VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

727 CVEsRSS

CVE-2026-53975Critical· 9.8
1mo ago

OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verb…

OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verb…

▾ MidnightEPSS 1.7%via NVD
CVE-2026-67434High· 7.8
1mo ago

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgbl…

▾ TwilightRed Hat · squizlabs/php_codesnifferEPSS 1.1%via NVD
CVE-2026-70375High· 8.8
1mo ago

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec, interpolating the configured b…

▾ TwilightEPSS 1.9%via NVD
CVE-2026-70374High· 8.8
1mo ago

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbna…

▾ TwilightEPSS 1.9%via NVD
CVE-2026-71312High· 8.0
1mo ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscap…

▾ Twilightrclone · github.com/rclone/rcloneEPSS 0.49%via NVD
CVE-2026-70611Medium· 6.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather th…

▾ Sunlitelectron · electronEPSS 0.18%via NVD
CVE-2026-67599High· 7.2PoC
1mo ago

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated …

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated …

▾ MidnightEPSS 2.4%via NVD
CVE-2026-69096High· 8.8
1mo ago

OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability

OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus ac…

▾ TwilightEPSS 3.3%via NVD
CVE-2026-67608High· 7.2
1mo ago

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system comman…

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system comman…

▾ TwilightEPSS 2.4%via NVD
CVE-2026-52102Critical· 9.8PoC
1mo ago

An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.

An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.

▾ AbyssalEPSS 2.9%via NVD
CVE-2026-51190Critical· 9.8
1mo ago

The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true

The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL ending in ".git" bypasses the only input check, allowing OS command injection when a user…

▾ MidnightEPSS 1.9%via NVD
CVE-2026-69097High· 7.0
1mo ago

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerou…

▾ Twilightgitpython_project · gitpythonEPSS 0.27%via NVD
GHSA-6r2r-ww24-7h52High· 8.8
1mo ago

Duplicate Advisory: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

Duplicate Advisory: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-cw2r-r7mw-j3hcCritical· 9.8
1mo ago

Duplicate Advisory: GitPython unsafe clone option gate bypass through joined short options

Duplicate Advisory: GitPython unsafe clone option gate bypass through joined short options

▾ Midnightgitpython · gitpythonvia GHSA
CVE-2026-67325High· 8.8
1mo ago

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like uplo…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 2.2%via NVD
CVE-2026-67324Critical· 9.8
1mo ago

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Re…

▾ MidnightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.64%via NVD
CVE-2026-67308Critical· 10.0
1mo ago

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metachar…

▾ MidnightEPSS 0.73%via NVD
CVE-2026-9044High· 8.0
1mo ago

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers

An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN cl…

▾ Twilighttp-link · archer_axe75_firmwareEPSS 2.5%via NVD
CVE-2026-16843High· 7.2
1mo ago

Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation

Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to…

▾ TwilightEPSS 0.92%via NVD
CVE-2026-17566Critical· 9.9PoC
1mo ago

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the…

▾ AbyssalEPSS 0.67%via NVD
CVE-2026-17347High· 7.5
1mo ago

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous…

▾ TwilightEPSS 0.72%via NVD
CVE-2026-44106High· 7.8
1mo ago

A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

▾ TwilightEPSS 0.19%via NVD
CVE-2026-44096High· 7.8
1mo ago

A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.

A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.

▾ TwilightEPSS 0.19%via NVD
CVE-2026-67438Medium· 6.6
1mo ago

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

▾ SunlitOliveTin · github.com/OliveTin/OliveTinEPSS 1.6%via GHSA
CVE-2026-24252High· 7.8
2mo ago

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.

▾ Twilightnvidia · nemoEPSS 1.5%via NVD
CVE-2026-17497High· 8.3
2mo ago

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore in…

▾ TwilightEPSS 0.75%via NVD
CVE-2026-16766None
2mo ago

Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly to the wkhtmltopdf command without sanitization. Any web application that passes user-co…

Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly to the wkhtmltopdf command without sanitization. Any web application that passes user-co…

▾ SunlitEPSS 2.6%via NVD
GHSA-g3hq-hphg-8fhhHigh· 8.8
2mo ago

Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes

Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes

▾ Twilightpheditor · pheditor/pheditorvia GHSA
GHSA-6v4m-fw66-8r4xMedium
2mo ago

Shescape: Path disclosure on Unix with Zsh

Shescape: Path disclosure on Unix with Zsh

▾ Sunlitshescape · shescapevia GHSA
GHSA-w4hw-qcx7-56prCritical
2mo ago

Shescape: Shell injection via unescaped parentheses on Windows with CMD

Shescape: Shell injection via unescaped parentheses on Windows with CMD

▾ Midnightshescape · shescapevia GHSA
CWE-78 vulnerabilities (CVEs) — page 15 · VulnSea