78 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-12940 | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable | CRITICAL | 9.8 | 39%ile | NVD | 2026-07-30 |
| CVE-2026-12943 | IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power en | CRITICAL | 9.8 | 57%ile | NVD | 2026-07-30 |
| CVE-2026-38709 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2 | CRITICAL | 9.8 | 84%ile | NVD | 2026-07-30 |
| CVE-2026-38711 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2 | CRITICAL | 9.8 | 84%ile | NVD | 2026-07-31 |
| CVE-2026-38708 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2 | CRITICAL | 9.8 | 84%ile | NVD | 2026-07-31 |
| CVE-2026-38713 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2 | CRITICAL | 9.8 | 84%ile | NVD | 2026-07-31 |
| CVE-2024-3566 | Command injection vulnerability in programing languages on Microsoft Windows operating system. | CRITICAL | 9.8 | 93%ile | Microsoft | 2024-04-09 |
| CVE-2026-17566 | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query in | CRITICAL | 9.4 | 35%ile | NVD | 2026-07-31 |
| CVE-2024-1874 | Command injection via array-ish $command parameter of proc_open() | CRITICAL | 9.4 | 98%ile | Microsoft | 2024-04-09 |
| CVE-2026-67308 | Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execut | CRITICAL | 9.3 | 37%ile | NVD | 2026-08-01 |
| CVE-2026-67324 | GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value> | CRITICAL | 9.3 | 31%ile | NVD | 2026-08-01 |
| CVE-2026-61515 | Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allo | CRITICAL | 9.3 | — | NVD | 2026-08-04 |
| CVE-2026-14958 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to | CRITICAL | 9.1 | 41%ile | NVD | 2026-07-28 |
| CVE-2026-14959 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to | CRITICAL | 9.1 | 61%ile | NVD | 2026-07-28 |
| CVE-2026-8450 | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file() | CRITICAL | 9.1 | 70%ile | Microsoft | 2026-05-12 |
| CVE-2026-18601 | A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the fi | HIGH | 8.9 | 82%ile | NVD | 2026-08-03 |
| CVE-2026-18602 | A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_conf | HIGH | 8.9 | 79%ile | NVD | 2026-08-03 |
| CVE-2026-18612 | A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/p | HIGH | 8.9 | 80%ile | NVD | 2026-08-03 |
| CVE-2026-18614 | A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file | HIGH | 8.9 | 79%ile | NVD | 2026-08-03 |
| CVE-2026-18615 | A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate | HIGH | 8.9 | 79%ile | NVD | 2026-08-03 |
| CVE-2026-18616 | A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of | HIGH | 8.9 | 79%ile | NVD | 2026-08-03 |
| CVE-2026-18684 | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the f | HIGH | 8.9 | 79%ile | NVD | 2026-08-03 |
| CVE-2026-18685 | A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the | HIGH | 8.9 | 79%ile | NVD | 2026-08-04 |
| CVE-2026-18686 | A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of | HIGH | 8.9 | 84%ile | NVD | 2026-08-04 |
| CVE-2026-44098 | This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to p | HIGH | 8.8 | 69%ile | NVD | 2026-07-30 |
| CVE-2026-22622 | Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could al | HIGH | 8.8 | 23%ile | NVD | 2026-07-30 |
| CVE-2026-14522 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to e | HIGH | 8.8 | 40%ile | NVD | 2026-07-30 |
| CVE-2026-6893 | Dracut: dracut: root code execution via dhcp options command injection | HIGH | 8.8 | 62%ile | Microsoft | 2026-06-09 |
| CVE-2026-67325 | GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option p | HIGH | 8.7 | 71%ile | NVD | 2026-08-01 |
| CVE-2026-69096 | OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after | HIGH | 8.7 | 74%ile | NVD | 2026-08-03 |
| CVE-2026-67323 | GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and g | HIGH | 8.6 | 60%ile | NVD | 2026-08-01 |
| CVE-2026-67608 | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injecti | HIGH | 8.6 | 72%ile | NVD | 2026-08-03 |
| CVE-2026-67599 | ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attacke | HIGH | 8.6 | 78%ile | NVD | 2026-08-03 |
| CVE-2026-44093 | A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user t | HIGH | 8.5 | 14%ile | NVD | 2026-07-30 |
| CVE-2026-44095 | A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to ex | HIGH | 8.5 | 14%ile | NVD | 2026-07-30 |
| CVE-2026-44096 | A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, re | HIGH | 8.5 | 14%ile | NVD | 2026-07-30 |
| CVE-2026-44099 | A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary | HIGH | 8.5 | 14%ile | NVD | 2026-07-30 |
| CVE-2026-44106 | A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to exec | HIGH | 8.5 | 14%ile | NVD | 2026-07-30 |
| CVE-2026-9044 | An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an | HIGH | 8.5 | 59%ile | NVD | 2026-07-31 |
