VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

727 CVEsRSS

CVE-2026-56688Critical· 9.1
2mo ago

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exp…

▾ Midnightdell · powerflex_managerEPSS 2.0%via NVD
CVE-2026-54088CriticalPoC
2mo ago

File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)

File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)

▾ Abyssalfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.76%via GHSA
CVE-2026-41857High· 7.8
2mo ago

A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5.

A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5.

▾ Twilightcloudfoundry · bosh_cliEPSS 0.23%via NVD
CVE-2026-0286High· 7.2
2mo ago

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly m…

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly m…

▾ Twilightpaloaltonetworks · pan-osEPSS 1.7%via NVD
CVE-2026-40187High
2mo ago

EGroupware has Authenticated RCE via Malicious eTemplate Upload

EGroupware has Authenticated RCE via Malicious eTemplate Upload

▾ Twilightegroupware · egroupware/egroupwareEPSS 0.86%via GHSA
CVE-2026-55427High· 8.3
2mo ago

Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.47%via GHSA
CVE-2026-55786High· 8.4
2mo ago

flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`

flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`

▾ Twilightflyto-core · flyto-corevia GHSA
CVE-2026-12195None
2mo ago

myVesta is affected by an authenticated remote code execution vulnerability

myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part of the v_ftp_user parameter when deleting FTP usernames. This could result in the execution of comm…

▾ SunlitEPSS 0.66%via NVD
CVE-2026-53478High· 7.2
2mo ago

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neut…

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neut…

▾ TwilightEPSS 2.0%via NVD
CVE-2026-49815High· 7.2
2mo ago

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neut…

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neut…

▾ TwilightEPSS 1.7%via NVD
CVE-2026-49814High· 7.2
2mo ago

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper Neut…

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper Neut…

▾ TwilightEPSS 2.0%via NVD
CVE-2026-49813Medium· 6.7
2mo ago

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neut…

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neut…

▾ SunlitEPSS 0.62%via NVD
CVE-2026-54483Medium· 6.7
2mo ago

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neut…

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neut…

▾ SunlitEPSS 0.62%via NVD
CVE-2026-26355Medium· 6.5
2mo ago

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neut…

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neut…

▾ SunlitEPSS 1.8%via NVD
CVE-2026-58652High· 7.5
2mo ago

luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration

luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration. While the LuCI U…

▾ TwilightEPSS 0.80%via NVD
CVE-2026-59800Critical
2mo ago

9router: Missing Authorization and OS Command Injection

9router: Missing Authorization and OS Command Injection

▾ Midnight9router · 9routerEPSS 2.0%via GHSA
GHSA-g6g7-pvmx-m74pCritical
2mo ago

9router: Missing Authorization and OS Command Injection

9router: Missing Authorization and OS Command Injection

▾ Midnight9router · 9routervia GHSA
GHSA-vv65-f55v-xm6gHigh
2mo ago

Grackle has command/argument injection in the git worktree executor that enables RCE on provisioned hosts via an unsanitized task branch name (shell:true)

Grackle has command/argument injection in the git worktree executor that enables RCE on provisioned hosts via an unsanitized task branch name (shell:true)

▾ Twilightgrackle-ai · @grackle-ai/runtime-sdkvia GHSA
CVE-2026-44454High· 8.1
2mo ago

Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent

Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent

▾ Twilightcoder · github.com/coder/coder/v2EPSS 2.6%via GHSA
GHSA-qh2f-99mv-mrcfMedium
2mo ago

OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn

OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn

▾ Sunlitopenclaw · openclawvia GHSA
CVE-2026-53810High· 8.8
2mo ago

OpenClaw's marketplace runtime extension metadata could point at unscanned payloads

OpenClaw's marketplace runtime extension metadata could point at unscanned payloads

▾ Twilightopenclaw · openclawEPSS 0.62%via GHSA
GHSA-mhq8-78pj-5j79High· 7.1
2mo ago

OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-53488High· 8.8
2mo ago

github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin (CVE-2026-53488)

A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin, which manages container operations, fails to validate labels propagated from an image configuration to a container. This oversi…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.16%via CSAF
CVE-2026-49869Critical· 10.0CISA KEVPoC
3mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Bec…

▾ Hadalkestra · kestraEPSS 2.1%via NVD
CVE-2026-32833High· 8.8
3mo ago

Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the cbid.system.ntp.current P…

Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the cbid.system.ntp.current P…

▾ TwilightEPSS 2.4%via NVD
CVE-2026-54636Critical· 9.0
3mo ago

Dokku is a docker-powered PaaS

Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not lim…

▾ MidnightEPSS 0.53%via NVD
GHSA-5vwr-qchf-q4pfMedium
3mo ago

@cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths

@cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths

▾ Sunlitcyclonedx · @cyclonedx/cdxgenvia GHSA
CVE-2026-49260High· 8.2
3mo ago

php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)

php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)

▾ Twilightpontedilana · pontedilana/php-weasyprintEPSS 0.22%via GHSA
CVE-2026-55697High· 7.5
3mo ago

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

▾ Twilightpnpm · pnpmEPSS 0.19%via GHSA
CVE-2026-49219Medium· 5.5
3mo ago

ImageMagick: Policy Bypass can read disallowed files via symlink

ImageMagick: Policy Bypass can read disallowed files via symlink

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.17%via GHSA
CWE-78 vulnerabilities (CVEs) — page 17 · VulnSea