125 CVEs — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-85885 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized | CRITICAL | 9.9 | 44%ile | NVD | 2026-09-17 |
| CVE-2026-57124 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect | CRITICAL | 9.8 | 49%ile | NVD | 2026-09-14 |
| CVE-2026-27565 | An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root pr | CRITICAL | 9.8 | 59%ile | NVD | 2026-09-16 |
| CVE-2026-90822 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command i | CRITICAL | 9.8 | 71%ile | NVD | 2026-09-17 |
| CVE-2026-73447 | A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full | CRITICAL | 9.4 | 54%ile | NVD | 2026-09-16 |
| CVE-2026-58146 | WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the | CRITICAL | 9.4 | 81%ile | NVD | 2026-09-16 |
| CVE-2026-54501 | Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through | CRITICAL | 9.4 | 67%ile | NVD | 2026-09-17 |
| CVE-2026-89308 | An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to exec | CRITICAL | 9.3 | 87%ile | NVD | 2026-09-15 |
| CVE-2026-40855 | WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality | CRITICAL | 9.3 | 65%ile | NVD | 2026-09-16 |
| CVE-2026-58147 | WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password cha | CRITICAL | 9.3 | 67%ile | NVD | 2026-09-16 |
| CVE-2026-73172 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command | CRITICAL | 9.3 | 77%ile | NVD | 2026-09-16 |
| CVE-2026-55158 | Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, | CRITICAL | 9.1 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-76675 | A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploi | CRITICAL | 9.1 | 70%ile | NVD | 2026-09-15 |
| CVE-2026-20305 | A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perfor | CRITICAL | 9.1 | 71%ile | NVD | 2026-09-16 |
| CVE-2026-20306 | A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform comman | CRITICAL | 9.1 | 71%ile | NVD | 2026-09-16 |
| CVE-2026-8450 | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file() | CRITICAL | 9.1 | 71%ile | Microsoft | 2026-05-12 |
| CVE-2026-91931 | Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated att | CRITICAL | 9.0 | 49%ile | NVD | 2026-09-15 |
| CVE-2026-16466 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitra | HIGH | 8.8 | 58%ile | NVD | 2026-09-14 |
| CVE-2026-16673 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitra | HIGH | 8.8 | 36%ile | NVD | 2026-09-14 |
| CVE-2026-57133 | PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/t | HIGH | 8.8 | 37%ile | NVD | 2026-09-15 |
| CVE-2026-57136 | PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/s | HIGH | 8.8 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-52484 | An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code | HIGH | 8.8 | 39%ile | NVD | 2026-09-15 |
| CVE-2026-27547 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info | HIGH | 8.8 | 81%ile | NVD | 2026-09-16 |
| CVE-2026-27548 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info | HIGH | 8.8 | 81%ile | NVD | 2026-09-16 |
| CVE-2026-27549 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do | HIGH | 8.8 | 81%ile | NVD | 2026-09-16 |
| CVE-2026-27550 | A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using | HIGH | 8.8 | 81%ile | NVD | 2026-09-16 |
| CVE-2026-27551 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage en | HIGH | 8.8 | 81%ile | NVD | 2026-09-16 |
| CVE-2026-27554 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_paramete | HIGH | 8.8 | 81%ile | NVD | 2026-09-16 |
| CVE-2026-27558 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/aj | HIGH | 8.8 | 81%ile | NVD | 2026-09-16 |
| CVE-2026-27559 | A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sendi | HIGH | 8.8 | 81%ile | NVD | 2026-09-16 |
| CVE-2026-88622 | NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php. | HIGH | 8.8 | — | NVD | 2026-09-18 |
| CVE-2025-14754 | IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on | HIGH | 8.8 | — | NVD | 2026-09-18 |
| CVE-2026-6893 | Dracut: dracut: root code execution via dhcp options command injection | HIGH | 8.8 | 69%ile | Microsoft | 2026-06-09 |
| CVE-2024-5585 | Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix) | HIGH | 8.8 | 98%ile | Microsoft | 2024-06-11 |
| CVE-2026-90444 | A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shel | HIGH | 8.7 | 15%ile | NVD | 2026-09-11 |
| CVE-2026-90770 | Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supp | HIGH | 8.7 | 52%ile | NVD | 2026-09-13 |
| CVE-2026-82762 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 | HIGH | 8.7 | 66%ile | NVD | 2026-09-14 |
| CVE-2026-82766 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If t | HIGH | 8.7 | 66%ile | NVD | 2026-09-14 |
| CVE-2026-82774 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M | HIGH | 8.7 | 66%ile | NVD | 2026-09-14 |
| CVE-2026-82777 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC | HIGH | 8.7 | 66%ile | NVD | 2026-09-14 |
| CVE-2026-82779 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM | HIGH | 8.7 | 62%ile | NVD | 2026-09-14 |
