VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

727 CVEsRSS

CVE-2026-89066High· 7.8
2w ago

Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous int…

Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous int…

▾ TwilightAWS · projenEPSS 0.23%via NVD
CVE-2026-8301High· 7.8
2w ago

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardu…

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardu…

▾ TwilightTUBITAK BILGEM Software Technologies Research Institute · Pardus Boot RepairEPSS 0.84%via NVD
CVE-2026-7863High· 8.4
2w ago

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software allows OS Command Injection. This issue affects Pardus S…

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software allows OS Command Injection. This issue affects Pardus S…

▾ TwilightTUBITAK BILGEM Software Technologies Research Institute · Pardus SoftwareEPSS 0.95%via NVD
CVE-2026-88888High· 7.0
2w ago

Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters

Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters. Attackers can inject shell metacharacters through malicious package names …

▾ Twilightrenovatebot · renovateEPSS 0.89%via NVD
CVE-2026-78575High· 8.8
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.

▾ Twilightlangflow · langflowEPSS 0.79%via NVD
CVE-2026-79724Critical· 9.8
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

▾ Midnightlangflow · langflowEPSS 0.67%via NVD
CVE-2026-78569High· 8.8
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.

▾ Twilightlangflow · langflowEPSS 0.65%via NVD
CVE-2026-81468Critical· 9.1
2w ago

Dell ThinOS 10, versions prior to 2605_10

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploi…

▾ Midnightdell · thinosEPSS 2.0%via NVD
CVE-2026-88273High· 7.2
2w ago

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.70%via NVD
CVE-2026-88274High· 7.2
2w ago

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.70%via NVD
CVE-2026-82098High· 8.8
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.79%via NVD
CVE-2026-73694High· 7.2PoC
2w ago

FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition

FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input to reach an exec() sink uns…

▾ MidnightFileRun · FileRunEPSS 2.2%via CVEORG
CVE-2026-82099High· 8.8
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.81%via NVD
CVE-2026-81467Critical· 9.8
2w ago

Dell ThinOS 10, versions prior to 2605_10

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially explo…

▾ Midnightdell · thinosEPSS 3.0%via NVD
CVE-2026-88272High· 7.2
2w ago

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.54%via NVD
CVE-2026-88885High· 7.0
2w ago

Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode

Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode. Attackers can inject shell metacharacters …

▾ Twilightrenovatebot · renovateEPSS 0.89%via NVD
CVE-2026-0302Low· 1.1
2w ago

An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.

An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.

▾ SunlitPalo Alto Networks · Checkov by Prisma CloudEPSS 0.82%via NVD
CVE-2026-19136High· 7.8
2w ago

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially cr…

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially cr…

▾ TwilightLenovo · Tianxi AI Agent PC ApplicationEPSS 0.87%via NVD
CVE-2026-82095High· 8.8
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.81%via NVD
CVE-2026-65639Critical· 9.5
2w ago

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplie…

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplie…

▾ MidnightWebPros · ConfigServer Security & FirewallEPSS 1.4%via CVEORG
CVE-2026-65638Critical· 9.2
2w ago

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions o…

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions o…

▾ MidnightWebPros · ConfigServer Security & FirewallEPSS 2.3%via CVEORG
CVE-2026-81550High· 8.8
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.81%via NVD
CVE-2026-88277High· 8.8
2w ago

GV-LPCLPC2011/2211 - ONVIF Subscribe Address Command Injection

GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root.

▾ TwilightGeoVision Inc. · GV-LPCLPC2011/2211EPSS 0.65%via CVEORG
CVE-2026-73693High· 8.8
2w ago

FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler

FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading files with shell metacharacters in th…

▾ TwilightFileRun · FileRunEPSS 2.7%via CVEORG
CVE-2026-0309Medium· 4.0
2w ago

PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have…

▾ SunlitPalo Alto Networks · Cloud NGFWEPSS 0.45%via CVEORG
CVE-2026-88276High· 7.2
2w ago

GV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command Injection

GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.

▾ TwilightGeoVision Inc. · GV-LPCLPC2011/2211EPSS 0.70%via CVEORG
CVE-2026-88275High· 7.2
2w ago

GV-LPC2011/LPC2211 - Wireless WPA-PSK Command Injection

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.70%via CVEORG
CVE-2026-88886High· 7.8
2w ago

Renovate is a dependency update automation tool

Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before 15.4.0, and the mend-renovate-enterprise-edition Helm chart before 10.4.0), the manager/gradle-wrapper module do…

▾ Twilightrenovatebot · renovateEPSS 0.23%via NVD
CVE-2026-64837High· 8.8
2w ago

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters i…

▾ TwilightICEcoder · icecoder/icecoderEPSS 0.81%via NVD
CVE-2026-88889High· 7.8
2w ago

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attacke…

▾ Twilightrenovatebot · renovateEPSS 1.0%via NVD
CWE-78 vulnerabilities (CVEs) — page 7 · VulnSea