VulnSea

CWE-77

CVEs classified under CWE-77, newest first.

235 CVEsRSS

CVE-2026-90843High· 8.3PoC
6d ago

A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25

A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler. Such manipul…

MidnightSabyasachiRana · WebMapEPSS 1.4%via NVD
CVE-2026-90704Medium· 6.6PoC
1w ago

A vulnerability was found in D-Link DWR-M921 1.1.52

A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitatio…

TwilightD-Link · DWR-M921EPSS 1.5%via NVD
CVE-2026-90703Critical· 9.1PoC
1w ago

A vulnerability has been found in D-Link DWR-M921 1.1.52

A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be …

AbyssalD-Link · DWR-M921EPSS 2.8%via NVD
CVE-2026-90621Medium· 6.3PoC
1w ago

A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0

A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the file src/hackingBuddyGPT/extensions/ssh_run_command.py. Such manipulation leads to os command injection. The attack c…

Twilightipa-lab · HackingBuddyGPTEPSS 1.1%via NVD
CVE-2026-90619High· 7.3
1w ago

A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04

A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute Endpoint. The manipulation of the argument code…

Twilight0x4m4 · HexStrike AIEPSS 1.4%via NVD
CVE-2026-90618High· 7.3PoC
1w ago

A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2

A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. Executing a manipu…

MidnightGH05TCREW · PentestAgentEPSS 1.6%via NVD
CVE-2026-90617High· 7.3PoC
1w ago

A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2

A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerability affects the function run_task of the file interface/main.py of the component MCP HTTP Server. Performing a manipula…

MidnightGH05TCREW · PentestAgentEPSS 1.6%via NVD
CVE-2026-90702Critical· 9.1PoC
1w ago

A flaw has been found in D-Link DWR-M921 1.1.52

A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The explo…

AbyssalD-Link · DWR-M921EPSS 2.8%via NVD
CVE-2026-90690High· 7.3PoC
1w ago

A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04

A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the component API Tools Endpoint. Executing a m…

Midnight0x4m4 · HexStrike AIEPSS 1.4%via NVD
CVE-2026-90705Medium· 6.6PoC
1w ago

A vulnerability was determined in D-Link DWR-M921 1.1.52

A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command inj…

TwilightD-Link · DWR-M921EPSS 1.5%via NVD
CVE-2026-90699Critical· 9.9PoC
1w ago

A weakness has been identified in D-Link DWR-M920 1.1.7

A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated…

AbyssalD-Link · DWR-M920EPSS 1.6%via NVD
CVE-2026-90788Medium· 4.7PoC
1w ago

A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055

A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown functionality of the file /admin1.php/admin/template/index/path/.%40template%40default%40html%40label.html of the com…

Twilightmagicblack · MacCMS10EPSS 1.6%via NVD
CVE-2026-90706Medium· 6.6PoC
1w ago

A vulnerability was identified in D-Link DWR-M921 1.1.52

A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc. The manipulation of the argument targetAPSsid leads to os command injection. The attack is possible to be carried ou…

TwilightD-Link · DWR-M921EPSS 1.5%via NVD
CVE-2026-57130High· 8.1PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteri…

MidnightMervinPraison · praisonaiagentsEPSS 0.35%via NVD
CVE-2026-90492Medium· 6.3
1w ago

A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0

A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function controller_listen/controller_recover of the file py/web.py. The manipulation of the argument case_name leads to os com…

Sunlitwebgjc · web_robotEPSS 1.5%via NVD
CVE-2026-81048Critical· 9.6
1w ago

Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability

Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially expl…

Midnightdell · thinosEPSS 1.2%via NVD
CVE-2026-78493Medium· 5.5
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low pr…

Sunlitdell · secure_connect_gatewayEPSS 1.8%via NVD
CVE-2026-79941Medium· 5.3
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthentica…

Sunlitdell · secure_connect_gatewayEPSS 1.9%via NVD
CVE-2026-79945Medium· 5.5
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low pr…

Sunlitdell · secure_connect_gatewayEPSS 1.7%via NVD
CVE-2026-79741Medium· 5.3
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthentica…

SunlitDell · Secure Connect Gateway 5.0 - ApplicationEPSS 1.5%via CVEORG
CVE-2026-78484Medium· 5.5
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low pr…

SunlitDell · Secure Connect Gateway 5.0 - ApplicationEPSS 1.8%via CVEORG
CVE-2026-83948High· 8.0
1w ago

Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network.

Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network.

Twilightmicrosoft · vm_repairEPSS 0.42%via NVD
CVE-2026-81380Medium· 5.3
1w ago

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · Visual Studio CodeEPSS 0.63%via NVD
CVE-2026-69534High· 7.8
1w ago

Improper neutralization of special elements used in a command ('command injection') in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

Improper neutralization of special elements used in a command ('command injection') in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.62%via NVD
CVE-2026-84387High· 7.2
1w ago

A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthor…

A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthor…

TwilightFortinet · FortiSandboxEPSS 0.88%via NVD
CVE-2026-86427High· 8.8
2w ago

LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments by breaking out of double-quote escaping

LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments by breaking out of double-quote escaping. Attackers can inject DEF…

Twilightlibrenms · librenmsEPSS 0.33%via NVD
CVE-2026-86299Critical· 9.9PoC
2w ago

A vulnerability was detected in Linksys RE7000 2.0.15

A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSiz…

AbyssalLinksys · RE7000EPSS 2.0%via NVD
CVE-2026-86295High· 8.3PoC
2w ago

A vulnerability was found in D-Link DIR-895L A1_102b07

A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can…

MidnightD-Link · DIR-895LEPSS 1.7%via NVD
CVE-2026-79698Critical· 9.9PoC
2w ago

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

AbyssalAdvantech · WISE-6610-NBEPSS 1.7%via NVD
CVE-2026-79697Critical· 9.9PoC
2w ago

A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

AbyssalAdvantech · WISE-6610-NBEPSS 3.4%via NVD
CWE-77 vulnerabilities (CVEs) — page 2 · VulnSea