Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2026-71989 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers … No fix yet Fix from $5,7502026-08-09 CRITICAL 9.8 CVE-2026-71983 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to… No fix yet Fix from $5,7502026-08-08 CRITICAL 9.8 CVE-2026-71956 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi … No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71954 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71955 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71948 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71949 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71950 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71951 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71952 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71953 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71944 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71945 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71946 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71947 D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /… No fix yet Fix from $2,3002026-08-08 MEDIUM 5.4 CVE-2026-48122 Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to v… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.3 CVE-2026-19243 A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file… No fix yet Fix from $1,6002026-08-07 HIGH 7.8 CVE-2026-48097 NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a co… No fix yet Fix from $1,9502026-08-07 HIGH 7.3 CVE-2026-48098 NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute p… No fix yet Fix from $1,9502026-08-07 HIGH 7.5 CVE-2026-15816 A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory wit… No fix yet Fix from $1,9502026-08-07 HIGH 7.3 CVE-2026-67434 PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer … No fix yet Fix from $1,9502026-08-06 HIGH 7.2 CVE-2026-63725 sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a tar shell command by string-con… No fix yet Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-15733EPSS 14% A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attack… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-67261 Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI … Virtual Storage Integrator 10.11.1.0+ Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-53975 OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands b… No fix yet Fix from $2,3002026-08-06 HIGH 7.2 CVE-2026-19036 A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulatio… No fix yet Fix from $1,9502026-08-06 HIGH 7.2 CVE-2026-19035 A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The m… No fix yet Fix from $1,9502026-08-06 HIGH 7.2 CVE-2026-19034 A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimit… No fix yet Fix from $1,9502026-08-06 HIGH 8.0 CVE-2026-71312 rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates r… No fix yet Fix from $1,9502026-08-05 HIGH 8.0 CVE-2026-66297 Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebook allows command inject… Livebook 0.18.7 / 0.19.9+ Fix from $1,9502026-08-05