| CVE-2026-22621 | Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could al | HIGH | 8.3 | 45%ile | NVD | 2026-07-30 |
| CVE-2026-16524 | A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.fil | HIGH | 7.8 | 62%ile | NVD | 2026-07-30 |
| CVE-2026-40034 | gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule | HIGH | 7.8 | 28%ile | Microsoft | 2026-05-12 |
| CVE-2022-45639 | OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a cra | HIGH | 7.8 | 91%ile | Microsoft | 2023-01-10 |
| CVE-2026-17347 | The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that | HIGH | 7.7 | 19%ile | NVD | 2026-07-31 |
| CVE-2026-18598 | A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_l | HIGH | 7.4 | 74%ile | NVD | 2026-08-03 |
| CVE-2026-18600 | A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.s | HIGH | 7.4 | 78%ile | NVD | 2026-08-03 |
| CVE-2026-18787 | A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the fi | HIGH | 7.4 | — | NVD | 2026-08-04 |
| CVE-2026-18599 | A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the f | HIGH | 7.3 | 70%ile | NVD | 2026-08-03 |
| CVE-2026-16843 | Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validatio | HIGH | 7.2 | 56%ile | NVD | 2026-07-31 |
| CVE-2026-38710 | TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the system.setclock in | HIGH | 7.2 | 83%ile | NVD | 2026-07-31 |
| CVE-2026-6837 | A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions | HIGH | 7.2 | 58%ile | NVD | 2026-08-04 |
| CVE-2024-3154 | Cri-o: arbitrary command injection via pod annotation | HIGH | 7.2 | 70%ile | Microsoft | 2024-04-09 |
| CVE-2026-56389 | GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of gram | MEDIUM | 6.8 | 5%ile | NVD | 2026-07-29 |
| CVE-2026-18587 | A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component | MEDIUM | 6.8 | 67%ile | NVD | 2026-08-03 |
| CVE-2026-67438 | OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/inte | MEDIUM | 6.6 | 59%ile | NVD | 2026-07-29 |
| CVE-2026-41411 | Vim: Command injection via backtick expansion in tag filenames | MEDIUM | 6.6 | 40%ile | Microsoft | 2026-04-14 |
| CVE-2026-57453 | Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction | MEDIUM | 6.5 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-54753 | `nx graph` dev server permissive CORS policy | MEDIUM | 5.9 | 54%ile | GitHub | 2026-07-31 |
| CVE-2026-18641 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by | MEDIUM | 5.5 | 75%ile | NVD | 2026-08-03 |
| CVE-2026-39881 | Vim Ex command injection in Vims NetBeans integration | MEDIUM | 5.0 | 46%ile | Microsoft | 2026-04-14 |
| CVE-2026-11526 | GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments | MEDIUM | 4.2 | 69%ile | Microsoft | 2026-06-09 |
| CVE-2026-46483 | Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag | LOW | 3.6 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2024-58266 | The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may fa | LOW | 3.2 | 52%ile | Microsoft | 2025-07-08 |
| CVE-2026-18590 | A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file ad | LOW | 2.1 | 62%ile | NVD | 2026-08-03 |
| CVE-2026-51190 | The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spaw | UNKNOWN | — | 39%ile | NVD | 2026-08-03 |
| CVE-2026-52102 | An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to exe | UNKNOWN | — | 46%ile | NVD | 2026-08-03 |
| CVE-2025-29296 | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V | UNKNOWN | — | — | NVD | 2026-08-04 |
| CVE-2026-4786 | Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open() | UNKNOWN | — | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-44656 | Vim: OS Command Injection via 'path' completion | UNKNOWN | — | 57%ile | Microsoft | 2026-05-12 |
| CVE-2026-42257 | net-imap: Command Injection via "raw" arguments to multiple commands | UNKNOWN | — | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-42258 | net-imap: Command Injection via unvalidated Symbol inputs | UNKNOWN | — | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-47242 | Net::IMAP: Command Injection via ID command argument | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |
| CVE-2026-47240 | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument | UNKNOWN | — | 40%ile | Microsoft | 2026-06-09 |
| FG-IR-26-141 | Second-Order OS Command Injection via JSON Input on start vnc feature | UNKNOWN | — | — | Fortinet | 2026-06-09 |
| FG-IR-26-131 | Command injection in CLI | UNKNOWN | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-133 | OS command injection in CLI | UNKNOWN | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-132 | SQL command injection in administrative portal | UNKNOWN | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-100 | OS Command Injection through API endpoint | UNKNOWN | — | — | Fortinet | 2026-04-14 |