Vulnerability index

Browse CVEs

6,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 8.8 CVE-2026-0784 ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $1,9502026-01-23 HIGH 8.8 CVE-2026-0765 Open WebUI PIP install_frontmatter_requirements Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to … Open Webui Mitigation only Fix from $1,9502026-01-23 CRITICAL 9.8 CVE-2026-0755 gemini-mcp-tool execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0756 github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbit… Mitigation only Fix from $2,3002026-01-23 HIGH 8.8 CVE-2026-0757 MCP Manager for Claude Desktop execute-command Command Injection Sandbox Escape Vulnerability. This vulnerability allows remote attackers to bypass t… Mitigation only Fix from $1,9502026-01-23 HIGH 7.8 CVE-2026-0758 mcp-server-siri-shortcuts shortcutName Command Injection Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate pr… Mitigation only Fix from $1,9502026-01-23 CRITICAL 9.8 CVE-2026-0759 Katana Network Development Starter Kit executeCommand Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attacke… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2025-15063 Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2025-15061 Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut… Mitigation only Fix from $2,3002026-01-23 HIGH 8.8 CVE-2026-24129 Runtipi is a Docker-based, personal homeserver orchestrator that facilitates multiple services on a single server. Versions 3.7.0 and above allow an … Runtipi 4.7.0+ Fix from $1,9502026-01-22 CRITICAL 9.8 CVE-2025-56590 An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could allow an attacker to execute … Html2pdf Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-1324EPSS 6% A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionCon… Operation And Maintenance Security Management System after 3.0.12 Fix from $2,3002026-01-22 HIGH 7.2 CVE-2026-23699 AP180 series with firmware versions prior to AP_RGOS 11.9(4)B1P8 contains an OS command injection vulnerability. If this vulnerability is exploited, … Mitigation only Fix from $1,9502026-01-22 CRITICAL 9.8 CVE-2021-47851 Mini Mouse 9.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands through an unauthenticated HTTP e… Mini Mouse Mitigation only Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2021-47748 Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manip… Graphql Engine Mitigation only Fix from $2,3002026-01-21 HIGH 7.3 CVE-2025-33228 NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malici… Cuda Toolkit 13.1.0+ Fix from $1,9502026-01-20 HIGH 7.3 CVE-2025-33230 NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supplying a … Cuda Toolkit 13.1.0+ Fix from $1,9502026-01-20 CRITICAL 9.9 CVE-2026-22844EPSS 13% A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote … Mitigation only Fix from $2,3002026-01-20 HIGH 8.8 CVE-2021-47816 Thecus N4800Eco NAS Server Control Panel contains a command injection vulnerability that allows authenticated attackers to execute arbitrary system c… No fix yet Fix from $1,9502026-01-16 HIGH 8.8 CVE-2026-20759 OS Command Injection vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation, which may allow a logged-in user … Mitigation only Fix from $1,9502026-01-16 HIGH 8.8 CVE-2021-47794 ZesleCP 3.1.9 contains an authenticated remote code execution vulnerability that allows attackers to create malicious FTP accounts with shell injecti… Zeslecp after 3.1.9 Fix from $1,9502026-01-16 HIGH 8.0 CVE-2026-23520 Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported … Arcane 1.13.0+ Fix from $1,9502026-01-15 HIGH 7.5 CVE-2026-22265 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to 8.2.8.2, command injection vulnerability exists in th… Roxy Wi 8.2.8.2+ Fix from $1,9502026-01-15 CRITICAL 9.8 CVE-2025-62193 Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests that include PyFerret express… Patch available Fix from $2,3002026-01-15 HIGH 7.8 CVE-2025-33206 NVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful exploit of this vulnerability… Nsight Graphics 2025.5+ Fix from $1,9502026-01-14 CRITICAL 9.8 CVE-2026-22708 Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, ce… Cursor 2.3+ Fix from $2,3002026-01-14 MEDIUM 6.8 CVE-2026-22718 The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine. Mitigation only Fix from $1,6002026-01-14 CRITICAL 9.8 CVE-2023-54339 Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter… Webgrind after 1.1 Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2022-50919 Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers to inject and chain arbitrar… Tdarr Mitigation only Fix from $2,3002026-01-13 HIGH 8.8 CVE-2022-50909 Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows authenticated attackers to e… No fix yet Fix from $1,9502026-01-13