VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

727 CVEsRSS

CVE-2026-5679Medium· 5.5
5mo ago

A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024

A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument stun_pass leads to os command inje…

▾ SunlitEPSS 2.5%via NVD
CVE-2026-5678High· 7.3
5mo ago

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument mode can lead to os command injection…

▾ TwilightEPSS 2.1%via NVD
CVE-2026-5621Medium· 5.3
5mo ago

A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0

A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown functionality of the file src/index.ts of the component HTTP Interface. The manipulation of the argument config_path results …

▾ SunlitEPSS 1.4%via NVD
CVE-2026-5619Medium· 5.3
5mo ago

A flaw has been found in Braffolk mcp-summarization-functions up to 0.1.5

A flaw has been found in Braffolk mcp-summarization-functions up to 0.1.5. This impacts an unknown function of the file src/server/mcp-server.ts of the component summarize_command. Executing a manipulation of the argument command can lea…

▾ SunlitEPSS 1.4%via NVD
CVE-2026-34982High· 8.2
5mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` option…

▾ Twilightvim · vimEPSS 0.27%via NVD
CVE-2026-34977Critical· 9.8
5mo ago

Aperi'Solve is an open-source steganalysis web platform

Aperi'Solve is an open-source steganalysis web platform. In versions 3.1.3 through 3.2.0, when uploading a JPEG, a user can specify an optional password to accompany the JPEG. This password is then directly passed into an expect command,…

▾ MidnightEPSS 1.2%via NVD
CVE-2026-5528Medium· 6.3
5mo ago

A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0

A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command injection. It is possible to launch the atta…

▾ SunlitEPSS 2.4%via NVD
CVE-2026-25044High· 8.8
5mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync without proper sanitization or validation. User input is processed through processStringSync w…

▾ Twilightbudibase · budibaseEPSS 0.47%via NVD
CVE-2026-5485High· 7.8
5mo ago

OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection parameters that are loaded…

OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection parameters that are loaded…

▾ Twilightamazon · athena_odbcEPSS 1.1%via NVD
CVE-2017-20236Critical· 9.8
5mo ago

ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows remote attackers to inject and execute system commands by submitting malicious input th…

ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows remote attackers to inject and execute system commands by submitting malicious input th…

▾ Midnightprosoft-technology · icx35-hwc_firmwareEPSS 0.68%via NVD
CVE-2026-34797High· 8.8
5mo ago

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open…

▾ Twilightendian · firewall_communityEPSS 1.9%via NVD
CVE-2026-34796High· 8.8
5mo ago

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.cgi

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl o…

▾ Twilightendian · firewall_communityEPSS 1.9%via NVD
CVE-2026-34795High· 8.8
5mo ago

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open(…

▾ Twilightendian · firewall_communityEPSS 1.9%via NVD
CVE-2026-34794High· 8.8
5mo ago

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open(…

▾ Twilightendian · firewall_communityEPSS 1.9%via NVD
CVE-2026-34793High· 8.8
5mo ago

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl …

▾ Twilightendian · firewall_communityEPSS 1.9%via NVD
CVE-2026-34792High· 8.8
5mo ago

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl op…

▾ Twilightendian · firewall_communityEPSS 1.9%via NVD
CVE-2026-3692High· 8.8
5mo ago

In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.

In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.

▾ Twilightprogress · flowmonEPSS 0.57%via NVD
CVE-2026-30314Critical· 9.8
6mo ago

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command str…

▾ Midnightridvay · auto-approval_moduleEPSS 2.2%via NVD
CVE-2026-30312Critical· 9.8
6mo ago

DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective

DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on string-based parsing to validate commands; while …

▾ MidnightEPSS 2.1%via NVD
CVE-2026-30311Critical· 9.8
6mo ago

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command str…

▾ Midnightridvay · auto-approval_moduleEPSS 2.2%via NVD
CVE-2026-30309High· 7.8
6mo ago

InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist security mechanism completely ineffective

InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist security mechanism completely ineffective. The predefined blocklist fails to cover native high-risk commands in Windo…

▾ Twilighttokfinity · infcodeEPSS 0.38%via NVD
CVE-2026-32917Critical· 9.8
6mo ago

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsaniti…

▾ Midnightopenclaw · openclawEPSS 3.2%via NVD
CVE-2025-14213None
6mo ago

Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attacker with access to the Socket web interface (UI) to execute arbitrary operating system commands as the root user on th…

Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attacker with access to the Socket web interface (UI) to execute arbitrary operating system commands as the root user on th…

▾ SunlitEPSS 0.98%via NVD
CVE-2026-24154High· 7.6
6mo ago

NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments

NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments. A successful exploit of this vulnerability might lead to code execution, escalation of pri…

▾ Twilightnvidia · jetson_linuxEPSS 0.26%via NVD
CVE-2026-34243Critical· 9.8PoC
6mo ago

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title)

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell com…

▾ Abyssalnjzjz · wenxianEPSS 2.8%via NVD
CVE-2026-0596High· 7.8PoC
6mo ago

A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`

A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into a shell command executed via `bash -c` without proper sanitization. If the `model_uri` …

▾ Midnightlfprojects · mlflowEPSS 1.3%via NVD
CVE-2025-15379Critical· 10.0
6mo ago

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependen…

▾ Midnightlfprojects · mlflowEPSS 2.4%via NVD
CVE-2026-34714Critical· 9.2
6mo ago

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

▾ MidnightEPSS 0.29%via NVD
CVE-2026-4946High· 8.8
6mo ago

Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts with the UI

Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts with the UI. Specifically, the @execute annotati…

▾ Twilightnsa · ghidraEPSS 0.77%via NVD
CVE-2026-1961High· 8.0PoC
6mo ago

A flaw was found in Foreman

A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resou…

▾ MidnightEPSS 1.4%via NVD
CWE-78 vulnerabilities (CVEs) — page 21 · VulnSea