VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

725 CVEsRSS

CVE-2026-27550High· 8.8
1w ago

A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.9%via NVD
CVE-2026-27549High· 8.8
1w ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.9%via NVD
CVE-2026-27548High· 8.8
1w ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.9%via NVD
CVE-2026-27547High· 8.8
1w ago

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 2.9%via NVD
CVE-2026-73447Critical· 9.1
1w ago

A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise

A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista E…

▾ MidnightArista Networks · EOSEPSS 0.70%via NVD
CVE-2026-86108High· 8.0
1w ago

Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command

Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Success…

▾ TwilightArista Networks · VeloCloud EdgeEPSS 0.61%via NVD
CVE-2026-10144High· 7.8
1w ago

Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arbitrary OS commands by supplying a crafted URL containing shell metacharacters to the server.open configuration on macOS

Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arbitrary OS commands by supplying a crafted URL containing shell metacharacters to the server.open configuration on macOS. The openBrowser(…

▾ Twilightweb-infra-dev · rsbuildEPSS 1.6%via NVD
CVE-2026-76690High· 7.2
1w ago

A vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways that may allow for arbitrary command execution

A vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways that may allow for arbitrary command execution. An authenticated remote attacker could exploit this vulnerability by providing a specially crafted in…

▾ TwilightHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 1.1%via NVD
CVE-2026-58502High· 7.1PoC
1w ago

githubtoplanguages generates a user's top GitHub languages as an SVG

githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow runs when an issue is opened or closed and interpolates github.event.issue.title directly into the Bash assignment for…

▾ Midnightgouef · githubtoplanguagesEPSS 0.53%via NVD
CVE-2026-52484High· 8.8PoC
1w ago

An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code via the /cgi-bin/device-management-utilities-internet.cgi component

An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code via the /cgi-bin/device-management-utilities-internet.cgi component

▾ MidnightEPSS 0.64%via NVD
CVE-2026-91853High· 7.4PoC
1w ago

A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224

A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvpn of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user of the component Export Ovpn Handler. The manipulation…

▾ MidnightTOTOLINK · X5000REPSS 1.8%via NVD
CVE-2026-85013High· 7.3PoC
1w ago

A flaw was found in environment-modules

A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `…

▾ MidnightRed Hat · environment-modules-mainEPSS 0.22%via NVD
CVE-2026-91936Medium· 6.8PoC
1w ago

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shel…

▾ TwilightFlowiseAI · FlowiseEPSS 0.46%via NVD
CVE-2026-91931High· 8.5PoC
1w ago

Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter

Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invok…

▾ MidnightFlowiseAI · FlowiseEPSS 0.68%via NVD
CVE-2026-57586High· 8.6
1w ago

CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents

CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/mana…

▾ Twilightnaranor · agent-coderagEPSS 0.21%via NVD
CVE-2026-89308Critical· 9.3
1w ago

An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.

An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.

▾ MidnightTREXOM · TrxTimeATTENDANCEEPSS 2.1%via NVD
CVE-2026-57133High· 8.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delimited token against safeCommands and then passes the compl…

▾ MidnightMervinPraison · PraisonAIEPSS 0.80%via NVD
CVE-2026-57136High· 8.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExec…

▾ MidnightMervinPraison · PraisonAIEPSS 0.55%via NVD
CVE-2026-19515High· 7.0
1w ago

The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources

The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources. This allows a crafted project to inject and execute arbitrary op…

▾ TwilightWSO2 · WSO2 Integrator: MI for Visual Studio CodeEPSS 0.14%via NVD
CVE-2026-77853High· 8.8
1w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.

▾ TwilightLITE-ON Technology Corporation · FF-RFI079I4EPSS 1.9%via NVD
CVE-2026-90847Critical· 9.1PoC
1w ago

A vulnerability was determined in EFM ipTIME C200E 1.094

A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the at…

▾ AbyssalEFM · ipTIME C200EEPSS 3.4%via NVD
CVE-2026-90843High· 8.3PoC
1w ago

A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25

A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler. Such manipul…

▾ MidnightSabyasachiRana · WebMapEPSS 2.2%via NVD
CVE-2026-55158Critical· 9.1
1w ago

Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests

Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the attacker-controlled …

▾ Midnightwktk · conflibotEPSS 0.80%via NVD
CVE-2026-14277Medium· 6.3
1w ago

IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a session file.

IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a session file.

▾ SunlitIBM · i Access FamilyEPSS 0.50%via NVD
CVE-2026-14276Medium· 6.3
1w ago

IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a m…

IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a m…

▾ SunlitIBM · i Access FamilyEPSS 0.27%via NVD
CVE-2026-14275Medium· 6.3
1w ago

IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a S…

IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a S…

▾ SunlitIBM · i Access FamilyEPSS 0.27%via NVD
CVE-2026-17133High· 7.8
1w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

▾ TwilightIBM · App Connect EnterpriseEPSS 0.15%via NVD
CVE-2026-16673High· 8.8
1w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.42%via NVD
CVE-2026-16466High· 8.8
1w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.91%via NVD
CVE-2026-90703Critical· 9.1PoC
1w ago

A vulnerability has been found in D-Link DWR-M921 1.1.52

A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be …

▾ AbyssalD-Link · DWR-M921EPSS 3.6%via NVD
CWE-78 vulnerabilities (CVEs) — page 5 · VulnSea