VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

627 CVEsRSS

CVE-2026-93012None
today

Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe

Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 the envelope sender and every recipi…

Sunlitvia CVEORG
CVE-2026-62182High· 8.8
today

KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.21.0 until 1.21.2, 1.22.2, and 1.23.1, ConfigUpdateJob processing in edge/pkg/taskmanager/actions/config…

Twilightkubeedge · kubeedgevia CVEORG
CVE-2026-62371High· 8.8
today

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actio…

Twilightkubeedge · kubeedgevia NVD
CVE-2026-82412High· 8.8
today

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept the sca…

Twilightntop · ntopngvia NVD
CVE-2026-84285High· 8.8
today

An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server.

An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server.

TwilightDassault Systèmes · Tuleap Enterprise Editionvia NVD
CVE-2026-89139High· 8.7
today

Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Work…

Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Work…

TwilightTemporal Technologies, Inc. · go.temporal.io/servervia NVD
CVE-2026-94106High· 8.8
yesterday

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary comma…

Twilightjames-heinrich · getid3EPSS 1.7%via NVD
CVE-2026-93958Critical· 9.1PoC
yesterday

A vulnerability was found in D-Link R95 BE9500_1.00.16

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack c…

AbyssalD-Link · R95EPSS 2.2%via NVD
CVE-2026-84085High· 8.1
3d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

TwilightIBM · Guardium Data ProtectionEPSS 0.32%via NVD
CVE-2026-17262Medium· 5.4
3d ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands.

SunlitIBM · iEPSS 0.19%via NVD
CVE-2026-81623Medium· 6.3
3d ago

IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileges on the system due to improper validation of user supplied input.

IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileges on the system due to improper validation of user supplied input.

SunlitIBM · Guardium Data ProtectionEPSS 0.26%via NVD
CVE-2026-80442Critical· 9.9
3d ago

IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality

IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact th…

MidnightIBM · Guardium Data ProtectionEPSS 0.63%via NVD
CVE-2026-82887High· 8.8
3d ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

TwilightIBM · Guardium Data ProtectionEPSS 0.41%via NVD
CVE-2026-81669High· 7.2
3d ago

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in c…

TwilightIBM · Guardium Data ProtectionEPSS 1.3%via NVD
CVE-2026-82892High· 8.1
3d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

TwilightIBM · Guardium Data ProtectionEPSS 0.39%via NVD
CVE-2026-81937High· 7.2
3d ago

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potent…

TwilightIBM · Guardium Data ProtectionEPSS 1.5%via NVD
CVE-2026-84071High· 7.2
3d ago

IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality

IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell comman…

TwilightIBM · Guardium Data ProtectionEPSS 1.5%via NVD
CVE-2026-93533Medium· 6.3
3d ago

A vulnerability was determined in spatie Scotty up to 1.4.4

A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler…

Sunlitspatie · ScottyEPSS 1.1%via NVD
CVE-2026-62943High· 8.7
3d ago

btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes

btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filter_btrbk.sh constructs allow_stream_match with a start anchor but without an end-of-string anchor for the complete c…

Twilightdigint · btrbkEPSS 0.29%via NVD
CVE-2026-81942High· 8.8
3d ago

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied input is passed to system() without suffic…

TwilightPLANET Technology Corp. · PLANET IGS-5225-8P2T4S V1EPSS 1.9%via NVD
CVE-2025-14754High· 8.8
3d ago

IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

TwilightIBM · Cloud Pak for DataEPSS 0.65%via NVD
CVE-2026-53534High· 7.5
4d ago

JabRef is a desktop application for managing BibTeX and BibLaTeX libraries

JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef's built-in HTTP server is enabled, the GET /better-bibtex/cayw endpoint accepts an external command query parameter a…

TwilightJabRef · jabrefEPSS 0.35%via NVD
CVE-2026-52483High· 8.8PoC
4d ago

The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authenticated users execute arbitrary OS command via concatenated params on a crafted POST request fo…

The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authenticated users execute arbitrary OS command via concatenated params on a crafted POST request fo…

MidnightEPSS 0.36%via NVD
CVE-2026-54501Critical· 9.4
4d ago

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Cust…

Midnightwebrecorder · browsertrixEPSS 1.2%via NVD
CVE-2026-92993Medium· 6.3
4d ago

A vulnerability was detected in Dromara mayfly-go up to 1.11.5

A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machine Script Feature. The manipulation of …

SunlitDromara · mayfly-goEPSS 1.5%via NVD
CVE-2026-54575Medium· 5.8
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path handling across libmport/fetch.c, libmport/clean.c, libmport/util.c, libmport/bundle_read_install_pkg.c…

SunlitMidnightBSD · mportEPSS 0.12%via NVD
CVE-2026-71538High· 8.5
4d ago

@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects

@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the Windows fallback path in src/npmRunner.ts, used when npm_execpath does not provide the npm CLI path, can construct a she…

TwilightCycloneDX · cyclonedx-node-npmEPSS 0.15%via NVD
CVE-2026-90822Critical· 9.8
4d ago

FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon

FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote attacker with access to the affected manageme…

MidnightFatPipe Networks · MPVPNEPSS 1.4%via NVD
CVE-2026-81476High· 8.1
4d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could …

TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 1.2%via NVD
CVE-2026-92580High· 8.8PoC
5d ago

In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection

In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync…

MidnightWWBN · AVideoEPSS 1.1%via NVD
CWE-78 vulnerabilities (CVEs) · VulnSea