Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-78 Clear
ID Title
CVE-2026-8665 OS Command Injection in rapid7 (CVE-2026-8665)
OS command injection in rapid7 (CVE-2026-8665). Confidential information can be exposed externally.
CVE-2026-8664 OS Command Injection in rapid7 (CVE-2026-8664)
OS command injection in rapid7 (CVE-2026-8664). Data can be tampered with by attackers.
CVE-2026-8592 OS Command Injection in rapid7 (CVE-2026-8592)
OS command injection in rapid7 (CVE-2026-8592). Confidential information can be exposed externally.
CVE-2026-9155 OS Command Injection in gnu (CVE-2026-9155)
OS command injection in gnu (CVE-2026-9155). Successful exploitation can lead to full system takeover.
CVE-2026-9787 OS Command Injection in quest (CVE-2026-9787)
OS command injection in quest (CVE-2026-9787). Successful exploitation can lead to full system takeover.
CVE-2026-8659 OS Command Injection in rapid7 (CVE-2026-8659)
OS command injection in rapid7 (CVE-2026-8659). Data can be tampered with by attackers.
CVE-2026-9772 OS Command Injection in unraid (CVE-2026-9772)
OS command injection in unraid (CVE-2026-9772). Successful exploitation can lead to full system takeover.
CVE-2026-8663 OS Command Injection in rapid7 (CVE-2026-8663)
OS command injection in rapid7 (CVE-2026-8663). Data can be tampered with by attackers.
CVE-2026-9773 OS Command Injection in unraid (CVE-2026-9773)
OS command injection in unraid (CVE-2026-9773). Successful exploitation can lead to full system takeover.
CVE-2026-40079 OS Command Injection in cacti (CVE-2026-40079)
OS command injection in cacti (CVE-2026-40079). Successful exploitation can lead to full system takeover.
CVE-2026-39938 Path Traversal in cacti (CVE-2026-39938)
path traversal in cacti (CVE-2026-39938). Successful exploitation can lead to full system takeover.
CVE-2026-54686 OS Command Injection in CVE-2026-54686 (CVE-2026-54686)
OS command injection in CVE-2026-54686 (CVE-2026-54686). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.2026.05.06.15.42.stable` or later.
CVE-2026-54699 OS Command Injection in CVE-2026-54699 (CVE-2026-54699)
OS command injection in CVE-2026-54699 (CVE-2026-54699). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.2026.05.06.15.42.stable` or later.
CVE-2026-48731 OS Command Injection in CVE-2026-48731 (CVE-2026-48731)
OS command injection in CVE-2026-48731 (CVE-2026-48731). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.2026.05.06.15.42.stable` or later.
CVE-2026-48732 OS Command Injection in CVE-2026-48732 (CVE-2026-48732)
OS command injection in CVE-2026-48732 (CVE-2026-48732). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.2026.05.06.15.42.stable` or later.
CVE-2026-48719 OS Command Injection in CVE-2026-48719 (CVE-2026-48719)
OS command injection in CVE-2026-48719 (CVE-2026-48719). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.2026.05.06.15.42.stable` or later.
CVE-2026-48703 OS Command Injection in CVE-2026-48703 (CVE-2026-48703)
OS command injection in CVE-2026-48703 (CVE-2026-48703). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.2026.05.06.15.42.stable` or later.
CVE-2026-57282 OS Command Injection in jenkins (CVE-2026-57282)
OS command injection in jenkins (CVE-2026-57282). Risk of unauthorized operations or information disclosure.
CVE-2026-12537 Vulnerability in google (CVE-2026-12537)
vulnerability in google (CVE-2026-12537). Successful exploitation can lead to full system takeover.
CVE-2026-12851 OS Command Injection in CVE-2026-12851 (CVE-2026-12851)
OS command injection in CVE-2026-12851 (CVE-2026-12851). Successful exploitation can lead to full system takeover. Exploitable via ``libNetSetObj.so``.
CVE-2026-12850 OS Command Injection in CVE-2026-12850 (CVE-2026-12850)
OS command injection in CVE-2026-12850 (CVE-2026-12850). Successful exploitation can lead to full system takeover. Exploitable via ``libNetSetObj.so``.
CVE-2026-12849 OS Command Injection in CVE-2026-12849 (CVE-2026-12849)
OS command injection in CVE-2026-12849 (CVE-2026-12849). Successful exploitation can lead to full system takeover. Exploitable via ``libNetSetObj.so``.
CVE-2026-12486 OS Command Injection in CVE-2026-12486 (CVE-2026-12486)
OS command injection in CVE-2026-12486 (CVE-2026-12486). Successful exploitation can lead to full system takeover. Exploitable via ``libNetSetObj.so``.
CVE-2026-55249 OS Command Injection in c (CVE-2026-55249)
OS command injection in c (CVE-2026-55249). Confidential information can be exposed externally.
CVE-2026-55448 OS Command Injection in mise (CVE-2026-55448)
OS command injection in mise (CVE-2026-55448). Confidential information can be exposed externally. Exploitable via ``mise``. Mitigation: upgrade to `2026.6.4` or later.
CVE-2026-55441 Vulnerability in mise (CVE-2026-55441)
vulnerability in mise (CVE-2026-55441). Successful exploitation can lead to full system takeover. Exploitable via ``mise.toml``. Mitigation: upgrade to `2026.6.4` or later.
