VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

727 CVEsRSS

CVE-2026-11417High· 7.3PoC
3mo ago

aws-cdk-lib: OS Command Injection in NodejsFunction Bundling

aws-cdk-lib: OS Command Injection in NodejsFunction Bundling

▾ Midnightaws-cdk-lib · aws-cdk-libEPSS 0.99%via GHSA
CVE-2026-6893High· 7.5
3mo ago

A flaw was found in dracut

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracu…

▾ TwilightRed Hat · dracutEPSS 3.1%via NVD
CVE-2026-42563High· 8.0
3mo ago

dulwich: Dulwich: Arbitrary code execution via malicious Git file paths during merge (CVE-2026-42563)

A flaw was found in Dulwich, a pure-Python implementation of Git file formats and protocols. An attacker can exploit this vulnerability by crafting malicious file paths within an untrusted Git branch. When a victim merges this branch, the …

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2EPSS 0.80%via CSAF
CVE-2026-0273High· 7.2PoC
3mo ago

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have…

▾ Midnightpaloaltonetworks · pan-osEPSS 1.3%via NVD
CVE-2026-47751Medium
3mo ago

Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration

Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration

▾ Sunlitanthropics · anthropics/claude-code-actionEPSS 0.77%via GHSA
CVE-2026-25089Critical· 9.8CISA KEVPoC
3mo ago

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud …

▾ Hadalfortinet · fortisandboxEPSS 76%via NVD
CVE-2026-48030Critical· 9.9PoC
3mo ago

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

▾ Abyssalpheditor · pheditor/pheditorEPSS 7.5%via GHSA
CVE-2026-10805Medium· 6.7
3mo ago

A flaw was found in NetworkManager

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to esca…

▾ SunlitRed Hat · NetworkManagerEPSS 0.17%via NVD
CVE-2026-47294High· 8.0
3mo ago

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · sharepoint_serverEPSS 1.2%via NVD
CVE-2026-45633Critical· 9.9
4mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated an…

▾ MidnightEPSS 1.9%via NVD
CVE-2026-45632Critical· 9.9
4mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belongi…

▾ MidnightEPSS 0.45%via NVD
CVE-2026-45630Critical· 9.0
4mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users to execute arbitrary system commands o…

▾ MidnightEPSS 1.2%via NVD
CVE-2026-45629Critical· 9.9
4mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to execute arbitrary system commands on …

▾ MidnightEPSS 1.3%via NVD
CVE-2026-44604High· 7.0
4mo ago

A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM

A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name int…

▾ TwilightEPSS 0.92%via NVD
CVE-2026-4408Critical· 9.0PoC
4mo ago

A flaw was found in Samba

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution characte…

▾ Abyssalredhat · openshift_container_platformEPSS 1.8%via NVD
CVE-2026-44724High· 7.8
4mo ago

systeminformation is a System and OS information library for node.js

systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name cont…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 1.2%via NVD
CVE-2026-8450Critical· 9.1
4mo ago

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open()

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subpro…

▾ MidnightEPSS 2.6%via NVD
CVE-2026-48695High· 8.1
4mo ago

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs shell comm…

▾ Twilightpavel-odintsov · fastnetmonEPSS 1.7%via NVD
CVE-2026-48687Critical· 9.8
4mo ago

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (lines 117-118) constructs shell command…

▾ Midnightpavel-odintsov · fastnetmonEPSS 2.7%via NVD
CVE-2026-9277High· 8.1PoC
4mo ago

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line term…

▾ MidnightEPSS 0.95%via NVD
CVE-2026-8632High· 7.8
4mo ago

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via operating system command injection.

▾ Twilighthp · linux_imaging_and_printingEPSS 4.6%via NVD
CVE-2026-20206Medium· 6.3
4mo ago

A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process.…

A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process.…

▾ SunlitEPSS 0.42%via NVD
CVE-2026-8603Critical· 9.8
4mo ago

In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.

In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.

▾ Midnightscadabr · scadabrEPSS 2.1%via NVD
CVE-2026-25244Critical· 9.8
4mo ago

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orc…

▾ Midnightopenjsf · webdriverioEPSS 3.3%via NVD
CVE-2025-53680Medium· 6.7
4mo ago

An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.…

An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.…

▾ Sunlitfortinet · fortiapEPSS 0.56%via NVD
CVE-2025-40949Critical· 9.1
4mo ago

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCO…

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCO…

▾ MidnightEPSS 0.67%via NVD
CVE-2025-40947High· 7.5
4mo ago

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCO…

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCO…

▾ TwilightEPSS 0.54%via NVD
CVE-2026-8265Medium· 4.7
4mo ago

A security vulnerability has been detected in Tenda AC6 15.03.06.23

A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file of the file /goform/getLogFile of the component httpd. The manipulation of the argument wans.flag leads to os comman…

▾ Sunlittenda · ac6_firmwareEPSS 8.3%via NVD
CVE-2026-8264Medium· 6.3
4mo ago

A weakness has been identified in Tenda AC6 15.03.06.23

A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan of the file /goform/WifiApScan of the component httpd. Executing a manipulation of the argument wl2g.public.country/wl…

▾ Sunlittenda · ac6_firmwareEPSS 6.5%via NVD
CVE-2026-8263Medium· 4.7
4mo ago

A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01

A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet of the component httpd. Performing a manipulation of the argument mac/ssid results …

▾ Sunlittenda · ac10u_firmwareEPSS 8.7%via NVD
CWE-78 vulnerabilities (CVEs) — page 19 · VulnSea