Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2026-27849 Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normall… Mitigation only Fix from $2,3002026-02-25 MEDIUM 6.7 CVE-2026-20099 A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local … Mitigation only Fix from $1,6002026-02-25 MEDIUM 6.5 CVE-2026-20036 A vulnerability in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker with valid … Mitigation only Fix from $1,6002026-02-25 CRITICAL 9.8 CVE-2026-27848 Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection, which are ultimately run as… Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.9 CVE-2026-27626 OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety chec… Olivetin after 3000.10.0 Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-22553 All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that… Masterscada Mitigation only Fix from $2,3002026-02-24 HIGH 8.8 CVE-2026-23678 Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnosti… 10g08 0800gsm Firmware Mitigation only Fix from $1,9502026-02-24 HIGH 8.8 CVE-2026-3101EPSS 6% A vulnerability was found in Intelbras TIP 635G 1.12.3.5. This vulnerability affects unknown code of the component Ping Handler. The manipulation res… Tip 635g Firmware No fix yet Fix from $1,9502026-02-24 HIGH 8.8 CVE-2026-3102 A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm… Exiftool 13.50+ Fix from $1,9502026-02-24 HIGH 7.8 CVE-2026-27208 bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involving OS Command Injection and P… Api Gateway Deploy Mitigation only Fix from $1,9502026-02-24 HIGH 8.8 CVE-2026-26331 yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt-dlp's `--netrc-cmd` command-… Yt Dlp 2026.02.21+ Fix from $1,9502026-02-24 CRITICAL 9.8 CVE-2025-13942 A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attack… Wx5610 B0 Firmware 1.00 / 1.16+ Fix from $2,3002026-02-24 HIGH 8.8 CVE-2025-13943 A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)… Ex5601 T1 Firmware 5.17 / 5.18+ Fix from $1,9502026-02-24 HIGH 7.2 CVE-2026-1459 A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions thro… Vmg3625 T50c Firmware after 5.50 Fix from $1,9502026-02-24 HIGH 7.2 CVE-2026-3040EPSS 9% A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cgi-bin/mainfunction.cgi/upload… Vigor300b Firmware after 1.5.1.6 Fix from $1,9502026-02-23 HIGH 8.8 CVE-2025-70328 TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executa… X6000r Firmware No fix yet Fix from $1,9502026-02-23 HIGH 8.0 CVE-2025-70329 TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable… X5000r Firmware No fix yet Fix from $1,9502026-02-23 CRITICAL 9.8 CVE-2026-2952EPSS 7% A flaw has been found in Vaelsys 4.1.0. This vulnerability affects unknown code of the file /tree/tree_server.php of the component HTTP POST Request … Vaelsys Mitigation only Fix from $2,3002026-02-22 CRITICAL 9.8 CVE-2026-2944EPSS 6% A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1.01. Affected is the function system of the file … Online Store Management System Mitigation only Fix from $2,3002026-02-22 HIGH 8.0 CVE-2026-27487 OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a… Openclaw 2026.2.14+ Fix from $1,9502026-02-21 HIGH 7.2 CVE-2026-26046 A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command in… Moodle 4.5.9 / 5.0.5+ Fix from $1,9502026-02-21 HIGH 8.8 CVE-2026-2041EPSS 73% Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut… Nagios Xi Mitigation only Fix from $1,9502026-02-20 HIGH 8.8 CVE-2026-2042EPSS 6% Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c… Nagios Xi Mitigation only Fix from $1,9502026-02-20 HIGH 8.8 CVE-2026-2043EPSS 73% Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to… Nagios Xi Mitigation only Fix from $1,9502026-02-20 MEDIUM 6.8 CVE-2026-2035 Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers … Patch available Fix from $1,6002026-02-20 CRITICAL 9.8 CVE-2019-25441EPSS 8% thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting mal… Thesystem Mitigation only Fix from $2,3002026-02-20 MEDIUM 6.3 CVE-2026-27113 Liquid Prompt is an adaptive prompt for Bash and Zsh. Starting in commit cf3441250bb5d8b45f6f8b389fcdf427a99ac28a and prior to commit a4f6b8d8c90b3ea… Patch available Fix from $1,6002026-02-20 CRITICAL 9.8 CVE-2026-27190 Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process impl… Deno 2.6.8+ Fix from $2,3002026-02-20 CRITICAL 10.0 CVE-2021-35402 PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter… Mitigation only Fix from $2,3002026-02-20 HIGH 7.2 CVE-2026-2846EPSS 10% A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the file /goform/formPdbUpConfig of… 520 Firmware No fix yet Fix from $1,9502026-02-20