Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2026-2847EPSS 9% A vulnerability was detected in UTT HiPER 520 1.7.7-160105. Affected is the function sub_44EFB4 of the file /goform/formReleaseConnect of the compone… 520 Firmware No fix yet Fix from $1,9502026-02-20 CRITICAL 9.8 CVE-2025-70831 A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The application fails to properly saniti… Smanga Mitigation only Fix from $2,3002026-02-20 HIGH 8.8 CVE-2026-26323 OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev script `scripts/update-clawtr… Openclaw 2026.2.14+ Fix from $1,9502026-02-19 CRITICAL 9.8 CVE-2026-27476 RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 … Mitigation only Fix from $2,3002026-02-19 HIGH 8.8 CVE-2026-26318 systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `l… Systeminformation 5.31.0+ Fix from $1,9502026-02-19 HIGH 7.8 CVE-2026-26280 systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetw… Systeminformation 5.30.8+ Fix from $1,9502026-02-19 HIGH 8.1 CVE-2026-26189 Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulnerability exists in `aquasecur… Trivy Action 0.34.1+ Fix from $1,9502026-02-19 CRITICAL 9.8 CVE-2025-15559 An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server API call to generate and dow… Worktime after 11.8.8 Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-2686 A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file /cgi-bin/session_login.cgi. … Mitigation only Fix from $2,3002026-02-19 HIGH 7.2 CVE-2026-2670EPSS 16% A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply o… Mitigation only Fix from $1,9502026-02-18 CRITICAL 9.8 CVE-2026-27175EPSS 7% MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param variable from user input is … Majordomo Patch available Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2025-65791 ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() f… Zoneminder Mitigation only Fix from $2,3002026-02-18 MEDIUM 6.4 CVE-2025-12122 The Popup Box – Easily Create WordPress Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframeBox' shortco… Mitigation only Fix from $1,6002026-02-18 HIGH 7.3 CVE-2026-2629 A weakness has been identified in jishi node-sonos-http-api up to 3776f0ee2261c924c7b7204de121a38100a08ca7. Affected is the function Promise of the f… Mitigation only Fix from $1,9502026-02-17 HIGH 8.8 CVE-2026-2630 A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable … Mitigation only Fix from $1,9502026-02-17 HIGH 8.8 CVE-2025-70828 An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configuration Datart No fix yet Fix from $1,9502026-02-17 MEDIUM 6.3 CVE-2026-2560 A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoRes… Mitigation only Fix from $1,6002026-02-16 HIGH 7.3 CVE-2026-2544 A security flaw has been discovered in yued-fe LuLu UI up to 3.0.0. This issue affects the function child_process.exec of the file run.js. The manipu… Mitigation only Fix from $1,9502026-02-16 HIGH 8.8 CVE-2026-25108 KEV FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted… Filezen 5.0.11+ Fix from $1,9502026-02-13 CRITICAL 9.9 CVE-2026-26068 emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is ac… Emp3r0r 3.21.1+ Fix from $2,3002026-02-12 MEDIUM 5.4 CVE-2026-25828 grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $ro… Mitigation only Fix from $1,6002026-02-12 MEDIUM 6.8 CVE-2026-25933 Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in the Terminal component of the … App Lab 0.4.0+ Fix from $1,6002026-02-12 HIGH 7.5 CVE-2026-26029 sf-mcp-server is an implementation of Salesforce MCP server for Claude for Desktop. A command injection vulnerability exists in sf-mcp-server due to … Patch available Fix from $1,9502026-02-11 HIGH 8.8 CVE-2025-65480 An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Templates which are executed wh… Mitigation only Fix from $1,9502026-02-11 HIGH 7.8 CVE-2024-56808 A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access who have also gained … Media Streaming Add On 500.1.1.6+ Fix from $1,9502026-02-11 CRITICAL 9.9 CVE-2026-26009 Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install scripts defined in server te… Patch available Fix from $2,3002026-02-10 HIGH 8.8 CVE-2026-0652EPSS 22% On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchron… Tapo C260 Firmware 1.1.9+ Fix from $1,9502026-02-10 HIGH 8.8 CVE-2025-11142 The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be expl… Axis Os 12.7.36+ Fix from $1,9502026-02-10 HIGH 7.2 CVE-2026-2260 A vulnerability was found in D-Link DCS-931L up to 1.13.0. This affects an unknown part of the file /goform/setSysAdmin. The manipulation of the argu… Dcs 931l Firmware after 1.13.00 Fix from $1,9502026-02-10 HIGH 7.2 CVE-2026-2210 A vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_filtering. Such manipulation l… Dir 823x Firmware No fix yet Fix from $1,9502026-02-09