Vulnerability index

Browse CVEs

6,340 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
HIGH 7.2 CVE-2026-14448 An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certificates view due to improper ne… No fix yet Fix from $1,9502026-07-20 HIGH 8.8 CVE-2026-50289 systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injec… Systeminformation 5.31.7+ Fix from $1,9502026-07-17 CRITICAL 9.8 CVE-2026-46420 setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.25.0 prior to 2.37.1, shivamma… Setup Php No fix yet Fix from $2,3002026-07-17 CRITICAL 9.1 CVE-2026-42168 django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passe… No fix yet Fix from $2,3002026-07-17 MEDIUM 5.4 CVE-2026-15069 IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input… Engineering Ai Hub 1.3.0+ Fix from $1,6002026-07-17 HIGH 8.8 CVE-2026-14499 IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system… Langflow 1.10.2+ Fix from $1,9502026-07-17 HIGH 8.8 CVE-2026-58195 Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone-stdio.ts, src/mcp/fastmcp/se… No fix yet Fix from $1,9502026-07-17 HIGH 8.1 CVE-2026-55173 WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because the fix for CVE-2026-33482 wa… No fix yet Fix from $1,9502026-07-16 MEDIUM 5.3 CVE-2026-47751 Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to 1.0.74, because the action c… No fix yet Fix from $1,6002026-07-16 HIGH 8.8 CVE-2026-14371 The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command… No fix yet Fix from $1,9502026-07-16 CRITICAL 9.8 CVE-2026-45695 Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, an… No fix yet Fix from $2,3002026-07-16 HIGH 8.1 CVE-2026-63304 AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function in… Mitigation only Fix from $1,9502026-07-16 HIGH 8.1 CVE-2026-63305 AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are conca… No fix yet Fix from $1,9502026-07-16 CRITICAL 9.8 CVE-2023-49900 An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command. No fix yet Fix from $2,3002026-07-16 HIGH 8.8 CVE-2026-55576 MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inline… Mitigation only Fix from $1,9502026-07-15 CRITICAL 9.9 CVE-2026-52891 Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passe… Mitigation only Fix from $2,3002026-07-15 MEDIUM 6.7 CVE-2026-55410 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/… Mitigation only Fix from $1,6002026-07-15 HIGH 8.8 CVE-2026-62312 9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitrary code execution on the host… Mitigation only Fix from $1,9502026-07-15 CRITICAL 10.0 CVE-2026-46339 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, a… Mitigation only Fix from $2,3002026-07-15 HIGH 7.8 CVE-2026-15895 OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrar… Mitigation only Fix from $1,9502026-07-15 HIGH 7.8 CVE-2026-46709 Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/path… Tabby 1.0.234+ Fix from $1,9502026-07-15 HIGH 7.3 CVE-2026-61438 PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validatio… Mitigation only Fix from $1,9502026-07-15 HIGH 8.2 CVE-2026-48345 Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result … Animate 23.0.16 / 24.0.14+ Fix from $1,9502026-07-14 HIGH 7.7 CVE-2026-48347 Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result … Animate 23.0.16 / 24.0.14+ Fix from $1,9502026-07-14 HIGH 8.1 CVE-2026-15427 An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and … Archer Vx1800v Firmware 0.16.0+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-15428 An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent att… Archer Vx1800v Firmware 0.16.0+ Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-58479 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allow… Sustainable Irrigation Platform after 5.2.16 Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-62392 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job… Kylin 5.0.4+ Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-3014 Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. … Mitigation only Fix from $2,3002026-07-14 MEDIUM 5.2 CVE-2026-14852 Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows a local unprivile… Mitigation only Fix from $1,6002026-07-14