VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

727 CVEsRSS

CVE-2026-13745High· 7.7
2w ago

A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory

A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory. The vulnerability is triggered via untrusted .env fi…

▾ TwilightGoogle Cloud · Gemini CLIEPSS 0.38%via NVD
CVE-2026-88282High· 7.2
2w ago

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled FTP username containing shell metacharacters to be executed as arbitrary root commands during a subsequent FTP-account update.

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled FTP username containing shell metacharacters to be executed as arbitrary root commands during a subsequent FTP-account update.

▾ TwilightGeoVision Inc. · GV-LPCLPC2011/2211EPSS 0.54%via NVD
CVE-2026-87911Critical· 9.6
2w ago

An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a s…

An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a s…

▾ MidnightAWS · AWS Labs postgres MCP ServerEPSS 1.7%via NVD
CVE-2026-77120High· 8.7
2w ago

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause privilege escalation to root and unauthorized execution of administrative functions when an authenti…

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause privilege escalation to root and unauthorized execution of administrative functions when an authenti…

▾ TwilightSchneider Electric · PowerLogic T300EPSS 0.67%via NVD
CVE-2026-70425Medium· 6.7
2w ago

Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain a command injection vulnerability

Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain a command injection vulnerability. An admin privileged local attacker could potentially exploit t…

▾ Sunlitdell · powerscale_onefsEPSS 0.53%via NVD
CVE-2026-79641High· 7.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low pr…

▾ TwilightDell · Secure Connect Gateway 5.0 - ApplicationEPSS 1.1%via CVEORG
CVE-2026-23855High· 7.2
2w ago

Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection…

Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection…

▾ TwilightDell · iDRAC9EPSS 0.93%via CVEORG
CVE-2026-79689Medium· 5.3
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unaut…

▾ SunlitDell · Secure Connect Gateway 5.0 - ApplicationEPSS 4.7%via CVEORG
CVE-2026-87088High· 7.0
2w ago

Tanium addressed an unauthorized code execution vulnerability in Enforce.

Tanium addressed an unauthorized code execution vulnerability in Enforce.

▾ Twilighttanium · enforceEPSS 0.17%via NVD
CVE-2026-78630Medium· 6.7
2w ago

The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS commands

The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS commands. An authenticated local user with access to the management interface can supply c…

▾ Sunlitokta · access_gatewayEPSS 0.22%via NVD
CVE-2026-82004Critical· 10.0
2w ago

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An …

▾ Midnightadobe · campaignEPSS 3.3%via NVD
CVE-2026-81349High· 7.2
2w ago

Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.

Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · azure_hdinsightEPSS 1.0%via NVD
CVE-2026-86733High· 7.2
2w ago

Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands su…

Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands su…

▾ Twilightsnipeitapp · snipe-itEPSS 0.58%via NVD
CVE-2026-61517High· 7.2PoC
2w ago

Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command injection vulnerability in the ping diagnostic handler that allows authenticated administrators to execute arbitrary shell commands as root by injecting into the IpAdd…

Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command injection vulnerability in the ping diagnostic handler that allows authenticated administrators to execute arbitrary shell commands as root by injecting into the IpAdd…

▾ MidnightNetis Systems · NX10EPSS 2.5%via NVD
CVE-2026-71376Critical· 9.8
2w ago

OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03…

OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03…

▾ MidnightHitachi · Cosminexus Component ContainerEPSS 1.8%via NVD
CVE-2026-76561High· 7.2
2w ago

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Admi…

▾ TwilightRed Hat · pki-coreEPSS 0.58%via NVD
CVE-2026-86540High· 7.8PoC
2w ago

knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file

knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository w…

▾ Midnightknowns-dev · knownsEPSS 0.21%via NVD
CVE-2026-80127High· 7.2
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high p…

▾ Twilightdell · secure_connect_gatewayEPSS 1.4%via NVD
CVE-2026-78488Medium· 6.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low pr…

▾ Sunlitdell · secure_connect_gatewayEPSS 4.8%via NVD
CVE-2026-19843High· 8.4PoC
2w ago

A flaw was found in 389-ds-base

A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated…

▾ MidnightRed Hat · redhat-ds:11EPSS 0.48%via NVD
CVE-2026-61409High· 7.3
2w ago

Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remot…

▾ Twilightdell · secure_connect_gatewayEPSS 1.5%via NVD
CVE-2026-86299Critical· 9.9PoC
2w ago

A vulnerability was detected in Linksys RE7000 2.0.15

A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSiz…

▾ AbyssalLinksys · RE7000EPSS 3.7%via NVD
CVE-2026-84256High· 7.7
2w ago

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject

▾ TwilightOpenVPN · OpenVPNEPSS 0.38%via NVD
CVE-2026-86167Critical· 9.9PoC
3w ago

A vulnerability was identified in Tenda HG10 300001138

A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remot…

▾ AbyssalTenda · HG10EPSS 2.7%via NVD
CVE-2026-86152Critical· 10.0
3w ago

A flaw has been found in Tenda CP3 27.5.57.101

A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The at…

▾ MidnightTenda · CP3EPSS 2.9%via NVD
CVE-2026-86151Critical· 9.1PoC
3w ago

A vulnerability was detected in Tenda CP3 27.5.57.101

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection…

▾ AbyssalTenda · CP3EPSS 2.9%via NVD
CVE-2026-86149Critical· 9.1
3w ago

A weakness has been identified in Tenda CP3 27.5.57.101

A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be in…

▾ MidnightTenda · CP3EPSS 2.9%via NVD
CVE-2026-86148Critical· 9.1
3w ago

A security flaw has been discovered in Tenda CP3 27.5.57.101

A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command inject…

▾ MidnightTenda · CP3EPSS 2.9%via NVD
CVE-2026-85660High· 8.1
3w ago

cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled

cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. Attackers can use shell command substitution syntax like $(...) or backticks t…

▾ TwilightEPSS 0.62%via NVD
CVE-2026-85696Critical· 9.8
3w ago

SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping

SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters…

▾ MidnightOpenTalker · SadTalkerEPSS 2.6%via NVD
CWE-78 vulnerabilities (CVEs) — page 8 · VulnSea