Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2026-21654 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum H… Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 HIGH 8.8 CVE-2026-0980 A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with … Satellite after 0.12.1 Fix from $1,9502026-02-27 CRITICAL 9.8 CVE-2026-3301 A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file … N300rh Firmware Mitigation only Fix from $2,3002026-02-27 HIGH 8.8 CVE-2026-25196 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-25721 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-3037 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-25037 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-25105 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code e… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-20764 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-23702 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-24452 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-24695 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code ex… Xweb 500b Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-25109 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code exec… Xweb 500b Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-25111 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut… Xweb 500b Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 MEDIUM 6.6 CVE-2026-25195 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code exe… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,6002026-02-27 HIGH 7.2 CVE-2026-24517 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code exec… Xweb 500b Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 CRITICAL 9.8 CVE-2026-24663 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code exec… Xweb 500b Pro Firmware after 1.12.1 Fix from $2,3002026-02-27 HIGH 8.8 CVE-2026-24689 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu… Xweb 500b Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-20742 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execu… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-20902 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code exe… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-20910 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-21389 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execut… Xweb 300d Pro Firmware after 1.12.1 Fix from $1,9502026-02-27 HIGH 8.4 CVE-2026-28279 osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `osctrl-admin` environment conf… Osctrl 0.5.0+ Fix from $1,9502026-02-26 HIGH 8.8 CVE-2026-28269 Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated u… Kiteworks 9.2.0+ Fix from $1,9502026-02-26 HIGH 7.3 CVE-2026-28207 Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command injection vulnerability (CWE-78)… Zen C 0.4.2+ Fix from $1,9502026-02-26 CRITICAL 9.9 CVE-2026-27965 Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the bac… Vitess 22.0.4 / 23.0.3+ Fix from $2,3002026-02-26 HIGH 7.7 CVE-2026-27938 WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository contains a GitHub Actions workfl… Patch available Fix from $1,9502026-02-26 HIGH 8.8 CVE-2026-27635 Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version… Manyfold 0.133.0+ Fix from $1,9502026-02-26 CRITICAL 9.8 CVE-2026-27613 TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers … Tinyweb 2.01+ Fix from $2,3002026-02-25 HIGH 8.8 CVE-2026-27728 OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMo… Oneuptime 10.0.7+ Fix from $1,9502026-02-25