| CVE-2026-82791 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2. | HIGH | 8.7 | 62%ile | NVD | 2026-09-14 |
| CVE-2026-82794 | SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is explo | HIGH | 8.7 | 62%ile | NVD | 2026-09-14 |
| CVE-2026-77853 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 a | HIGH | 8.7 | 62%ile | NVD | 2026-09-15 |
| CVE-2026-92580 | In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClie | HIGH | 8.7 | 64%ile | NVD | 2026-09-16 |
| CVE-2026-81942 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 cont | HIGH | 8.7 | — | NVD | 2026-09-18 |
| CVE-2026-62943 | btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_fil | HIGH | 8.7 | — | NVD | 2026-09-18 |
| CVE-2026-90699 | A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/ | HIGH | 8.6 | 75%ile | NVD | 2026-09-14 |
| CVE-2026-57586 | CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default | HIGH | 8.6 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-73163 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command | HIGH | 8.6 | 59%ile | NVD | 2026-09-16 |
| CVE-2026-73164 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command | HIGH | 8.6 | 59%ile | NVD | 2026-09-16 |
| CVE-2026-73165 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command | HIGH | 8.6 | 60%ile | NVD | 2026-09-16 |
| CVE-2026-73167 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command | HIGH | 8.6 | 60%ile | NVD | 2026-09-16 |
| CVE-2026-73176 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command | HIGH | 8.6 | 60%ile | NVD | 2026-09-16 |
| CVE-2026-90702 | A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. Thi | HIGH | 8.5 | 86%ile | NVD | 2026-09-14 |
| CVE-2026-90703 | A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafr | HIGH | 8.5 | 86%ile | NVD | 2026-09-14 |
| CVE-2026-90847 | A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_se | HIGH | 8.5 | 82%ile | NVD | 2026-09-15 |
| CVE-2026-92397 | A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc | HIGH | 8.5 | 82%ile | NVD | 2026-09-16 |
| CVE-2026-92398 | A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality o | HIGH | 8.5 | 84%ile | NVD | 2026-09-16 |
| CVE-2026-71538 | @cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the Win | HIGH | 8.5 | 4%ile | NVD | 2026-09-17 |
| CVE-2026-91102 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | HIGH | 8.4 | 16%ile | NVD | 2026-09-16 |
| CVE-2026-91936 | Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_di | HIGH | 8.3 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-54182 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha | HIGH | 8.1 | 38%ile | NVD | 2026-09-14 |
| CVE-2026-81476 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Element | HIGH | 8.1 | 68%ile | NVD | 2026-09-17 |
| CVE-2026-53790 | rsync < 3.5.0 Command Injection via Multiple Code Paths | HIGH | 8.1 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-90894 | Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_s | HIGH | 7.8 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-17133 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to ex | HIGH | 7.8 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-79992 | Emacs: local shell command injection through the user field in emacs tramp | HIGH | 7.8 | 3%ile | Microsoft | 2026-08-11 |
| CVE-2026-40034 | gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule | HIGH | 7.8 | 29%ile | Microsoft | 2026-05-12 |
| CVE-2026-84838 | Rpm: command injection in rpmuncompress via unescaped filenames passed to popen() | HIGH | 7.8 | 62%ile | Microsoft | 2026-09-08 |
| CVE-2026-59960 | Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-contro | HIGH | 7.5 | 40%ile | NVD | 2026-09-14 |
| CVE-2026-86108 | Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may al | HIGH | 7.5 | 56%ile | NVD | 2026-09-16 |
| CVE-2026-85756 | SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into | HIGH | 7.5 | 46%ile | NVD | 2026-09-16 |
| CVE-2026-53534 | JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef' | HIGH | 7.5 | 29%ile | NVD | 2026-09-17 |
| CVE-2026-78501 | Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business | HIGH | 7.4 | 41%ile | NVD | 2026-09-17 |
| CVE-2026-85013 | A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named | HIGH | 7.3 | 12%ile | NVD | 2026-09-15 |
| CVE-2026-71179 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used | HIGH | 7.3 | 42%ile | NVD | 2026-09-16 |
| CVE-2026-27560 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by send | HIGH | 7.2 | 82%ile | NVD | 2026-09-16 |
| CVE-2026-27561 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by send | HIGH | 7.2 | 82%ile | NVD | 2026-09-16 |
| CVE-2026-27562 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by send | HIGH | 7.2 | 82%ile | NVD | 2026-09-16 |
| CVE-2026-27563 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by | HIGH | 7.2 | 80%ile | NVD | 2026-09-16 |
| CVE-2026-27564 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by | HIGH | 7.2 | 80%ile | NVD | 2026-09-16 |
| CVE-2026-58502 | githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow r | HIGH | 7.1 | 23%ile | NVD | 2026-09-15 |
