Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
MEDIUM 6.9 CVE-2026-70611 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-b… No fix yet Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-17625 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, … Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-17623 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the com… Langflow 1.11.0+ Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-13477 IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary c… Qradar Security Information And Event Manager No fix yet Fix from $1,9502026-08-05 HIGH 7.2 CVE-2026-71284 Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the first extracted tar member's fil… No fix yet Fix from $1,9502026-08-05 HIGH 7.8 CVE-2026-16022 @oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constructs shell commands through s… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-71243 The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. cmd =… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-70374 HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateT… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-70375 HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server… No fix yet Fix from $1,9502026-08-05 HIGH 7.2 CVE-2026-18900 A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This man… No fix yet Fix from $1,9502026-08-05 CRITICAL 9.8 CVE-2026-66902 Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable sub… No fix yet Fix from $2,3002026-08-04 HIGH 8.8 CVE-2026-16793 An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) … No fix yet Fix from $1,9502026-08-04 HIGH 7.2 CVE-2026-6837 A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could… No fix yet Fix from $1,9502026-08-04 CRITICAL 9.8 CVE-2026-51190 The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL e… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-52102 An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as ro… No fix yet Fix from $2,3002026-08-03 HIGH 7.2 CVE-2026-67599 ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary comma… No fix yet Fix from $1,9502026-08-03 HIGH 7.3 CVE-2026-18641 A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the fu… No fix yet Fix from $1,9502026-08-03 HIGH 8.8 CVE-2026-69096 OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) con… Mitigation only Fix from $1,9502026-08-03 HIGH 7.2 CVE-2026-67608 Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_au… No fix yet Fix from $1,9502026-08-03 MEDIUM 6.3 CVE-2026-18590 A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin … No fix yet Fix from $1,6002026-08-03 HIGH 7.5 CVE-2026-18587 A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a m… No fix yet Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-67324 GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default … No fix yet Fix from $2,3002026-08-01 HIGH 8.8 CVE-2026-67325 GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. A… No fix yet Fix from $1,9502026-08-01 CRITICAL 9.3 CVE-2026-67308 Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submi… No fix yet Fix from $2,3002026-08-01 HIGH 8.0 CVE-2026-9044 An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated atta… Archer Axe75 Firmware 1.5.6+ Fix from $1,9502026-07-31 CRITICAL 9.9 CVE-2026-17566 pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passi… Pgadmin 4 9.18+ Fix from $2,3002026-07-31 HIGH 8.8 CVE-2026-17347 The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption… Pgadmin 4 9.17+ Fix from $1,9502026-07-31 HIGH 7.2 CVE-2026-16843 Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid crede… No fix yet Fix from $1,9502026-07-31 CRITICAL 9.8 CVE-2026-12943 IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink)… Hardware Management Console 10.3.1064.1 / 11.1.1112.1+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-12940 IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model C… Langflow 1.10.2+ Fix from $2,3002026-07-30