VulnSea

CWE-77

CVEs classified under CWE-77, newest first.

271 CVEsRSS

CVE-2026-8229Medium· 6.3
4mo ago

A vulnerability was detected in Wavlink NU516U1 240425

A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument AuthMethod/EncrypType results in os command injection. Re…

▾ Sunlitwavlink · wl-nu516u1_firmwareEPSS 8.5%via NVD
CVE-2026-8228Medium· 6.3
4mo ago

A security vulnerability has been detected in Wavlink NU516U1 240425

A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/ieee_80211h leads to os command inject…

▾ Sunlitwavlink · wl-nu516u1_firmwareEPSS 8.5%via NVD
CVE-2026-8227Medium· 6.3
4mo ago

A weakness has been identified in Wavlink NU516U1 240425

A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation causes os command injection. The attack may be initiated remotely. The exploit has been m…

▾ Sunlitwavlink · wl-nu516u1_firmwareEPSS 8.5%via NVD
CVE-2026-42258Medium· 5.3
4mo ago

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol a…

▾ SunlitEPSS 1.3%via NVD
CVE-2026-42271High· 8.8CISA KEVPoC
4mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /m…

▾ Abyssallitellm · litellmEPSS 13%via NVD
CVE-2026-20169Medium· 6.4PoC
4mo ago

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router. This vulnerability is…

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router. This vulnerability is…

▾ Twilightcisco · iot_field_network_directorEPSS 0.21%via NVD
CVE-2026-20147Critical· 9.9
5mo ago

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have va…

▾ Midnightcisco · identity_services_engine_passive_identity_connectorEPSS 10%via NVD
CVE-2026-20186Critical· 9.9
5mo ago

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker mus…

▾ Midnightcisco · identity_services_engineEPSS 5.6%via NVD
CVE-2026-23653Medium· 5.7
5mo ago

GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft Visual Studio Code CoPilot Chat ExtensionEPSS 0.74%via CVEORG
CVE-2026-32183High· 7.8
5mo ago

Windows Snipping Tool Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.46%via CVEORG
CVE-2026-4786High· 7.1
5mo ago

Mitgation of CVE-2026-4519 was incomplete

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 fo…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-5833Medium· 5.3
5mo ago

A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1

A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the file index.ts. Such manipulation of the argument Identifier leads to command injection. T…

▾ SunlitEPSS 1.1%via NVD
CVE-2026-5741High· 7.3
5mo ago

A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0

A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_image of the file src/index.ts of the component HTTP Interface. This manipulation causes…

▾ TwilightEPSS 2.1%via NVD
CVE-2026-5692High· 7.3
5mo ago

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os command injection. The attack may be pe…

▾ TwilightEPSS 2.1%via NVD
CVE-2026-5691High· 7.3
5mo ago

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setFirewallType of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument firewallType leads to os command injection. The attack …

▾ TwilightEPSS 2.1%via NVD
CVE-2026-5690High· 7.3
5mo ago

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument enable can lead to os command injection. The att…

▾ TwilightEPSS 2.1%via NVD
CVE-2026-5689High· 7.3
5mo ago

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setNtpCfg of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument tz results in os command injection. Remote …

▾ TwilightEPSS 2.1%via NVD
CVE-2026-5688High· 7.3
5mo ago

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument provider leads to os command injection. The atta…

▾ TwilightEPSS 2.1%via NVD
CVE-2026-5679Medium· 5.5
5mo ago

A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024

A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument stun_pass leads to os command inje…

▾ SunlitEPSS 2.5%via NVD
CVE-2026-5678High· 7.3
5mo ago

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument mode can lead to os command injection…

▾ TwilightEPSS 2.1%via NVD
CVE-2026-5621Medium· 5.3
5mo ago

A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0

A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown functionality of the file src/index.ts of the component HTTP Interface. The manipulation of the argument config_path results …

▾ SunlitEPSS 1.4%via NVD
CVE-2026-5619Medium· 5.3
5mo ago

A flaw has been found in Braffolk mcp-summarization-functions up to 0.1.5

A flaw has been found in Braffolk mcp-summarization-functions up to 0.1.5. This impacts an unknown function of the file src/server/mcp-server.ts of the component summarize_command. Executing a manipulation of the argument command can lea…

▾ SunlitEPSS 1.4%via NVD
CVE-2026-5528Medium· 6.3
5mo ago

A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0

A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command injection. It is possible to launch the atta…

▾ SunlitEPSS 2.4%via NVD
CVE-2026-20096Medium· 6.5
5mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands a…

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands a…

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.72%via NVD
CVE-2026-20095Medium· 6.5
5mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands a…

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands a…

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.93%via NVD
CVE-2026-20094High· 8.8
5mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the r…

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the r…

▾ Twilightcisco · unified_computing_systemEPSS 1.1%via NVD
CVE-2026-30310Critical· 9.8
6mo ago

In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all commands

In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all commands. The description for the former states that commands determined by the model to be safe will be automaticall…

▾ MidnightEPSS 0.97%via NVD
CVE-2026-34243Critical· 9.8PoC
6mo ago

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title)

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell com…

▾ Abyssalnjzjz · wenxianEPSS 2.8%via NVD
CVE-2025-15379Critical· 10.0
6mo ago

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependen…

▾ Midnightlfprojects · mlflowEPSS 2.4%via NVD
CVE-2026-23815High· 7.2
6mo ago

A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection

A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized comma…

▾ Twilighthpe · arubaos-cxEPSS 0.94%via NVD
CWE-77 vulnerabilities (CVEs) — page 7 · VulnSea