Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-22313 |
|
OS Command Injection in CVE-2026-22313 (CVE-2026-22313)
OS command injection in CVE-2026-22313 (CVE-2026-22313). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49402 |
|
OS Command Injection in deno (CVE-2026-49402)
OS command injection in deno (CVE-2026-49402). Successful exploitation can lead to full system takeover. Exploitable via ``spawn``. Mitigation: upgrade to `2.7.10` or later.
|
| CVE-2026-44932 |
|
OS Command Injection in CVE-2026-44932 (CVE-2026-44932)
OS command injection in CVE-2026-44932 (CVE-2026-44932). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12398 |
|
OS Command Injection in galaxy-ng (CVE-2026-12398)
OS command injection in galaxy-ng (CVE-2026-12398). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5416 |
|
OS Command Injection in CVE-2026-5416 (CVE-2026-5416)
OS command injection in CVE-2026-5416 (CVE-2026-5416). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12161 |
|
OS Command Injection in devolutions (CVE-2026-12161)
OS command injection in devolutions (CVE-2026-12161). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48723 |
|
OS Command Injection in CVE-2026-48723 (CVE-2026-48723)
OS command injection in CVE-2026-48723 (CVE-2026-48723). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50874 |
|
OS Command Injection in CVE-2026-50874 (CVE-2026-50874)
OS command injection in CVE-2026-50874 (CVE-2026-50874). Confidential information can be exposed externally.
|
| CVE-2026-38065 |
|
OS Command Injection in CVE-2026-38065 (CVE-2026-38065)
OS command injection in CVE-2026-38065 (CVE-2026-38065). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38060 |
|
OS Command Injection in CVE-2026-38060 (CVE-2026-38060)
OS command injection in CVE-2026-38060 (CVE-2026-38060). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38061 |
|
OS Command Injection in CVE-2026-38061 (CVE-2026-38061)
OS command injection in CVE-2026-38061 (CVE-2026-38061). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38062 |
|
OS Command Injection in CVE-2026-38062 (CVE-2026-38062)
OS command injection in CVE-2026-38062 (CVE-2026-38062). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38063 |
|
OS Command Injection in CVE-2026-38063 (CVE-2026-38063)
OS command injection in CVE-2026-38063 (CVE-2026-38063). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38064 |
|
OS Command Injection in CVE-2026-38064 (CVE-2026-38064)
OS command injection in CVE-2026-38064 (CVE-2026-38064). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9862 |
|
OS Command Injection in forta (CVE-2026-9862)
OS command injection in forta (CVE-2026-9862). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9863 |
|
OS Command Injection in forta (CVE-2026-9863)
OS command injection in forta (CVE-2026-9863). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11526 |
|
Vulnerability in CVE-2026-11526 (CVE-2026-11526)
vulnerability in CVE-2026-11526 (CVE-2026-11526). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11527 |
|
Vulnerability in CVE-2026-11527 (CVE-2026-11527)
vulnerability in CVE-2026-11527 (CVE-2026-11527). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48163 |
|
OS Command Injection in mariadb (CVE-2026-48163)
OS command injection in mariadb (CVE-2026-48163). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48165 |
|
OS Command Injection in mariadb (CVE-2026-48165)
OS command injection in mariadb (CVE-2026-48165). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44168 |
|
OS Command Injection in mariadb (CVE-2026-44168)
OS command injection in mariadb (CVE-2026-44168). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44170 |
|
OS Command Injection in mariadb (CVE-2026-44170)
OS command injection in mariadb (CVE-2026-44170). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11845 |
|
OS Command Injection in CVE-2026-11845 (CVE-2026-11845)
OS command injection in CVE-2026-11845 (CVE-2026-11845). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42846 |
|
OS Command Injection in CVE-2026-42846 (CVE-2026-42846)
OS command injection in CVE-2026-42846 (CVE-2026-42846). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45172 |
|
OS Command Injection in paloaltonetworks (CVE-2026-45172)
OS command injection in paloaltonetworks (CVE-2026-45172). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48547 |
|
OS Command Injection in CVE-2026-48547 (CVE-2026-48547)
OS command injection in CVE-2026-48547 (CVE-2026-48547). Confidential information can be exposed externally.
|
| CVE-2026-49261 |
|
OS Command Injection in mariadb (CVE-2026-49261)
OS command injection in mariadb (CVE-2026-49261). Successful exploitation can lead to full system takeover. Exploitable via ``wsrep_notify_cmd``. Mitigation: upgrade to `10.6.27` or later.
