Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2026-14522 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due… App Connect Enterprise 12.0.12.28 / 13.0.8.0+ Fix from $2,3002026-07-30 HIGH 8.3 CVE-2026-22621 Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administ… No fix yet Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-22622 Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to … No fix yet Fix from $1,9502026-07-30 HIGH 7.8 CVE-2026-44106 A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as roo… No fix yet Fix from $1,9502026-07-30 HIGH 7.8 CVE-2026-44099 A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting … No fix yet Fix from $1,9502026-07-30 HIGH 7.8 CVE-2026-44093 A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands … No fix yet Fix from $1,9502026-07-30 HIGH 7.8 CVE-2026-44095 A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as r… No fix yet Fix from $1,9502026-07-30 HIGH 7.8 CVE-2026-44096 A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compro… No fix yet Fix from $1,9502026-07-30 HIGH 8.6 CVE-2026-44098 This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injectio… No fix yet Fix from $1,9502026-07-30 HIGH 7.8 CVE-2026-16524 A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed valid… No fix yet Fix from $1,9502026-07-30 MEDIUM 6.6 CVE-2026-67438 OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/internal/executor/arguments.go ch… No fix yet Fix from $1,6002026-07-29 MEDIUM 6.8 CVE-2026-56389 GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration var… No fix yet Fix from $1,6002026-07-29 HIGH 7.2 CVE-2026-14958 IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation. Aspera Faspex 5.0.16+ Fix from $1,9502026-07-28 HIGH 7.2 CVE-2026-14959 IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection. Aspera Faspex 5.0.16+ Fix from $1,9502026-07-28 HIGH 7.2 CVE-2026-59764 ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an … No fix yet Fix from $1,9502026-07-28 HIGH 7.2 CVE-2026-61376 ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exp… No fix yet Fix from $1,9502026-07-28 HIGH 8.8 CVE-2026-54540 Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated terminal command whitelist bypass… No fix yet Fix from $1,9502026-07-27 HIGH 8.8 CVE-2026-55578 Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the terminal feature in Pheditor uses a… No fix yet Fix from $1,9502026-07-27 CRITICAL 9.9 CVE-2026-48030EPSS 5% Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability i… No fix yet Fix from $2,3002026-07-27 HIGH 7.8 CVE-2026-24252 NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead … No fix yet Fix from $1,9502026-07-27 CRITICAL 10.0 CVE-2026-16812 KEV VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an… Velocloud Orchestrator 5.2.3.14 / 6.1.3.4+ Fix from $2,3002026-07-27 HIGH 8.5 CVE-2025-59172 Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacke… No fix yet Fix from $1,9502026-07-27 HIGH 8.4 CVE-2026-59687 An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows… Connection Manager For Objectscale 7.2.54.19 / 7.2.63.3+ Fix from $1,9502026-07-27 HIGH 8.4 CVE-2026-59688 An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows… Connection Manager For Objectscale 7.2.54.19 / 7.2.63.3+ Fix from $1,9502026-07-27 HIGH 8.4 CVE-2026-59686 An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows… Connection Manager For Objectscale 7.2.54.19 / 7.2.63.3+ Fix from $1,9502026-07-27 HIGH 8.3 CVE-2026-17497 NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the defa… No fix yet Fix from $1,9502026-07-26 CRITICAL 9.8 CVE-2026-16766 Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly t… No fix yet Fix from $2,3002026-07-25 HIGH 7.2 CVE-2026-65711 sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands … No fix yet Fix from $1,9502026-07-24 HIGH 7.2 CVE-2026-66138 In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic… No fix yet Fix from $1,9502026-07-24 CRITICAL 9.9 CVE-2026-63732 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation… No fix yet Fix from $2,3002026-07-23