Vulnerability index

Browse CVEs

6,363 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2025-67041 An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly saniti… Eds3016ps1ns Firmware Mitigation only Fix from $2,3002026-03-11 HIGH 7.8 CVE-2024-14026 A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who h… Qts Mitigation only Fix from $1,9502026-03-11 HIGH 7.2 CVE-2026-23816 A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the un… Arubaos Cx after 10.17.0001 Fix from $1,9502026-03-11 CRITICAL 9.8 CVE-2026-28292 `simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacke… Simple Git 3.32.2+ Fix from $2,3002026-03-10 HIGH 7.2 CVE-2026-25836 An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, For… Fortisandbox Cloud Mitigation only Fix from $1,9502026-03-10 HIGH 7.2 CVE-2025-66178 A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, … Fortiweb 7.0.13 / 7.2.13+ Fix from $1,9502026-03-10 CRITICAL 9.8 CVE-2025-41709 An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device. Mitigation only Fix from $2,3002026-03-10 HIGH 8.8 CVE-2026-26982 Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dropped text. These can be used … Ghostty 1.3.0+ Fix from $1,9502026-03-10 HIGH 7.2 CVE-2026-25041 Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the PostgreSQL integration construc… Budibase after 3.23.22 Fix from $1,9502026-03-09 CRITICAL 9.8 CVE-2025-70039 An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223. Twake Mitigation only Fix from $2,3002026-03-09 HIGH 8.0 CVE-2025-15568 A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network… Archer Axe75 Firmware 1.3.2+ Fix from $1,9502026-03-09 CRITICAL 9.8 CVE-2026-3696 A vulnerability was found in Totolink N300RH 6..1c.1353_B20190305. The affected element is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi… N300rh Firmware Mitigation only Fix from $2,3002026-03-08 HIGH 8.8 CVE-2026-30861 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an … Weknora 0.2.10+ Fix from $1,9502026-03-07 CRITICAL 9.8 CVE-2026-25070 XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endp… Zikestor Sks8310 8x Firmware after 1.04.b07 Fix from $2,3002026-03-07 HIGH 7.8 CVE-2026-29783 The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution through crafted bash parameter ex… Copilot Command Line Interface 0.0.423+ Fix from $1,9502026-03-06 CRITICAL 9.8 CVE-2026-29058 AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by inj… Avideo Encoder 7.0+ Fix from $2,3002026-03-06 HIGH 7.2 CVE-2026-28507 Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained import file write and templa… Known 1.6.4+ Fix from $1,9502026-03-06 CRITICAL 9.8 CVE-2026-28470 OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbit… Openclaw 2026.2.2+ Fix from $2,3002026-03-05 MEDIUM 5.5 CVE-2026-28463 OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist validation that checks pre-expansio… Openclaw 2026.2.14+ Fix from $1,6002026-03-05 CRITICAL 9.8 CVE-2026-28391 OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configurat… Openclaw 2026.2.2+ Fix from $2,3002026-03-05 HIGH 8.8 CVE-2026-28287EPSS 8% FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vu… Freepbx 16.0.20 / 17.0.5+ Fix from $1,9502026-03-05 HIGH 7.2 CVE-2026-28209 FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, a command injection vulnerabi… Freepbx 16.0.20 / 17.0.5+ Fix from $1,9502026-03-05 MEDIUM 6.0 CVE-2026-20008 A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure … Adaptive Security Appliance Software 7.0.9 / 7.2.11+ Fix from $1,6002026-03-04 CRITICAL 9.8 CVE-2026-26478 A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially craf… Tichome Mini Firmware Mitigation only Fix from $2,3002026-03-04 HIGH 7.2 CVE-2025-59783 API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injecti… Access Commander 3.4.2+ Fix from $1,9502026-03-04 CRITICAL 9.8 CVE-2026-27441 SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution. Seppmail 15.0.1+ Fix from $2,3002026-03-04 HIGH 8.8 CVE-2026-28773 The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite  Receiver We… Sfx2100 Firmware No fix yet Fix from $1,9502026-03-04 HIGH 8.8 CVE-2026-28774 An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series… Sfx2100 Firmware No fix yet Fix from $1,9502026-03-04 CRITICAL 9.1 CVE-2026-26279 Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disable… Froxlor 2.3.4+ Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-3485 A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument… Dir 868l Firmware Mitigation only Fix from $2,3002026-03-03