Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2026-0709 Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid cr… Mitigation only Fix from $1,9502026-01-30 HIGH 7.8 CVE-2026-22277 Dell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul… Unity Operating Environment 5.5.3.0+ Fix from $1,9502026-01-30 HIGH 7.8 CVE-2026-21418 Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vuln… Unity Operating Environment 5.5.3.0+ Fix from $1,9502026-01-30 MEDIUM 5.4 CVE-2026-1665 A command injection vulnerability exists in nvm (Node Version Manager) versions 0.40.3 and below. The nvm_download() function uses eval to execute wg… Patch available Fix from $1,6002026-01-29 HIGH 7.8 CVE-2026-24905 Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The `ig… Inspektor Gadget 0.48.1+ Fix from $1,9502026-01-29 HIGH 7.8 CVE-2026-25063 gradle-completion provides Bash and Zsh completion support for Gradle. A command injection vulnerability was found in gradle-completion up to and inc… Gradle Completion after 9.3.0 Fix from $1,9502026-01-29 CRITICAL 9.8 CVE-2020-37012 Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary shell commands through the /a… Mitigation only Fix from $2,3002026-01-29 CRITICAL 9.8 CVE-2020-37002 Ajenti 2.1.36 contains a post-authenticated remote command execution vulnerability that allows remote attackers to execute arbitrary commands after s… Mitigation only Fix from $2,3002026-01-29 HIGH 8.8 CVE-2026-1544 A security flaw has been discovered in D-Link DIR-823X 250416. Impacted is the function sub_41E2A0 of the file /goform/set_mode. Performing a manipul… Dir 823x Firmware No fix yet Fix from $1,9502026-01-28 HIGH 7.8 CVE-2025-57283 The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly san… Browserstack Local Mitigation only Fix from $1,9502026-01-28 HIGH 7.2 CVE-2026-1506EPSS 5% A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php of the component MAC Filter Co… Dir 615 Firmware No fix yet Fix from $1,9502026-01-28 HIGH 7.2 CVE-2026-1505 A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes.php of the component URL Fil… Dir 615 Firmware No fix yet Fix from $1,9502026-01-28 CRITICAL 9.9 CVE-2026-24841 Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokp… Dokploy 0.26.6+ Fix from $2,3002026-01-28 HIGH 7.2 CVE-2026-23592 Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated attackers to achieve remote code … Mitigation only Fix from $1,9502026-01-27 HIGH 7.8 CVE-2025-33234 NVIDIA runx contains a vulnerability where an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code ex… Mitigation only Fix from $1,9502026-01-27 HIGH 7.2 CVE-2026-1448EPSS 5% A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component We… Dir 615 Firmware after 4.10 Fix from $1,9502026-01-27 HIGH 8.8 CVE-2026-1428 Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbi… Single Sign On Portal System Mitigation only Fix from $1,9502026-01-26 HIGH 8.8 CVE-2026-1427 Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbi… Single Sign On Portal System Mitigation only Fix from $1,9502026-01-26 HIGH 7.8 CVE-2025-67264 An OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pro+ allows a local attacker to… Note59 Pro\+ Firmware No fix yet Fix from $1,9502026-01-23 HIGH 8.8 CVE-2021-47903 LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authent… No fix yet Fix from $1,9502026-01-23 HIGH 8.8 CVE-2026-0795 ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $1,9502026-01-23 HIGH 8.8 CVE-2026-0796 ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $1,9502026-01-23 HIGH 8.8 CVE-2026-0785 ALGO 8180 IP Audio Alerter API Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $1,9502026-01-23 HIGH 8.8 CVE-2026-0786 ALGO 8180 IP Audio Alerter SCI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $1,9502026-01-23 CRITICAL 9.8 CVE-2026-0787 ALGO 8180 IP Audio Alerter SAC Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $2,3002026-01-23 HIGH 8.8 CVE-2026-0779 ALGO 8180 IP Audio Alerter Ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $1,9502026-01-23 HIGH 8.8 CVE-2026-0780 ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $1,9502026-01-23 HIGH 8.8 CVE-2026-0781 ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $1,9502026-01-23 HIGH 8.8 CVE-2026-0782 ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $1,9502026-01-23 HIGH 8.8 CVE-2026-0783 ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $1,9502026-01-23