CVE-2026-55173 OS Command Injection in wwbn/avideo (CVE-2026-55173)
OS command injection in wwbn/avideo (CVE-2026-55173). Successful exploitation can lead to full system takeover. Exploitable via ``sanitizeFFmpegCommand``.
CVE-2026-35018 OS Command Injection in CVE-2026-35018 (CVE-2026-35018)
OS command injection in CVE-2026-35018 (CVE-2026-35018). Successful exploitation can lead to full system takeover.
CVE-2026-56379 Vulnerability in imagemagick (CVE-2026-56379)
vulnerability in imagemagick (CVE-2026-56379). Successful exploitation can lead to full system takeover.
CVE-2026-56274 OS Command Injection in flowiseai (CVE-2026-56274)
OS command injection in flowiseai (CVE-2026-56274). Successful exploitation can lead to full system takeover.
CVE-2025-67038 KEV An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell...
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell...
CVE-2026-11834 OS Command Injection in CVE-2026-11834 (CVE-2026-11834)
OS command injection in CVE-2026-11834 (CVE-2026-11834). Risk of unauthorized operations or information disclosure.
CVE-2026-46606 OS Command Injection in glances (CVE-2026-46606)
OS command injection in glances (CVE-2026-46606). Successful exploitation can lead to full system takeover. Exploitable via ``domain``. Mitigation: upgrade to `4.5.5` or later.
CVE-2026-12815 Command Injection in CVE-2026-12815 (CVE-2026-12815)
command injection in CVE-2026-12815 (CVE-2026-12815). Risk of unauthorized operations or information disclosure.
CVE-2026-12814 Command Injection in CVE-2026-12814 (CVE-2026-12814)
command injection in CVE-2026-12814 (CVE-2026-12814). Risk of unauthorized operations or information disclosure.
CVE-2026-55849 OS Command Injection in @cyclonedx/cyclonedx-npm (CVE-2026-55849)
OS command injection in @cyclonedx/cyclonedx-npm (CVE-2026-55849). Risk of unauthorized operations or information disclosure. Exploitable via ``npm_execpath``. Mitigation: upgrade to `5.0.0` or later.
CVE-2026-48787 OS Command Injection in vue (CVE-2026-48787)
OS command injection in vue (CVE-2026-48787). Risk of unauthorized operations or information disclosure. Exploitable via `POST /autoCode/addFunc`.
CVE-2026-49260 OS Command Injection in pontedilana/php-weasyprint (CVE-2026-49260)
OS command injection in pontedilana/php-weasyprint (CVE-2026-49260). Successful exploitation can lead to full system takeover. Exploitable via ``master``. Mitigation: upgrade to `2.5.1` or later.
CVE-2026-12104 OS Command Injection in CVE-2026-12104 (CVE-2026-12104)
OS command injection in CVE-2026-12104 (CVE-2026-12104). Risk of unauthorized operations or information disclosure.
CVE-2026-54051 OS Command Injection in network-ai (CVE-2026-54051)
OS command injection in network-ai (CVE-2026-54051). Successful exploitation can lead to full system takeover. Exploitable via ``SandboxPolicy.isCommandAllowed``. Mitigation: upgrade to `5.9.1` or later.
CVE-2026-40456 OS Command Injection in CVE-2026-40456 (CVE-2026-40456)
OS command injection in CVE-2026-40456 (CVE-2026-40456). Risk of unauthorized operations or information disclosure.
CVE-2026-48997 OS Command Injection in c (CVE-2026-48997)
OS command injection in c (CVE-2026-48997). Data can be tampered with by attackers.
CVE-2026-20266 OS Command Injection in splunk (CVE-2026-20266)
OS command injection in splunk (CVE-2026-20266). Successful exploitation can lead to full system takeover.
CVE-2026-55743 OS Command Injection in CVE-2026-55743 (CVE-2026-55743)
OS command injection in CVE-2026-55743 (CVE-2026-55743). Successful exploitation can lead to full system takeover.
CVE-2026-55748 OS Command Injection in horizon (CVE-2026-55748)
OS command injection in horizon (CVE-2026-55748). Confidential information can be exposed externally.
CVE-2026-53876 OS Command Injection in CVE-2026-53876 (CVE-2026-53876)
OS command injection in CVE-2026-53876 (CVE-2026-53876). Successful exploitation can lead to full system takeover.
CVE-2026-11409 OS Command Injection in tp-link (CVE-2026-11409)
OS command injection in tp-link (CVE-2026-11409). Successful exploitation can lead to full system takeover.
CVE-2026-11410 OS Command Injection in tp-link (CVE-2026-11410)
OS command injection in tp-link (CVE-2026-11410). Successful exploitation can lead to full system takeover.
CVE-2026-49980 Vulnerability in github.com/rclone/rclone (CVE-2026-49980)
vulnerability in github.com/rclone/rclone (CVE-2026-49980). Successful exploitation can lead to full system takeover. Exploitable via ``GET``. Mitigation: upgrade to `1.74.3` or later.
CVE-2026-22313 OS Command Injection in CVE-2026-22313 (CVE-2026-22313)
OS command injection in CVE-2026-22313 (CVE-2026-22313). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →