VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

727 CVEsRSS

CVE-2026-38820High· 8.3
1mo ago

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.

▾ TwilightEPSS 2.9%via NVD
CVE-2026-37751Critical· 9.8
1mo ago

An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.

An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.

▾ MidnightEPSS 2.9%via NVD
CVE-2026-75486High· 8.0
1mo ago

Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters.<key>.optic…

Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters.<key>.optic…

▾ TwilightEPSS 2.3%via NVD
CVE-2026-75123High· 7.2
1mo ago

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_smtp_test_post handler incorporates a caller-supplied SMTP server value directly into a…

▾ TwilightEPSS 1.5%via NVD
CVE-2026-75122High· 7.2
1mo ago

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi. The certificate password field in a certificate upload request is incorporated into a shell…

▾ TwilightEPSS 0.94%via NVD
CVE-2026-75121High· 7.2
1mo ago

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter int…

▾ TwilightEPSS 1.5%via NVD
CVE-2026-55673High
1mo ago

PowSyBl (Power System Blocks) is a framework to build power system oriented software

PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandExecutor and WindowsLocalCommandExecutor concatenate command arguments and environment variables into strings interpret…

▾ Twilightpowsybl · com.powsybl:powsybl-computation-localEPSS 0.60%via NVD
CVE-2026-81097High· 8.4
1mo ago

The execute_ruby tool is documented as a read-only Ruby sandbox and is enforced by a pattern denylist together with replacements for the process-spawning methods on Kernel

The execute_ruby tool is documented as a read-only Ruby sandbox and is enforced by a pattern denylist together with replacements for the process-spawning methods on Kernel. The pseudo-terminal library's spawn entry points are neither in …

▾ TwilightEPSS 0.24%via NVD
CVE-2026-74233Critical· 9.8
1mo ago

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, an…

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, an…

▾ MidnightEPSS 3.4%via NVD
CVE-2026-57499Critical· 9.1
1mo ago

Liman is open source server management software

Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execute arbitrary operating system commands…

▾ MidnightEPSS 1.4%via NVD
CVE-2026-80214None
1mo ago

LibreNMS’s Virtualization Discovery module is vulnerable to command line injection

LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can execute arbitrary code on the host server.

▾ SunlitEPSS 0.54%via NVD
CVE-2026-79992High· 7.8
1mo ago

Emacs: emacs: command injection via crafted filenames in tramp

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to …

▾ TwilightRed Hat · emacsEPSS 0.20%via CVEORG
CVE-2026-80138Critical· 9.8
1mo ago

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli…

▾ MidnightEPSS 1.2%via NVD
CVE-2026-76197Critical· 10.0
1mo ago

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An …

▾ MidnightEPSS 3.5%via NVD
CVE-2026-76195Critical· 10.0
1mo ago

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An …

▾ MidnightEPSS 3.5%via NVD
CVE-2026-45018Critical· 9.8
1mo ago

Chainlit is a Python framework for building production-ready conversational AI applications

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint wi…

▾ Midnightchainlit · chainlitEPSS 1.1%via NVD
CVE-2026-55582High· 8.4
1mo ago

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShel…

▾ Twilightsonirico · github.com/sonirico/mcp-shellEPSS 0.27%via NVD
CVE-2026-55581High· 8.4
1mo ago

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and ch…

▾ Twilightsonirico · github.com/sonirico/mcp-shellEPSS 0.45%via NVD
CVE-2026-55580High
1mo ago

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-bi…

▾ Twilightsonirico · github.com/sonirico/mcp-shellEPSS 0.20%via NVD
CVE-2026-52490Critical· 9.8⚖ disputed
1mo ago

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c

▾ MidnightRed Hat · Red Hat Enterprise Linux 8EPSS 0.51%via NVD
CVE-2026-57998High· 7.8
1mo ago

better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then pa…

better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then pa…

▾ TwilightEPSS 0.21%via NVD
CVE-2026-41451High· 7.8
1mo ago

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly …

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly …

▾ TwilightEPSS 1.2%via NVD
CVE-2026-41450High· 7.8
1mo ago

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly into command strings via sed without pro…

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly into command strings via sed without pro…

▾ TwilightEPSS 1.1%via NVD
CVE-2026-41449High· 7.8
1mo ago

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data …

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data …

▾ TwilightEPSS 1.0%via NVD
CVE-2026-53804High· 7.2
1mo ago

OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary pat…

OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary pat…

▾ TwilightEPSS 1.5%via NVD
CVE-2026-68560None
1mo ago

Wekan is open source kanban built with Meteor

Wekan is open source kanban built with Meteor. Prior to 9.75, models/fileValidation.js interpolated the uploaded fileObj.path into the administrator-configured externalCommandLine at its {file} placeholder and executed the result through…

▾ SunlitEPSS 0.58%via NVD
CVE-2026-53545Critical· 9.8
1mo ago

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the DELETE /ssh/tunnel/disconnect/:tunnelName teardown path in src/backend/ssh/tunnel.ts interpolates endpointP…

▾ MidnightEPSS 0.73%via NVD
CVE-2026-53542High· 8.8
1mo ago

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the archive creation endpoint in src/backend/ssh/file-manager.ts passes selected file basenames to tar without …

▾ TwilightEPSS 0.66%via NVD
CVE-2026-71961High· 8.8
1mo ago

Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT co…

Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary OS commands with root privileges by sending unsanitized input through the mesh MQTT co…

▾ TwilightEPSS 2.7%via NVD
CVE-2026-75616Medium· 6.8PoC
1mo ago

An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations

An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation…

▾ Twilighttp-link · archer_c20_firmwareEPSS 2.8%via NVD
CWE-78 vulnerabilities (CVEs) — page 10 · VulnSea