Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.8 CVE-2026-31994 OpenClaw versions prior to 2026.2.19 contain a local command injection vulnerability in Windows scheduled task script generation due to unsafe handli… Openclaw 2026.2.19+ Fix from $1,9502026-03-19 HIGH 7.0 CVE-2026-31995 OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Windows shell fallback mechanism … Openclaw 2026.2.19+ Fix from $1,9502026-03-19 MEDIUM 6.8 CVE-2026-29607 OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persistence that allows attackers to bypas… Openclaw 2026.2.22+ Fix from $1,6002026-03-19 HIGH 7.1 CVE-2026-28460 OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers to execute non-allowlisted command… Openclaw 2026.2.22+ Fix from $1,9502026-03-19 HIGH 7.8 CVE-2026-22176 OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script generation where environment variable… Openclaw 2026.2.19+ Fix from $1,9502026-03-19 HIGH 8.8 CVE-2026-27566 OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fails to unwrap env and shell-dispatc… Openclaw 2026.2.22+ Fix from $1,9502026-03-19 CRITICAL 9.8 CVE-2026-30703 A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02). The adm.cgi e… Mitigation only Fix from $2,3002026-03-18 HIGH 7.0 CVE-2026-32608 Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to configure shell commands that exe… Glances 4.5.2+ Fix from $1,9502026-03-18 HIGH 7.2 CVE-2026-22179 OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows remote attackers to execute … Openclaw 2026.2.22+ Fix from $1,9502026-03-18 MEDIUM 6.7 CVE-2026-22169 OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external… Openclaw 2026.2.22+ Fix from $1,6002026-03-18 HIGH 7.2 CVE-2026-28673 xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the standard plugin… Xiaoheifs 0.4.0+ Fix from $1,9502026-03-18 HIGH 8.8 CVE-2026-27811 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a command injection vulnerability ex… Roxy Wi 8.2.6.3+ Fix from $1,9502026-03-18 CRITICAL 9.1 CVE-2026-32298 The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute O… Es3 Kvm Firmware Mitigation only Fix from $2,3002026-03-17 HIGH 7.2 CVE-2026-23759 Perle IOLAN STS/SCS terminal server models with firmware versions prior to 6.0 allow authenticated OS command injection via the restricted shell acce… Mitigation only Fix from $1,9502026-03-17 HIGH 7.2 CVE-2026-4253EPSS 7% A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of the file /cgi-bin/UploadCfg of … Ac8 Firmware No fix yet Fix from $1,9502026-03-16 CRITICAL 9.8 CVE-2026-4170 A weakness has been identified in Topsec TopACM 3.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/manage… Mitigation only Fix from $2,3002026-03-16 MEDIUM 6.8 CVE-2026-3227 A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special e… Tl Wr802n Firmware 260303 / 260304+ Fix from $1,6002026-03-16 HIGH 7.2 CVE-2026-31386 OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be ex… Litespeed Web Server 6.3.5+ Fix from $1,9502026-03-16 HIGH 8.8 CVE-2025-14287 A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/__init__.py` file at lines 16… Mlflow 3.7.0+ Fix from $1,9502026-03-16 CRITICAL 9.8 CVE-2025-15060 claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi… Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2026-32260 Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exists in Deno's node:child_proces… Deno 2.7.2+ Fix from $2,3002026-03-12 HIGH 8.8 CVE-2026-3841 A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by … Tl Mr6400 Firmware 1.9.0+ Fix from $1,9502026-03-12 CRITICAL 9.4 CVE-2026-28384 An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as th… Patch available Fix from $2,3002026-03-12 MEDIUM 5.3 CVE-2026-3964 A weakness has been identified in OpenAkita up to 1.24.3. This impacts the function run of the file src/openakita/tools/shell.py of the component Cha… Mitigation only Fix from $1,6002026-03-11 MEDIUM 5.3 CVE-2026-3959 A vulnerability was found in 0xKoda WireMCP up to 7f45f8b2b4adeb76be8c6227eefb38533fdd6b1e. Impacted is the function server.tool of the file index.js… Mitigation only Fix from $1,6002026-03-11 CRITICAL 9.8 CVE-2026-31975 Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection v… Cloud Cli 1.25.0+ Fix from $2,3002026-03-11 HIGH 8.8 CVE-2026-31862 Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, multiple Git-related A… Cloud Cli 1.24.0+ Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-31854 Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted instructions, the model may at… Cursor 2.0+ Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-20040 A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underly… Ios Xr 25.2.21 / 25.4.2+ Fix from $1,9502026-03-11 CRITICAL 9.8 CVE-2025-70082 An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component Eds3016ps1ns Firmware Mitigation only Fix from $2,3002026-03-11