VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

727 CVEsRSS

CVE-2026-8259Medium· 4.7
4mo ago

A vulnerability has been found in Tenda AC6 2.0/15.03.06.23

A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /goform/telnet of the component httpd. The manipulation of the argument lan.ip leads to os command injection. Remote exp…

▾ Sunlittenda · ac6_firmwareEPSS 8.3%via NVD
CVE-2026-8235Medium· 5.5
4mo ago

A vulnerability was detected in 8421bit MiniClaw 0.8.0/0.9.0

A vulnerability was detected in 8421bit MiniClaw 0.8.0/0.9.0. This issue affects the function resolveSkillScriptPath of the file src/kernel.ts of the component System Command Handler. The manipulation results in os command injection. The…

▾ SunlitEPSS 3.6%via NVD
CVE-2026-8230Medium· 6.3
4mo ago

A flaw has been found in Wavlink NU516U1 240425

A flaw has been found in Wavlink NU516U1 240425. The impacted element is the function sys_login1 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to os command injection. The attack can be executed…

▾ Sunlitwavlink · wl-nu516u1_firmwareEPSS 8.5%via NVD
CVE-2026-8229Medium· 6.3
4mo ago

A vulnerability was detected in Wavlink NU516U1 240425

A vulnerability was detected in Wavlink NU516U1 240425. The affected element is the function WifiBasic of the file /cgi-bin/wireless.cgi. Performing a manipulation of the argument AuthMethod/EncrypType results in os command injection. Re…

▾ Sunlitwavlink · wl-nu516u1_firmwareEPSS 8.5%via NVD
CVE-2026-8228Medium· 6.3
4mo ago

A security vulnerability has been detected in Wavlink NU516U1 240425

A security vulnerability has been detected in Wavlink NU516U1 240425. Impacted is the function advance of the file /cgi-bin/wireless.cgi. Such manipulation of the argument wlan_conf/Channel/skiplist/ieee_80211h leads to os command inject…

▾ Sunlitwavlink · wl-nu516u1_firmwareEPSS 8.5%via NVD
CVE-2026-8227Medium· 6.3
4mo ago

A weakness has been identified in Wavlink NU516U1 240425

A weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation causes os command injection. The attack may be initiated remotely. The exploit has been m…

▾ Sunlitwavlink · wl-nu516u1_firmwareEPSS 8.5%via NVD
CVE-2022-45899Medium· 6.5
4mo ago

Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log Scanner Search Pattern field.

Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log Scanner Search Pattern field.

▾ Sunlitnokia · broadcast_message_centerEPSS 1.4%via NVD
CVE-2026-42271High· 8.8CISA KEVPoC
4mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /m…

▾ Abyssallitellm · litellmEPSS 13%via NVD
CVE-2026-43003High· 8.0
4mo ago

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a mal…

▾ Twilightopenstack · ironic_python_agentEPSS 1.1%via NVD
CVE-2026-32649Medium· 6.8
5mo ago

A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras.

A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras.

▾ SunlitEPSS 1.5%via NVD
CVE-2026-1460High· 7.2
5mo ago

A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with adm…

A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with adm…

▾ Twilightzyxel · nebula_fwa70_firmwareEPSS 1.2%via NVD
CVE-2026-0711Medium· 6.8
5mo ago

A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS …

A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS …

▾ Sunlitzyxel · nr5307_firmwareEPSS 0.85%via NVD
CVE-2024-54012Medium· 5.3
5mo ago

Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted requests containing malicious commands to be executed on the device

Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted requests containing malicious commands to be executed on the device. The manufacture…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-40520High· 7.2
5mo ago

FreePBX api module Command Injection via GraphQL

FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation input fields are passed directly to shell_exec() without sanitization or escaping. An au…

▾ TwilightFreePBX · apiEPSS 2.4%via CVEORG
CVE-2026-24893High· 8.8
5mo ago

openITCOCKPIT is an open source monitoring tool built for different monitoring engines

openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user with permission t…

▾ Twilightit-novum · openitcockpitEPSS 1.4%via NVD
CVE-2026-39808Critical· 9.8CISA KEVPoC
5mo ago

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector…

▾ Hadalfortinet · fortisandboxEPSS 47%via NVD
CVE-2026-21915Medium· 6.7
5mo ago

A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to escalate their privileges to root. The CLI menu acce…

A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to escalate their privileges to root. The CLI menu acce…

▾ Sunlitjuniper · virtual_lightweight_collectorEPSS 2.2%via NVD
CVE-2026-30818High· 8.0
5mo ago

An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted configuration file is processed due to insufficient inpu…

An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted configuration file is processed due to insufficient inpu…

▾ Twilighttp-link · archer_ax53_firmwareEPSS 2.6%via NVD
CVE-2026-30815High· 8.0
5mo ago

An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient inp…

An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient inp…

▾ Twilighttp-link · archer_ax53_firmwareEPSS 3.1%via NVD
CVE-2026-27806High· 7.8
5mo ago

Fleet is open source device management software

Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script ex…

▾ Twilightfleetdm · fleetEPSS 0.11%via NVD
CVE-2026-5741High· 7.3
5mo ago

A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0

A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_image of the file src/index.ts of the component HTTP Interface. This manipulation causes…

▾ TwilightEPSS 2.1%via NVD
CVE-2026-5692High· 7.3
5mo ago

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os command injection. The attack may be pe…

▾ TwilightEPSS 2.1%via NVD
CVE-2026-34197High· 8.8CISA KEVPoC
5mo ago

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web conso…

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web conso…

▾ Abyssalapache · activemqEPSS 15%via NVD
CVE-2026-4631Critical· 9.8PoC
5mo ago

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP r…

▾ AbyssalEPSS 9.2%via NVD
CVE-2026-5691High· 7.3
5mo ago

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setFirewallType of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument firewallType leads to os command injection. The attack …

▾ TwilightEPSS 2.1%via NVD
CVE-2026-5690High· 7.3
5mo ago

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument enable can lead to os command injection. The att…

▾ TwilightEPSS 2.1%via NVD
CVE-2026-5689High· 7.3
5mo ago

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setNtpCfg of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument tz results in os command injection. Remote …

▾ TwilightEPSS 2.1%via NVD
CVE-2026-5688High· 7.3
5mo ago

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument provider leads to os command injection. The atta…

▾ TwilightEPSS 2.1%via NVD
CVE-2026-5709High· 8.8
5mo ago

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via craft…

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via craft…

▾ Twilightamazon · research_and_engineering_studioEPSS 0.98%via NVD
CVE-2026-5707High· 8.8
5mo ago

Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as roo…

Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as roo…

▾ Twilightamazon · research_and_engineering_studioEPSS 0.98%via NVD
CWE-78 vulnerabilities (CVEs) — page 20 · VulnSea