| CVE-2026-10144 | Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arbitrary OS commands b | HIGH | 7.1 | 75%ile | NVD | 2026-09-15 |
| CVE-2026-19515 | The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micr | HIGH | 7.0 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-91100 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | MEDIUM | 6.8 | 16%ile | NVD | 2026-09-16 |
| CVE-2026-76698 | A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gate | MEDIUM | 6.5 | 90%ile | NVD | 2026-09-15 |
| CVE-2026-20283 | A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbi | MEDIUM | 6.5 | 37%ile | NVD | 2026-09-16 |
| CVE-2026-57453 | Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction | MEDIUM | 6.5 | 11%ile | Microsoft | 2026-06-09 |
| CVE-2026-14275 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute | MEDIUM | 6.3 | 20%ile | NVD | 2026-09-14 |
| CVE-2026-14276 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute | MEDIUM | 6.3 | 20%ile | NVD | 2026-09-14 |
| CVE-2026-14277 | IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal | MEDIUM | 6.3 | 42%ile | NVD | 2026-09-14 |
| CVE-2026-55946 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut | MEDIUM | 6.1 | 34%ile | NVD | 2026-09-17 |
| CVE-2026-54575 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used ra | MEDIUM | 5.8 | 2%ile | NVD | 2026-09-17 |
| CVE-2026-90617 | A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerabilit | MEDIUM | 5.5 | 75%ile | NVD | 2026-09-14 |
| CVE-2026-90618 | A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the f | MEDIUM | 5.5 | 75%ile | NVD | 2026-09-14 |
| CVE-2026-90619 | A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unkn | MEDIUM | 5.5 | 70%ile | NVD | 2026-09-14 |
| CVE-2026-90690 | A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected elemen | MEDIUM | 5.5 | 70%ile | NVD | 2026-09-14 |
| CVE-2026-90843 | A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This | MEDIUM | 5.5 | 71%ile | NVD | 2026-09-15 |
| CVE-2026-93371 | A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function Ne | MEDIUM | 5.5 | 70%ile | NVD | 2026-09-18 |
| CVE-2026-93533 | A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivi | MEDIUM | 5.3 | — | NVD | 2026-09-18 |
| CVE-2026-20350 | A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticat | MEDIUM | 4.7 | 27%ile | NVD | 2026-09-16 |
| CVE-2026-28417 | Vim has OS Command Injection in netrw | MEDIUM | 4.4 | 66%ile | Microsoft | 2026-02-10 |
| CVE-2026-11526 | GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments | MEDIUM | 4.2 | 70%ile | Microsoft | 2026-06-09 |
| CVE-2026-46483 | Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag | LOW | 3.6 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-35867 | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LI | LOW | 3.1 | 43%ile | NVD | 2026-09-13 |
| CVE-2026-90492 | A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function c | LOW | 2.1 | 73%ile | NVD | 2026-09-13 |
| CVE-2026-90621 | A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the | LOW | 2.1 | 64%ile | NVD | 2026-09-14 |
| CVE-2026-90880 | A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /c | LOW | 2.1 | 63%ile | NVD | 2026-09-15 |
| CVE-2026-91853 | A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvp | LOW | 2.1 | 71%ile | NVD | 2026-09-15 |
| CVE-2026-92993 | A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of | LOW | 2.1 | 72%ile | NVD | 2026-09-17 |
| CVE-2026-90704 | A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/for | LOW | 2.0 | 74%ile | NVD | 2026-09-14 |
| CVE-2026-90705 | A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/forms | LOW | 2.0 | 74%ile | NVD | 2026-09-14 |
| CVE-2026-90706 | A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc. | LOW | 2.0 | 74%ile | NVD | 2026-09-14 |
| CVE-2026-90788 | A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown | LOW | 2.0 | 74%ile | NVD | 2026-09-14 |
| CVE-2026-44656 | Vim: OS Command Injection via 'path' completion | UNKNOWN | — | 59%ile | Microsoft | 2026-05-12 |
| CVE-2026-42257 | net-imap: Command Injection via "raw" arguments to multiple commands | UNKNOWN | — | 37%ile | Microsoft | 2026-05-12 |
| CVE-2026-42258 | net-imap: Command Injection via unvalidated Symbol inputs | UNKNOWN | — | 54%ile | Microsoft | 2026-05-12 |
| CVE-2026-47240 | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument | UNKNOWN | — | 41%ile | Microsoft | 2026-06-09 |
| CVE-2026-47242 | Net::IMAP: Command Injection via ID command argument | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |
| OSS-20260912-2 | [vim-security] Ex Command Injection in sign_jump() in Vim < v9.2.1090 | UNKNOWN | — | — | OSS-Security | 2026-09-12 |
| FG-IR-26-167 | Cron Job Injection in Remote Backup | UNKNOWN | — | — | Fortinet | 2026-09-08 |
| FG-IR-26-141 | Second-Order OS Command Injection via JSON Input on start vnc feature | UNKNOWN | — | — | Fortinet | 2026-06-09 |
| FG-IR-26-131 | Command injection in CLI | UNKNOWN | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-133 | OS command injection in CLI | UNKNOWN | — | — | Fortinet | 2026-05-12 |