VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

727 CVEsRSS

CVE-2026-23920High· 8.8
6mo ago

Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode

Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass…

▾ Twilightzabbix · zabbixEPSS 0.30%via NVD
CVE-2026-3227Medium· 6.8PoC
6mo ago

A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command

A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an au…

▾ Twilighttp-link · tl-wr802n_firmwareEPSS 1.8%via NVD
CVE-2026-28384Critical· 9.9
6mo ago

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This iss…

▾ Midnightcanonical · lxdEPSS 0.86%via NVD
CVE-2026-23816High· 7.2
6mo ago

A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

▾ Twilighthpe · arubaos-cxEPSS 1.2%via NVD
CVE-2026-20040High· 8.8
6mo ago

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient…

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient…

▾ Twilightcisco · ios_xrEPSS 0.17%via NVD
CVE-2025-70082Critical· 9.8
6mo ago

An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component

An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component

▾ MidnightEPSS 0.46%via NVD
CVE-2025-67041Critical· 9.8
6mo ago

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly sanitized. This can be exploited to escape from the original command and execute an arbitrary …

▾ MidnightEPSS 0.42%via NVD
CVE-2025-67038Critical· 9.8CISA KEVPoC
6mo ago

An issue was discovered in Lantronix EDS5000 2.1.0.0R3

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This al…

▾ Hadallantronix · eds5008_firmwareEPSS 19%via NVD
CVE-2026-26318High· 8.8
7mo ago

Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation

Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation

▾ Twilightsysteminformation · systeminformationEPSS 1.3%via GHSA
CVE-2026-2670High· 7.2PoC
7mo ago

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WIS…

▾ MidnightEPSS 3.6%via NVD
CVE-2026-22223High· 8.0
7mo ago

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrati…

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrati…

▾ Twilighttp-link · archer_be230_firmwareEPSS 1.3%via NVD
CVE-2026-22221High· 8.0
7mo ago

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrativ…

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrativ…

▾ Twilighttp-link · archer_be230_firmwareEPSS 1.4%via NVD
CVE-2026-0631High· 8.0
7mo ago

An OS Command Injection vulnerability in OpenVPN modules in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1 allows an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain…

An OS Command Injection vulnerability in OpenVPN modules in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1 allows an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain…

▾ Twilighttp-link · archer_be230_firmwareEPSS 1.5%via NVD
CVE-2025-61731High· 7.8
8mo ago

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to…

▾ Twilightgolang · goEPSS 0.62%via NVD
CVE-2025-57283High· 7.8
8mo ago

The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability

The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.

▾ Twilightbrowserstack · browserstack-localEPSS 0.81%via NVD
CVE-2026-21267High· 8.6
8mo ago

Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker

Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploit…

▾ Twilightadobe · dreamweaverEPSS 0.83%via NVD
CVE-2025-13444High· 8.4
8mo ago

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsani…

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsani…

▾ Twilightprogress · connection_manager_for_objectscaleEPSS 27%via NVD
CVE-2025-69262High· 7.5
8mo ago

pnpm is a package manager

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environme…

▾ TwilightRed HatEPSS 1.1%via NVD
CVE-2025-68700High· 8.8
9mo ago

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) can execute arbitrary system commands on the server host process via the front…

▾ Twilightinfiniflow · ragflowEPSS 0.72%via NVD
CVE-2015-10145High· 8.8
9mo ago

Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utility/run_commands.sh

Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utility/run_commands.sh. The application fails to properly restrict or validate input supplied via the 'commands' parameter…

▾ Twilightgargoyle-router · gargoyleEPSS 0.73%via NVD
CVE-2025-65008None
9mo ago

In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of validation in the langGet parameter in the adm.cgi endpoint, the malicious attacker can execute system shell commands. The vendor was notified early about …

In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of validation in the langGet parameter in the adm.cgi endpoint, the malicious attacker can execute system shell commands. The vendor was notified early about …

▾ SunlitEPSS 2.7%via NVD
CVE-2025-65199High· 7.8
9mo ago

A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to execute arbitrary commands as root via the 'adapterName' parameter of the 'changeMTU' functi…

A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to execute arbitrary commands as root via the 'adapterName' parameter of the 'changeMTU' functi…

▾ Twilightwindscribe · windscribeEPSS 1.3%via NVD
CVE-2024-58278None
9mo ago

perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts

perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts. Attackers can control the 0th argument of packed executables to execute another executable, al…

▾ SunlitEPSS 0.19%via NVD
CVE-2025-29269Critical· 9.8
9mo ago

ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint.

ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint.

▾ Midnightallnet · all-rut22gw_firmwareEPSS 2.0%via NVD
CVE-2025-11787High· 8.8
9mo ago

Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()', 'CheckPing()' and 'TraceRoute()' functions.

Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()', 'CheckPing()' and 'TraceRoute()' functions.

▾ Twilightcircutor · sge-plc1000_firmwareEPSS 1.0%via NVD
CVE-2025-10230Critical· 10.0PoC
10mo ago

A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping

A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserte…

▾ AbyssalEPSS 40%via NVD
CVE-2025-34312High· 8.8
11mo ago

IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the 'nobody' user via the BE_NAME parameter when installing a blacklist

IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the 'nobody' user via the BE_NAME parameter when installing a blacklist. Whe…

▾ Twilightipfire · ipfireEPSS 2.3%via NVD
CVE-2025-34311High· 8.8
11mo ago

IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the user 'nobody' via multiple parameters when creating a Proxy report

IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the user 'nobody' via multiple parameters when creating a Proxy report. When…

▾ Twilightipfire · ipfireEPSS 14%via NVD
CVE-2025-9976Critical· 9.0
11mo ago

An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.

An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.

▾ MidnightEPSS 0.90%via NVD
CVE-2025-60965Critical· 9.1
11mo ago

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive in…

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive in…

▾ Midnightendruntechnologies · sonoma_d12_firmwareEPSS 1.2%via NVD
CWE-78 vulnerabilities (CVEs) — page 22 · VulnSea