Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
MEDIUM 5.3 CVE-2026-16763 A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js … No fix yet Fix from $1,6002026-07-23 CRITICAL 9.4 CVE-2026-47670 DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid … No fix yet Fix from $2,3002026-07-23 CRITICAL 10.0 CVE-2026-6516 Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. No fix yet Fix from $2,3002026-07-23 MEDIUM 5.3 CVE-2026-16733 A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js… No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-16735 A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file in… No fix yet Fix from $1,6002026-07-23 HIGH 7.8 CVE-2026-16287 Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Rese… No fix yet Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-16631 A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component packa… No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-16630 A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the… No fix yet Fix from $1,6002026-07-22 MEDIUM 5.3 CVE-2026-16629 A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/loc… No fix yet Fix from $1,6002026-07-22 MEDIUM 5.3 CVE-2026-16628 A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin En… No fix yet Fix from $1,6002026-07-22 HIGH 7.8 CVE-2026-14881 When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In … No fix yet Fix from $1,9502026-07-22 HIGH 7.8 CVE-2026-44191 A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling … No fix yet Fix from $1,9502026-07-22 CRITICAL 9.8 CVE-2026-65590 n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandbox… N8n 2.29.8+ Fix from $2,3002026-07-22 HIGH 7.8 CVE-2026-44190 A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to ex… No fix yet Fix from $1,9502026-07-22 HIGH 8.8 CVE-2026-3821 Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input … No fix yet Fix from $1,9502026-07-22 MEDIUM 5.5 CVE-2026-16492 A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/g… No fix yet Fix from $1,6002026-07-22 MEDIUM 5.0 CVE-2026-16488 A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/conf… No fix yet Fix from $1,6002026-07-22 MEDIUM 5.3 CVE-2026-16489 A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the comp… No fix yet Fix from $1,6002026-07-22 CRITICAL 9.8 CVE-2026-8986 Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious o… Maxicharger Single Charger Firmware after 1.03.51 Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-8985EPSS 7% Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthen… Maxicharger Single Charger Firmware after 1.03.51 Fix from $2,3002026-07-21 HIGH 8.8 CVE-2026-64881 The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation… Security Center No fix yet Fix from $1,9502026-07-21 CRITICAL 9.8 CVE-2026-30631 An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code vi… No fix yet Fix from $2,3002026-07-21 CRITICAL 9.9 CVE-2026-64878 Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a… Security Center No fix yet Fix from $2,3002026-07-21 CRITICAL 9.9 CVE-2026-64879 A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell … Security Center No fix yet Fix from $2,3002026-07-21 HIGH 7.5 CVE-2026-16445 A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, suc… No fix yet Fix from $1,9502026-07-21 HIGH 7.2 CVE-2026-6952 A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5… No fix yet Fix from $1,9502026-07-21 CRITICAL 9.8 CVE-2026-64625 AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command… No fix yet Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2026-63766 GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate… Mitigation only Fix from $2,3002026-07-20 CRITICAL 9.9 CVE-2026-54051 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`San… No fix yet Fix from $2,3002026-07-20 HIGH 8.6 CVE-2026-40187 In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTem… No fix yet Fix from $1,9502026-07-20