VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

727 CVEsRSS

CVE-2026-16466High· 8.8
1w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.91%via NVD
CVE-2026-90703Critical· 9.1PoC
1w ago

A vulnerability has been found in D-Link DWR-M921 1.1.52

A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be …

▾ AbyssalD-Link · DWR-M921EPSS 3.6%via NVD
CVE-2026-90621Medium· 6.3PoC
1w ago

A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0

A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the file src/hackingBuddyGPT/extensions/ssh_run_command.py. Such manipulation leads to os command injection. The attack c…

▾ Twilightipa-lab · HackingBuddyGPTEPSS 1.8%via NVD
CVE-2026-90619High· 7.3
1w ago

A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04

A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute Endpoint. The manipulation of the argument code…

▾ Twilight0x4m4 · HexStrike AIEPSS 2.1%via NVD
CVE-2026-90618High· 7.3PoC
1w ago

A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2

A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. Executing a manipu…

▾ MidnightGH05TCREW · PentestAgentEPSS 2.1%via NVD
CVE-2026-90617High· 7.3PoC
1w ago

A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2

A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerability affects the function run_task of the file interface/main.py of the component MCP HTTP Server. Performing a manipula…

▾ MidnightGH05TCREW · PentestAgentEPSS 2.1%via NVD
CVE-2026-90702Critical· 9.1PoC
1w ago

A flaw has been found in D-Link DWR-M921 1.1.52

A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The explo…

▾ AbyssalD-Link · DWR-M921EPSS 3.6%via NVD
CVE-2026-90690High· 7.3PoC
1w ago

A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04

A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the component API Tools Endpoint. Executing a m…

▾ Midnight0x4m4 · HexStrike AIEPSS 2.1%via NVD
CVE-2026-90894High· 7.8
1w ago

Parallels Desktop runs prl_disp_service as root

Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, Pr…

▾ TwilightParallels · Parallels DesktopEPSS 0.17%via NVD
CVE-2026-90705Medium· 6.6PoC
1w ago

A vulnerability was determined in D-Link DWR-M921 1.1.52

A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command inj…

▾ TwilightD-Link · DWR-M921EPSS 2.3%via NVD
CVE-2026-90699Critical· 9.9PoC
1w ago

A weakness has been identified in D-Link DWR-M920 1.1.7

A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated…

▾ AbyssalD-Link · DWR-M920EPSS 3.3%via NVD
CVE-2026-82779High· 8.8
1w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to …

▾ TwilightContec Co., Ltd · CPS-TM341G5MB-ADSC1-931EPSS 1.9%via NVD
CVE-2026-82777High· 8.8
1w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to…

▾ TwilightContec Co., Ltd. · Integrated Type CPS-PC341[][]-*-9201EPSS 1.9%via NVD
CVE-2026-82774High· 8.8
1w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may …

▾ TwilightContec Co., Ltd. · M2M Gateway Integrated Type CPS-MG341*EPSS 1.9%via NVD
CVE-2026-82766High· 8.8
1w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

▾ TwilightContec Co., Ltd. · SGA1000EPSS 1.9%via NVD
CVE-2026-82762High· 8.8
1w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be execute…

▾ TwilightContec Co., Ltd. · FXA5000EPSS 1.9%via NVD
CVE-2026-82794High· 8.8
1w ago

SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings

SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

▾ TwilightContec Co., Ltd. · SV-CPT-MC310EPSS 1.9%via NVD
CVE-2026-82791High· 8.8
1w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may b…

▾ TwilightContec Co., Ltd. · CAN-2-WFEPSS 1.9%via NVD
CVE-2026-90788Medium· 4.7PoC
1w ago

A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055

A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown functionality of the file /admin1.php/admin/template/index/path/.%40template%40default%40html%40label.html of the com…

▾ Twilightmagicblack · MacCMS10EPSS 2.2%via NVD
CVE-2026-90706Medium· 6.6PoC
1w ago

A vulnerability was identified in D-Link DWR-M921 1.1.52

A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc. The manipulation of the argument targetAPSsid leads to os command injection. The attack is possible to be carried ou…

▾ TwilightD-Link · DWR-M921EPSS 2.3%via NVD
CVE-2026-59960High· 7.5
1w ago

Argos JavaScript provides official Argos SDKs for JavaScript

Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-controlled CI branch or ref values from GITHUB_HEAD_REF or ARGOS_BRANCH can flow through config.branch and getMergeBaseComm…

▾ Twilightargos-ci · argos-javascriptEPSS 0.64%via NVD
CVE-2026-54182High· 8.1
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::mak…

▾ TwilightLaravel-Backpack · CRUDEPSS 0.78%via NVD
CVE-2026-57124Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and args values that PraisonAIUI passes to Stdi…

▾ AbyssalMervinPraison · PraisonAIEPSS 1.0%via NVD
CVE-2026-90492Medium· 6.3
2w ago

A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0

A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function controller_listen/controller_recover of the file py/web.py. The manipulation of the argument case_name leads to os com…

▾ Sunlitwebgjc · web_robotEPSS 2.4%via NVD
CVE-2026-90770High· 8.8
2w ago

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions …

▾ Twilightopenspug · spugEPSS 1.3%via NVD
CVE-2026-35867Low· 3.1PoC
2w ago

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able …

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able …

▾ TwilightLB-LINK · AC1900 firmwareEPSS 1.0%via NVD
CVE-2026-90444High· 8.7
2w ago

A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters

A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, all…

▾ TwilightCISA · MalcolmEPSS 0.40%via NVD
CVE-2026-85979High· 8.6
2w ago

Affected versions of Puppet Enterprise contain a command injection vulnerability

Affected versions of Puppet Enterprise contain a command injection vulnerability. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, …

▾ TwilightPerforce Software · Puppet EnterpriseEPSS 1.3%via NVD
CVE-2026-89010Critical· 9.8PoC
2w ago

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to …

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to …

▾ AbyssalWAVLINK Technology · WN535M1EPSS 3.2%via NVD
CVE-2026-17176High· 7.7
2w ago

An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to compl…

An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to compl…

▾ TwilightTP-Link Systems Inc. · Deco BE11000 V2EPSS 3.7%via NVD
CWE-78 vulnerabilities (CVEs) — page 6 · VulnSea