Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.8 CVE-2026-25546 Godot MCP is a Model Context Protocol (MCP) server for interacting with the Godot game engine. Prior to version 0.1.1, a command injection vulnerabil… Godot Mcp 0.1.1+ Fix from $1,9502026-02-04 HIGH 8.8 CVE-2026-25512EPSS 19% Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote … Group Office 6.8.150 / 25.0.82+ Fix from $1,9502026-02-04 HIGH 7.8 CVE-2026-25143 melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacker who can influence inputs to… Melange 0.40.5+ Fix from $1,9502026-02-04 HIGH 7.5 CVE-2026-25157 OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeC… Openclaw 2026.1.29+ Fix from $1,9502026-02-04 HIGH 8.8 CVE-2026-24844 melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker who can provide build input … Melange after 0.40.5 Fix from $1,9502026-02-04 HIGH 7.2 CVE-2026-21893 n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s… N8n 1.120.3+ Fix from $1,9502026-02-04 CRITICAL 9.9 CVE-2026-25053 n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users… N8n 1.123.0 / 2.5.0+ Fix from $2,3002026-02-04 HIGH 8.8 CVE-2026-24887 Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirm… Claude Code 2.0.72+ Fix from $1,9502026-02-03 CRITICAL 9.8 CVE-2025-52626 A Potential Command Injection vulnerability in HCL AION.  An This can allow unintended command execution, potentially leading to unauthorized actio… Aion Mitigation only Fix from $2,3002026-02-03 HIGH 8.8 CVE-2026-22550 OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS comman… Wrc X1500gsa B Firmware after 1.13 Fix from $1,9502026-02-03 HIGH 7.8 CVE-2026-0383 A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash shell to access insecurely store… Fabric Operating System 9.2.1c2 / 9.2.2b+ Fix from $1,9502026-02-03 HIGH 8.8 CVE-2026-24763 OpenClaw (formerly Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command injection vulnerability existed i… Openclaw 2026.1.29+ Fix from $1,9502026-02-02 HIGH 8.8 CVE-2026-23515 Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated … Signal K Server 1.5.0+ Fix from $1,9502026-02-02 HIGH 8.0 CVE-2026-22223 An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attacker execute arbitrary code. … Archer Be230 Firmware 1.2.4+ Fix from $1,9502026-02-02 HIGH 7.2 CVE-2026-22224 A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface on the TP-Link Archer BE230 … Archer Be230 Firmware 1.2.4+ Fix from $1,9502026-02-02 HIGH 7.2 CVE-2026-22225 A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the Archer BE230 v1.2  and Arche… Archer Be230 Firmware 1.2.4+ Fix from $1,9502026-02-02 HIGH 7.2 CVE-2026-22226 A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration module on TP-Link Archer BE230 v1… Archer Be230 Firmware 1.2.4+ Fix from $1,9502026-02-02 HIGH 7.2 CVE-2026-22227 A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restoration function of the TP-Link … Archer Be230 Firmware 1.2.4+ Fix from $1,9502026-02-02 HIGH 7.2 CVE-2026-22229 A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN client configuration file on the … Archer Be230 Firmware 1.2.4+ Fix from $1,9502026-02-02 HIGH 8.0 CVE-2026-22221 An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attacker execute arbitrary code. … Archer Be230 Firmware 1.2.4+ Fix from $1,9502026-02-02 HIGH 8.0 CVE-2026-22222 An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attacker to execute arbitrary code.… Archer Be230 Firmware 1.2.4+ Fix from $1,9502026-02-02 HIGH 8.0 CVE-2026-0630 An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent authenticated attacker to e… Archer Be230 Firmware 1.2.4+ Fix from $1,9502026-02-02 HIGH 8.0 CVE-2026-0631 An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and OpenVPN of AXE75 v1 allows an adjacent authenticated attacker… Archer Be230 Firmware 1.2.4+ Fix from $1,9502026-02-02 HIGH 8.0 CVE-2025-9974 The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users to trigger unintended system-l… Mitigation only Fix from $1,9502026-02-02 HIGH 8.8 CVE-2026-24788 RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by … Mitigation only Fix from $1,9502026-02-02 HIGH 8.8 CVE-2020-37032 Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system c… Wing Ftp Server No fix yet Fix from $1,9502026-01-30 CRITICAL 9.8 CVE-2020-37027 Sickbeard alpha contains a remote command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands through the ext… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.6 CVE-2026-25130 Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple… Patch available Fix from $2,3002026-01-30 CRITICAL 9.2 CVE-2026-1723 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injecti… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2025-51958 aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system commands via lib/plugins/runcomm… Runcommand Mitigation only Fix from $2,3002026-01-30