On this page

Atomicorp WAF Rule 340023

Rule Summary

Description

This rule detects behavior identified by its current alert as “Attack Blocked - remote command execution” in the request URI, request arguments, JSON request data, SOAP request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2025-34037Linksys Routers E/WAG/WAP/WES/WET/WRT-SeriesE420010.0 (v4.0)Critical
CVE-2026-19188Haiwell IoT Cloud HMI Gateway OS Command InjectionHaiwell IoT Cloud HMI Gateway10.0 (v4.0)Critical
CVE-2026-34234CtrlPanel: Unauthenticated RCE using installer scriptpanel10.0 (v3.1)Critical
CVE-2026-44181Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Executionenterprise gateway10.0 (v4.0)Critical
CVE-2026-47668DbGate - Remote Code Execution via Anonymous JWTdbgate10.0 (v3.1)Critical
CVE-2026-49869Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in AuthenticationFilterkestra10.0 (v3.1)Critical
CVE-2026-81735UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command ExecutiUI-TARS-desktop10.0 (v4.0)Critical
CVE-2026-8984Unauthenticated RCEmaxicharger single charger firmware10.0 (v4.0)Critical
CVE-2026-8985Unauthenticated Command Injectionmaxicharger single charger firmware10.0 (v4.0)Critical
CVE-2026-34838Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in AbstractSettingsCollectiongroup-office9.9 (v3.1)Critical
CVE-2026-44450Lumiverse: RCE via MCP stdio argument injectionLumiverse9.9 (v3.1)Critical
CVE-2026-45632Dokploy: Schedule Authorization Bypass Enables Host/Server Command Executiondokploy9.9 (v3.1)Critical
CVE-2026-63298LXD arbitrary lxc.conf directive injection via NVIDIA instance configurationLXD9.9 (v3.1)Critical
CVE-2026-72868Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injectiondokploy9.9 (v3.1)Critical
CVE-2026-72869Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCEdokploy9.9 (v3.1)Critical
CVE-2026-72882Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed serversdokploy9.9 (v3.1)Critical
CVE-2026-73263Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-pathprowler9.9 (v3.1)Critical
CVE-2026-73294Semaphore U: OS Command Injectionsemaphore9.9 (v3.1)Critical
CVE-2014-1203Eyou E-Mail <3.6 - Remote Code Executioneyou9.8 (v3.1)Critical
CVE-2015-4664Xceedium Xsuite - Multiple Vulnerabilitiesprivileged access manager9.8 (v3.0)Critical
CVE-2015-4667Xceedium Xsuite - Multiple Vulnerabilitiesxsuite9.8 (v3.0)Critical
CVE-2018-16763FUEL CMS 1.4.1 - Remote Code Executionfuel cms9.8 (v3.1)Critical
CVE-2019-12725Zeroshell 3.9.0 - Remote Command Executionzeroshell9.8 (v3.0)Critical
CVE-2019-15107Webmin <= 1.920 - Unauthenticated Remote Command Executionwebmin9.8 (v3.1)Critical
CVE-2019-16920D-Link Routers - Remote Code Executiondir-655 firmware9.8 (v3.1)Critical
CVE-2020-15568TerraMaster TOS <.1.29 - Remote Code Executiontos9.8 (v3.1)Critical
CVE-2020-15920Mida eFramework <=2.9.0 - Remote Command Executioneframework9.8 (v3.1)Critical
CVE-2020-21224Inspur ClusterEngine 4.0 - Remote Code Executionclusterengine9.8 (v3.1)Critical
CVE-2020-29390Zeroshell 3.9.3 - Command Injectionzeroshell9.8 (v3.1)Critical
CVE-2020-9054Zyxel NAS Firmware 5.21- Remote Code Executionnas326 firmware9.8 (v3.1)Critical
CVE-2022-31137Roxy-WI < 6.1.1.0 - Remote Code Executionroxy-wi9.8 (v3.1)Critical
CVE-2022-35914GLPI <=10.0.2 - Remote Command Executionglpi9.8 (v3.1)Critical
CVE-2024-53584OpenPanel 0.3.4 - OS Command Injectionopenpanel9.8 (v3.1)Critical
CVE-2024-7954SPIP Porte Plume Plugin - Remote Code ExecutionSPIP9.8 (v3.1)Critical
CVE-2025-24893XWiki Platform - Remote Code Executionxwiki9.8 (v3.1)Critical
CVE-2026-12940Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpointlangflow9.8 (v3.1)Critical
CVE-2026-18482neo-mjs Command Injection Vulnerabilityneo-mjs9.8 (v3.1)Critical
CVE-2026-19912Kaltura HTML5 Video Player, html5 library Arbitrary Code Execution VulnerabilityKaltura HTML5 Video Player, html5 library9.8 (v3.1)Critical
CVE-2026-31040stata-mcp Code Injection Vulnerabilitystata-mcp9.8 (v3.1)Critical
