VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

727 CVEsRSS

CVE-2026-76228Medium· 6.7
1mo ago

Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injection vulnerability in Gradle Wrapper artifact handling

Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injection vulnerability in Gradle Wrapper artifact handling. When Renovate processes Gradle Wrapper updates, it invokes a …

▾ SunlitEPSS 0.96%via NVD
CVE-2026-76226Medium· 6.3
1mo ago

Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance

Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code by providing malicious dependencies …

▾ SunlitEPSS 0.29%via NVD
CVE-2024-58376High· 8.8
1mo ago

Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands

Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate regist…

▾ TwilightEPSS 2.7%via NVD
CVE-2026-16875High· 7.8
1mo ago

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to shell metacharacter injection.

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to shell metacharacter injection.

▾ Twilightibm · viosEPSS 0.22%via NVD
CVE-2026-16865High· 8.8
1mo ago

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command injection.

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command injection.

▾ Twilightibm · viosEPSS 0.72%via NVD
CVE-2026-16848High· 8.8
1mo ago

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of shell metacharacters in DHCP options.

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of shell metacharacters in DHCP options.

▾ TwilightEPSS 0.50%via NVD
CVE-2026-16844High· 8.8
1mo ago

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

▾ TwilightEPSS 0.50%via NVD
CVE-2026-16842High· 8.8
1mo ago

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

▾ TwilightEPSS 0.50%via NVD
CVE-2026-76220High· 8.8
1mo ago

gitpython: GitPython: Arbitrary command execution via crafted kwargs (CVE-2026-76220)

A flaw was found in GitPython. A remote attacker can bypass the `check_unsafe_options` guard by combining a single-character keyword argument with `split_single_char_options=False`. This allows the attacker to supply a crafted dictionary o…

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.91%via CSAF
CVE-2026-76221High· 8.8
1mo ago

gitpython: GitPython: Arbitrary code execution via config-name injection (CVE-2026-76221)

A flaw was found in GitPython. This vulnerability allows attackers to inject malicious configuration options by manipulating option names within the option-name validator. By injecting special characters, an attacker can forge arbitrary gi…

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.77%via CSAF
CVE-2026-49255High· 8.8
1mo ago

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm constructs operating system commands in src/app/lib/fs.js by interpolating untrusted file paths into the rmrf(), mv(), a…

▾ Twilightelecterm · electermEPSS 0.79%via NVD
CVE-2026-71551High· 7.8
1mo ago

Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities

Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.13.0, the EXEC IPC handler in electron/ipc-handlers/exec.ts accepts a command string from the renderer through the IPC…

▾ TwilightEPSS 0.22%via NVD
CVE-2026-73073High· 7.3
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a tags file,…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.20%via NVD
CVE-2026-68939None
1mo ago

Pyenv provides simple Python version management

Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-vers…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-50187High· 8.8
1mo ago

Oh My Zsh is a community-driven framework for managing Zsh configuration

Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .en…

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.54%via NVD
CVE-2026-52876High· 8.8
1mo ago

Streambert is a cross-platform Electron Desktop App to stream and download video content

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type o…

▾ TwilightEPSS 0.20%via NVD
CVE-2026-53455None
1mo ago

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git credential helper in custom_components/blueprint_studio/backend/git_manager.py by interpo…

▾ SunlitEPSS 0.50%via NVD
GHSA-rghg-q7wp-9767High
1mo ago

MONAI vulnerable to OS command injection

MONAI vulnerable to OS command injection

▾ TwilightMONAI · MONAIvia GHSA
GHSA-jf24-8g2h-2wg7Medium
1mo ago

LibreNMS Vulnerable to Remote Code Execution via AboutController

LibreNMS Vulnerable to Remote Code Execution via AboutController

▾ Sunlitlibrenms · librenms/librenmsvia GHSA
CVE-2026-55426High· 7.8
1mo ago

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. From the earliest affected releases u…

▾ Twilightlinuxfabrik-lib · linuxfabrik-libEPSS 0.21%via NVD
CVE-2026-75056High· 7.8
1mo ago

In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible

In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible

▾ Twilightjetbrains · intellij_ideaEPSS 0.19%via NVD
CVE-2026-71858None
1mo ago

Notepad++ is a free and open-source source code editor

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortcuts.xml bypass the HMAC validation applied to UserDefinedCommands and can invoke Scintilla actions and the internal O…

▾ SunlitEPSS 0.12%via NVD
CVE-2026-74997High· 8.8
1mo ago

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using th…

▾ Twilightroundcube · webmailEPSS 1.1%via NVD
CVE-2026-62982High· 8.8
1mo ago

Glances is an open-source system cross-platform monitoring tool

Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings such as process cmdline values, allowing pipe characters to…

▾ Twilightglances · glancesEPSS 0.20%via NVD
CVE-2026-68519High
1mo ago

Glances is an open-source system cross-platform monitoring tool

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run() in glances/actions.py ignores --disable-config-exec for on-alert action commands and invokes secure_popen() with shell operators enable…

▾ Twilightglances · glancesEPSS 0.18%via NVD
GHSA-fhgh-wq4q-r37xHigh· 7.8
1mo ago

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

▾ Twilightuniget-org · gitlab.com/uniget-org/clivia GHSA
CVE-2026-68518High
1mo ago

Glances is an open-source system cross-platform monitoring tool

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables…

▾ Twilightglances · glancesEPSS 0.17%via NVD
CVE-2026-73680High· 8.8
1mo ago

Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename

Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands by uploading a video file with a shell…

▾ TwilightCockpit HQ · Cockpit CMSEPSS 2.8%via CVEORG
CVE-2026-19188Critical· 10.0
1mo ago

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails …

▾ MidnightEPSS 2.9%via NVD
CVE-2026-55157High· 8.4
1mo ago

Token Optimizer MCP: OS command injection in smart_user via username in get-user-info

Token Optimizer MCP: OS command injection in smart_user via username in get-user-info

▾ Twilightooples · @ooples/token-optimizer-mcpvia GHSA
CWE-78 vulnerabilities (CVEs) — page 11 · VulnSea