VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

627 CVEsRSS

CVE-2026-91100Critical· 9.8⚖ disputed
5d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.25%via NVD
CVE-2026-91102Critical· 9.8⚖ disputed
5d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.25%via NVD
CVE-2026-92398Critical· 9.1PoC
5d ago

A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380

A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. Performing a manipulation of the argument Nam…

AbyssalRuijie · RG-EW3000GXEPSS 2.5%via NVD
CVE-2026-71179High· 7.3
5d ago

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentiall…

Twilightdell · update_package_frameworkEPSS 0.51%via NVD
CVE-2026-85756High· 7.5
5d ago

SSH.NET is a Secure Shell (SSH) library for .NET

SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on the server, and the default RemotePathTransformation.DoubleQuote transformation cannot…

Twilightsshnet · SSH.NETEPSS 0.57%via NVD
CVE-2026-20306Critical· 9.1
5d ago

A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root

A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability,…

MidnightCisco · Cisco Identity Services Engine SoftwareEPSS 1.4%via NVD
CVE-2026-20305Critical· 9.1
5d ago

A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root

A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this v…

MidnightCisco · Cisco Identity Services Engine SoftwareEPSS 1.4%via NVD
CVE-2026-20283Medium· 6.5
5d ago

A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system.  This vulnerability is due to insufficient validation of u…

A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system.  This vulnerability is due to insufficient validation of u…

SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.43%via NVD
CVE-2026-20350Medium· 4.7
5d ago

A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands. This vulnerability is due to improper validatio…

A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands. This vulnerability is due to improper validatio…

SunlitCisco · Cisco ThousandEyes Enterprise AgentEPSS 0.34%via NVD
CVE-2026-92397Critical· 9.1PoC
5d ago

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads t…

AbyssalRuijie · RG-EW3000GXEPSS 2.3%via NVD
CVE-2026-73176High· 8.6
5d ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

TwilightAdvantech · EKI-1242IEIMSEPSS 0.96%via NVD
CVE-2026-73172Critical· 9.3
5d ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01…

MidnightAdvantech · EKI-1242IEIMSEPSS 1.7%via NVD
CVE-2026-73167High· 8.6
5d ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

TwilightAdvantech · EKI-1242IEIMSEPSS 0.96%via NVD
CVE-2026-73165High· 8.6
5d ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

TwilightAdvantech · EKI-1242IEIMSEPSS 0.96%via NVD
CVE-2026-73163High· 8.6
5d ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

TwilightAdvantech · EKI-1242IEIMSEPSS 0.92%via NVD
CVE-2026-73164High· 8.6
5d ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

TwilightAdvantech · EKI-1242IEIMSEPSS 0.92%via NVD
CVE-2026-58146Critical· 9.4
5d ago

WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability

WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter. The cli_cookie parameter value is d…

MidnightWNC · T-Mobile 5G Box IDUEPSS 2.1%via NVD
CVE-2026-40855Critical· 9.3
5d ago

WNC T-Mobile 5G Box IDU router is vulnerable to a command injection

WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameter…

MidnightWNC · T-Mobile 5G Box IDUEPSS 1.1%via NVD
CVE-2026-58147Critical· 9.3
5d ago

WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality

WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdC…

MidnightWNC · T-Mobile 5G Box IDUEPSS 1.2%via NVD
CVE-2026-27565Critical· 9.8
5d ago

An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges

An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.

MidnightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.94%via NVD
CVE-2026-27564High· 7.2
5d ago

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.0%via NVD
CVE-2026-27563High· 7.2
5d ago

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.0%via NVD
CVE-2026-27562High· 7.2
5d ago

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.2%via NVD
CVE-2026-27561High· 7.2
5d ago

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.2%via NVD
CVE-2026-27560High· 7.2
5d ago

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.

A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.2%via NVD
CVE-2026-27559High· 8.8
5d ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.1%via NVD
CVE-2026-27558High· 8.8
5d ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges…

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges…

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.1%via NVD
CVE-2026-27554High· 8.8
5d ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.1%via NVD
CVE-2026-27551High· 8.8
5d ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.1%via NVD
CVE-2026-27550High· 8.8
5d ago

A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.1%via NVD
CWE-78 vulnerabilities (CVEs) — page 2 · VulnSea