CVE-2026-3296Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry MetadataEverest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder9.8 (v3.1)Critical
CVE-2026-35048Piwigo RCE via PHP Code Injection into Config File in InstallerPiwigo9.8 (v3.1)Critical
CVE-2026-35847dnsmgr 2.15 and Earlier Arbitrary Code Execution Vulnerability-9.8 (v3.1)Critical
CVE-2026-37281the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 Command Injection Vulnerabilitythe /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.09.8 (v3.1)Critical
CVE-2026-38431erpnext Code Injection Vulnerabilityerpnext9.8 (v3.1)Critical
CVE-2026-45018Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code executionchainlit9.8 (v3.1)Critical
CVE-2026-46562Yamcs: Remote Code Execution via Mission Database algorithm overrideyamcs9.8 (v3.1)Critical
CVE-2026-47391PraisonAI's unauthenticated A2A official example can reach real LLM-driven eval() tool executionPraisonAI9.8 (v3.1)Critical
CVE-2026-48687fastnetmon Command Injection Vulnerabilityfastnetmon9.8 (v3.1)Critical
CVE-2026-67919Halo 2.25.4 Arbitrary Code Execution Vulnerability-9.8 (v3.1)Critical
CVE-2026-72592dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Uploadphpfm9.8 (v3.1)Critical
CVE-2026-75411JeecgBoot v3.9.2 Code Injection Vulnerability-9.8 (v3.1)Critical
CVE-2026-75414In AntFlow V2.0.0, ActivitiTest.java Code Injection Vulnerability-9.8 (v3.1)Critical
CVE-2026-79408MetaGPT 0.8.1 Command Injection VulnerabilityMetaGPT 0.8.19.8 (v3.1)Critical
CVE-2026-84372Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connectionspredis9.8 (v3.1)Critical
CVE-2026-34449SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injectionsiyuan9.6 (v3.1)Critical
CVE-2026-53649Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCEjoro9.6 (v3.1)Critical
CVE-2026-72878Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell argumentsdokploy9.6 (v3.1)Critical
CVE-2026-8986Command Injection via Malicious OCPP Servermaxicharger single charger firmware9.5 (v4.0)Critical
CVE-2025-62593Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attackray9.4 (v4.0)Critical
CVE-2026-33324SQLBot prompt injection allows arbitrary SQL execution and remote code executionsqlbot9.4 (v4.0)Critical
CVE-2026-45272MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config Filetalebook9.4 (v4.0)Critical
CVE-2026-47670DbGate - Remote Code Execution via Dynamic Import Bypassdbgate9.4 (v4.0)Critical
CVE-2026-66398phpMyFAQ before 4.1.6 Remote Code Execution via Configuration APIphpMyFAQ9.4 (v4.0)Critical
CVE-2026-72879Dokploy: Command Injection via Registry Credentials in Swarm Uploaddokploy9.4 (v4.0)Critical
CVE-2026-73041SiYuan before v3.7.4 Remote Code Execution via PDF Annotationssiyuan9.4 (v4.0)Critical
CVE-2026-73042SiYuan before v3.7.4 Remote Code Execution via Menu Metadatasiyuan9.4 (v4.0)Critical
CVE-2026-73483Flowise before 3.1.3 Sandbox Escape via Puppeteerflowise9.4 (v4.0)Critical
CVE-2026-82244Budibase before 3.41.3 Remote Code Execution via Plugin eval()server9.4 (v4.0)Critical
CVE-2018-25114osCommerce 2.3.4.1 - Remote Code ExecutionOnline Merchant9.3 (v4.0)Critical
CVE-2018-25357Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.phpdolibarr erp/crm9.3 (v4.0)Critical
CVE-2019-25687Pegasus CMS 1.0 Remote Code Execution via extra_fields.phppegasus cms9.3 (v4.0)Critical
CVE-2024-58348WordPress Background Image Cropper 1.2 Remote Code ExecutionBackground Image Cropper9.3 (v4.0)Critical
CVE-2025-31114Fooocus webui vulnerable to Remote Code ExecutionFooocus9.3 (v4.0)Critical
CVE-2026-19586Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gatewayser7212pc firmware9.3 (v4.0)Critical
CVE-2026-44402Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgiSNMP Web Pro9.3 (v4.0)Critical
CVE-2026-53975OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/execOpenChamber9.3 (v4.0)Critical
CVE-2026-60121Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.phpflamingo9.3 (v4.0)Critical
CVE-2026-61498Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.phpflamingo9.3 (v4.0)Critical
