VulnSea

CWE-77

CVEs classified under CWE-77, newest first.

235 CVEsRSS

CVE-2026-94139High· 7.4
today

A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656

A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation o…

TwilightChengdu Feiyuxing Technology · Feiyu Star RouterEPSS 1.2%via NVD
CVE-2026-94138Medium· 6.6PoC
today

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation of the argument mac result…

TwilightChengdu Feiyuxing Technology · Feiyu Star RouterEPSS 2.1%via NVD
CVE-2026-94099Critical· 9.9
today

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246

A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results…

MidnightNetcore · NBR200V2EPSS 1.7%via NVD
CVE-2026-94098Critical· 9.1PoC
today

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246

A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING…

AbyssalNetcore · NBR200V2EPSS 2.4%via NVD
CVE-2026-94097Critical· 10.0
today

A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246

A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes co…

MidnightNetcore · NBR200V2EPSS 2.0%via NVD
CVE-2026-94096Critical· 9.9PoC
today

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246

A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4…

AbyssalNetcore · NBR200V2EPSS 1.7%via NVD
CVE-2026-94095Critical· 9.9
today

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the a…

MidnightNetcore · NBR200V2EPSS 1.7%via NVD
CVE-2026-94031Medium· 6.3PoC
yesterday

A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914

A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914. Affected by this issue is the function child_process.exec of the file src/auth/browser.ts of the component nexus_reauth MCP tool. The manipula…

Twilight0-Gaurav-0 · nexus-mcpEPSS 1.1%via NVD
CVE-2026-93966Medium· 4.7
yesterday

A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1

A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this vulnerability is the function paramiko.SSHClient.exec_command of the file backend/ops/host_tasks.py of the component TASK_RUN_COMMAND. Such manipulation of th…

Sunlitaiyiyi121 · SxDevOpsEPSS 1.6%via NVD
CVE-2026-93967Medium· 5.5
yesterday

A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1

A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of the file backend/aiops/services.py of the component Command Handler. Performing a manipulation of the argument command …

Sunlitaiyiyi121 · SxDevOpsEPSS 0.73%via NVD
CVE-2026-93965Medium· 6.6
yesterday

A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1

A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO Server Management. This manipulation of the argument endpoint_or_command caus…

Sunlitaiyiyi121 · SxDevOpsEPSS 1.6%via NVD
CVE-2026-93958Critical· 9.1PoC
yesterday

A vulnerability was found in D-Link R95 BE9500_1.00.16

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack c…

AbyssalD-Link · R95EPSS 2.2%via NVD
CVE-2026-93742Critical· 9.9
2d ago

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be init…

MidnightTotolink · A3002MUEPSS 1.9%via NVD
CVE-2026-93533Medium· 6.3
3d ago

A vulnerability was determined in spatie Scotty up to 1.4.4

A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler…

Sunlitspatie · ScottyEPSS 1.1%via NVD
CVE-2026-88622High· 8.8PoC
3d ago

NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.

NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.

MidnightEPSS 1.1%via NVD
CVE-2026-93371High· 8.3
3d ago

A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4

A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params leads t…

Twilightmarcopiovanello · yt-dlp-web-uiEPSS 1.4%via NVD
CVE-2026-85885Critical· 9.9
4d ago

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

MidnightMicrosoft · Microsoft 365 CopilotEPSS 0.53%via NVD
CVE-2026-78501High· 7.4
4d ago

Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.

Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.

TwilightMicrosoft · Microsoft 365 Copilot's Business ChatEPSS 0.49%via NVD
CVE-2026-55946Medium· 6.1
4d ago

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · Microsoft CopilotEPSS 0.40%via NVD
CVE-2026-54501Critical· 9.4
4d ago

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Cust…

Midnightwebrecorder · browsertrixEPSS 1.2%via NVD
CVE-2026-92993Medium· 6.3
4d ago

A vulnerability was detected in Dromara mayfly-go up to 1.11.5

A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machine Script Feature. The manipulation of …

SunlitDromara · mayfly-goEPSS 1.5%via NVD
CVE-2026-92398Critical· 9.1PoC
5d ago

A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380

A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. Performing a manipulation of the argument Nam…

AbyssalRuijie · RG-EW3000GXEPSS 2.5%via NVD
CVE-2026-20176Critical· 9.1
5d ago

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privilege…

MidnightCisco · Cisco Identity Services Engine SoftwareEPSS 0.78%via NVD
CVE-2026-20325Critical· 9.9
5d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release…

MidnightCisco · Cisco Nexus DashboardEPSS 0.34%via NVD
CVE-2026-92397Critical· 9.1PoC
5d ago

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads t…

AbyssalRuijie · RG-EW3000GXEPSS 2.3%via NVD
CVE-2026-73454High· 8.1
5d ago

On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties

On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties. This may result in the accoun…

TwilightArista Networks · EOSEPSS 0.30%via NVD
CVE-2026-88765High· 8.5
6d ago

GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a…

GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a…

TwilightGitLab · GitLabEPSS 0.72%via NVD
CVE-2026-91853High· 7.4PoC
6d ago

A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224

A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvpn of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user of the component Export Ovpn Handler. The manipulation…

MidnightTOTOLINK · X5000REPSS 1.4%via NVD
CVE-2026-90880High· 7.4PoC
6d ago

A security flaw has been discovered in D-Link DSL-3782 2016-07-28

A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr resul…

MidnightD-Link · DSL-3782EPSS 1.0%via NVD
CVE-2026-90847Critical· 9.1PoC
6d ago

A vulnerability was determined in EFM ipTIME C200E 1.094

A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the at…

AbyssalEFM · ipTIME C200EEPSS 2.2%via NVD
CWE-77 vulnerabilities (CVEs) · VulnSea