23 HIGH 8.8 CVE-2026-33648 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a log file path by embedding u… Avideo after 26.0 Fix from $1,9502026-03-23 HIGH 7.2 CVE-2025-15518 Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be e… Archer Nx600 Firmware 1.3.0 / 1.4.0+ Fix from $1,9502026-03-23 HIGH 7.2 CVE-2025-15519 Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be e… Archer Nx600 Firmware 1.3.0 / 1.4.0+ Fix from $1,9502026-03-23 CRITICAL 10.0 CVE-2026-33478EPSS 13% WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain toget… Avideo after 26.0 Fix from $2,3002026-03-23 HIGH 8.1 CVE-2026-33482 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` function in `plugin/API/standAlone/… Avideo after 26.0 Fix from $1,9502026-03-23 CRITICAL 9.8 CVE-2026-4585 A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy… Mitigation only Fix from $2,3002026-03-23 CRITICAL 9.8 CVE-2026-32968 Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in … Mitigation only Fix from $2,3002026-03-23 HIGH 8.8 CVE-2026-4558 A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipu… Mr9600 Firmware No fix yet Fix from $1,9502026-03-22 HIGH 7.5 CVE-2026-33319 WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin construc… Avideo 26.0+ Fix from $1,9502026-03-22 HIGH 8.8 CVE-2026-4554 A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The … F453 Firmware No fix yet Fix from $1,9502026-03-22 CRITICAL 9.8 CVE-2026-32056 OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system.run function, allowing attac… Openclaw 2026.2.22+ Fix from $2,3002026-03-21 HIGH 8.1 CVE-2026-33154 dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due … Dynaconf 3.2.13+ Fix from $1,9502026-03-20 HIGH 7.8 CVE-2025-63261 AWStats 8.0 is vulnerable to Command Injection via the open function Debian Linux No fix yet Fix from $1,9502026-03-20 CRITICAL 9.8 CVE-2026-4499 A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Executing a manipulation can le… Dir 820lw Firmware Mitigation only Fix from $2,3002026-03-20 MEDIUM 5.3 CVE-2026-4496 A vulnerability was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880. Affected by this vulnerability is the function ch… Patch available Fix from $1,6002026-03-20 CRITICAL 9.8 CVE-2026-4497 A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/c… Wa300 Firmware Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-22897 A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitra… Qunetswitch 2.0.4.0415+ Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-22901 A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulne… Qunetswitch after 2.0.5.0906 Fix from $2,3002026-03-20 MEDIUM 6.7 CVE-2026-22902 A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator account, they can then exploit … Qunetswitch after 2.0.5.0906 Fix from $1,6002026-03-20 HIGH 8.8 CVE-2026-32950 SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerab… Sqlbot 1.7.0+ Fix from $1,9502026-03-20 HIGH 8.8 CVE-2026-4465 A flaw has been found in D-Link DIR-513 1.10. The impacted element is an unknown function of the file /goform/formSysCmd. Executing a manipulation of… Dir 513 Firmware No fix yet Fix from $1,9502026-03-20 HIGH 8.1 CVE-2026-32034 OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowInsecureAuth is explicitly enabled an… Openclaw 2026.2.21+ Fix from $1,9502026-03-19 HIGH 8.8 CVE-2026-32010 OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort is manually added to tools.exe… Openclaw 2026.2.22+ Fix from $1,9502026-03-19 HIGH 7.2 CVE-2026-32003 OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run function that allows attackers to bypa… Openclaw 2026.2.22+ Fix from $1,9502026-03-19 CRITICAL 9.8 CVE-2026-32191 Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker t… Bing Images Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.1 CVE-2026-32238 OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command … Openemr 8.0.0.2+ Fix from $2,3002026-03-19 HIGH 7.8 CVE-2026-31999 OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in wrapper resolution for .cmd/.… Openclaw 2026.3.1+ Fix from $1,9502026-03-19 HIGH 7.1 CVE-2026-32000 OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution that uses Windows shell fallba… Openclaw 2026.2.19+ Fix from $1,9502026-03-19