CVE-2026-61511vBulletin 6.x - Remote Code ExecutionvBulletin9.3 (v4.0)Critical
CVE-2026-63766GPT-SoVITS 20250606v2pro OS Command Injection via webui.pyGPT-SoVITS9.3 (v4.0)Critical
CVE-2026-64625AVideo before 29.0 OS Command Injection via execAsyncAVideo9.3 (v4.0)Critical
CVE-2026-64824Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restoreHome Assistant Core9.3 (v4.0)Critical
CVE-2026-70553MaxSite CMS Unauthenticated RCE via Install EndpointMaxSite CMS9.3 (v4.0)Critical
CVE-2026-71921DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgiVigorSwitch G2540xs9.3 (v4.0)Critical
CVE-2026-71956D-Link DWR-M961 Command Injection via app.cgiDWR-M9619.3 (v4.0)Critical
CVE-2026-71984MSI Radix AXE6600 v781521 Command Injection via urlfilterRadix AXE66009.3 (v4.0)Critical
CVE-2026-71992MSI Radix AXE6600 v781521 Command Injection via macfilterRadix AXE66009.3 (v4.0)Critical
CVE-2026-76071Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost ParameterNC639.3 (v4.0)Critical
CVE-2026-10042manga-image-translator RCE via Unsafe Pickle Deserialization in Share Modelmanga-image-translator9.2 (v4.0)Critical
CVE-2026-63304AVideo through 29.0 OS Command Injection via listFFmpegProcessesAVideo9.2 (v4.0)Critical
CVE-2026-63305AVideo through 29.0 OS Command Injection via ffmpeg.json.phpAVideo9.2 (v4.0)Critical
CVE-2026-80138ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameterclipbucket-v59.2 (v4.0)Critical
CVE-2026-87930MaxSite CMS through 109.6 PHP Object Injection via ci_sessionMaxSite CMS9.2 (v4.0)Critical
CVE-2026-46621Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injectionyamcs9.1 (v3.1)Critical
CVE-2026-55511Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs executeSqlyamcs9.1 (v3.1)Critical
CVE-2026-57499Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE)core9.1 (v3.1)Critical
CVE-2026-58400GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formattercore-geonetwork9.1 (v3.1)Critical
CVE-2026-14602Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query ParameterRemote API9.0 (v3.1)Critical
CVE-2026-45630Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo Statementdokploy9.0 (v3.1)Critical
CVE-2026-73485Flowise before 3.1.3 Remote Code Execution via Airtable Agentflowise9.0 (v4.0)Critical
CVE-2026-73486Flowise before 3.1.3 Code Injection via CSV Agent customReadCSVflowise9.0 (v4.0)Critical
CVE-2026-73487Flowise before 3.1.3 Prompt Injection RCE via CSV Agentflowise9.0 (v4.0)Critical
CVE-2026-43945FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration InjectionFUXA8.9 (v4.0)High
CVE-2026-7202Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injectionA8000RU8.9 (v4.0)High
CVE-2026-7203Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injectionA8000RU8.9 (v4.0)High
CVE-2026-7204Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-73570zimbra collaboration suite Arbitrary Code Execution Vulnerabilityzimbra collaboration suite8.9 (v3.1)High
CVE-2026-9384Totolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9385Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9386Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9387Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9388Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9404Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9405Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9406Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9407Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9432Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9433Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9434Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9435Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9436Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9454Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9455Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9456Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9457Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9458Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9476Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9477Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9478Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injectionA8000RU8.9 (v4.0)High