|
| CVE-2026-49219 |
|
Information Disclosure in Magick.NET-Q16-AnyCPU (CVE-2026-49219)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-49219). Confidential information can be exposed externally. Mitigation: upgrade to `14.14.0` or later.
|
| CVE-2026-0273 |
|
OS Command Injection in paloaltonetworks (CVE-2026-0273)
OS command injection in paloaltonetworks (CVE-2026-0273). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6893 |
|
OS Command Injection in CVE-2026-6893 (CVE-2026-6893)
OS command injection in CVE-2026-6893 (CVE-2026-6893). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47751 |
|
OS Command Injection in anthropics/claude-code-action (CVE-2026-47751)
OS command injection in anthropics/claude-code-action (CVE-2026-47751). Risk of unauthorized operations or information disclosure. Exploitable via ``enableAllProjectMcpServers``. Mitigation: upgrade to `1.0.74` or later.
|
| CVE-2026-9151 |
|
OS Command Injection in CVE-2026-9151 (CVE-2026-9151)
OS command injection in CVE-2026-9151 (CVE-2026-9151). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11417 |
|
OS Command Injection in aws-cdk-lib (CVE-2026-11417)
OS command injection in aws-cdk-lib (CVE-2026-11417). Successful exploitation can lead to full system takeover. Exploitable via ``NodejsFunction``. Mitigation: upgrade to `2.246.0` or later.
|
| CVE-2026-45564 |
|
OS Command Injection in c (CVE-2026-45564)
OS command injection in c (CVE-2026-45564). Successful exploitation can lead to full system takeover. Exploitable via `POST /config/versions/`.
|
| CVE-2026-45556 |
|
Vulnerability in nginx (CVE-2026-45556)
vulnerability in nginx (CVE-2026-45556). Successful exploitation can lead to full system takeover. Exploitable via `POST /waf/`.
|
| CVE-2026-45558 |
|
Vulnerability in c (CVE-2026-45558)
vulnerability in c (CVE-2026-45558). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/service/haproxy/`.
|
| CVE-2026-24719 |
|
OS Command Injection in qnap (CVE-2026-24719)
OS command injection in qnap (CVE-2026-24719). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22893 |
|
OS Command Injection in qnap (CVE-2026-22893)
OS command injection in qnap (CVE-2026-22893). Successful exploitation can lead to full system takeover.
|
| CVE-2025-66279 |
|
OS Command Injection in qnap (CVE-2025-66279)
OS command injection in qnap (CVE-2025-66279). Successful exploitation can lead to full system takeover.
|
| CVE-2025-66273 |
|
OS Command Injection in qnap (CVE-2025-66273)
OS command injection in qnap (CVE-2025-66273). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48030 |
|
OS Command Injection in pheditor/pheditor (CVE-2026-48030)
OS command injection in pheditor/pheditor (CVE-2026-48030). Successful exploitation can lead to full system takeover. Exploitable via ``command``. Mitigation: upgrade to `2.0.4` or later.
|
| CVE-2026-38615 |
|
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
|
| CVE-2026-49959 |
|
OS Command Injection in CVE-2026-49959 (CVE-2026-49959)
OS command injection in CVE-2026-49959 (CVE-2026-49959). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25089 KEV |
|
[KEV] OS Command Injection in Fortinet fortisandbox (CVE-2026-25089)
OS command injection in Fortinet fortisandbox (CVE-2026-25089). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-10520 KEV |
|
[KEV] OS Command Injection in Ivanti standalone-sentry (CVE-2026-10520)
OS command injection in Ivanti standalone-sentry (CVE-2026-10520). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-10727 |
|
OS Command Injection in CVE-2026-10727 (CVE-2026-10727)
OS command injection in CVE-2026-10727 (CVE-2026-10727). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9277 |
|
Command Injection in shell-quote (CVE-2026-9277)
command injection in shell-quote (CVE-2026-9277). Successful exploitation can lead to full system takeover. Exploitable via ``envFn``. Mitigation: upgrade to `1.8.4` or later.
|
| CVE-2026-9279 |
|
OS Command Injection in CVE-2026-9279 (CVE-2026-9279)
OS command injection in CVE-2026-9279 (CVE-2026-9279). Risk of unauthorized operations or information disclosure. Exploitable via ``git``.
|
| CVE-2026-46746 |
|
OS Command Injection in siemens (CVE-2026-46746)
OS command injection in siemens (CVE-2026-46746). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11572 |
|
Command Injection in degit (CVE-2026-11572)
command injection in degit (CVE-2026-11572). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.3.1` or later.
|