CVE-2017-14535Trixbox - 2.8.0.4 OS Command Injectiontrixbox8.8 (v3.1)High
CVE-2017-6884Zyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command Injectionemg2926 firmware8.8 (v3.1)High
CVE-2020-15874Command Injection-8.8 (v3.1)High
CVE-2020-8163Ruby on Rails <5.0.1 - Remote Code Executionrails8.8 (v3.1)High
CVE-2024-39024In Packetfence 13.2.0, the WebGui interface setting Arbitrary Code Execution Vulnerability-8.8 (v3.1)High
CVE-2025-59710biztalk360 Arbitrary Code Execution Vulnerabilitybiztalk3608.8 (v3.1)High
CVE-2026-24893openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansionopenitcockpit8.8 (v3.1)High
CVE-2026-34197Apache ActiveMQ - Remote Code Executionactivemq8.8 (v3.1)High
CVE-2026-35196Chamilo LMS has OS Command Injection via export_all_certificates actionchamilo lms8.8 (v3.1)High
CVE-2026-45505Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia addNetworkConnector Discovery Wrapper Bypassactivemq8.8 (v3.1)High
CVE-2026-45578WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URLavideo8.8 (v3.1)High
CVE-2026-45662Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion)dokploy8.8 (v3.1)High
CVE-2026-48017DbGate: Remote Code Execution via functionName injection in loadReader endpointdbgate8.8 (v3.1)High
CVE-2026-55585QWED: Authenticated Remote Code Execution via Unsafe SymPy parse_expr()qwed-verification8.8 (v3.1)High
CVE-2026-58195Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into exagentic-flow8.8 (v3.1)High
CVE-2026-62675Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Toolsomnigent8.8 (v3.1)High
CVE-2026-72875Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFiledokploy8.8 (v3.1)High
CVE-2026-73222Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (–studio)claude-code-templates8.8 (v3.1)High
CVE-2026-78834Security Vulnerability-8.8 (v3.1)High
CVE-2026-79423the admin_config.php component of seacms v13.6 Arbitrary Code Execution Vulnerabilitythe admin config.php component of seacms v13.68.8 (v3.1)High
CVE-2026-82217Eclipse Theia Path Traversal VulnerabilityEclipse Theia8.8 (v3.1)High
CVE-2019-25671VA MAX 8.3.4 Remote Code Execution via changeip.phpVA MAX8.7 (v4.0)High
CVE-2021-47938ImpressCMS 1.4.2 Remote Code Execution via AutotasksImpressCMS8.7 (v4.0)High
CVE-2021-47943TextPattern CMS 4.8.7 Remote Code Execution via File UploadTextPattern CMS8.7 (v4.0)High
CVE-2022-50944Aero CMS 0.0.1 PHP Code Injection via posts.phpAero CMS8.7 (v4.0)High
CVE-2023-54350WordPress Augmented-Reality Plugin Remote Code Execution UnauthenticatedAugmented Reality8.7 (v4.0)High
CVE-2025-30007HestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record Managementcontrol panel8.7 (v4.0)High
CVE-2025-71260BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCEfootprints8.7 (v4.0)High
CVE-2026-34228Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Writeemlog8.7 (v4.0)High
CVE-2026-34735Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileControllerwiki8.7 (v4.0)High
CVE-2026-34792Endian Firewall /cgi-bin/logs_clamav.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34793Endian Firewall /cgi-bin/logs_firewall.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34795Endian Firewall /cgi-bin/logs_log.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34796Endian Firewall /cgi-bin/logs_openvpn.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34797Endian Firewall /cgi-bin/logs_smtp.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-47722nebula-mesh: Host advanced overrides allow YAML injection into agent config.ymlnebula-mesh8.7 (v4.0)High
CVE-2026-49143BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handlerbrowserstack-runner8.7 (v4.0)High
CVE-2026-63722ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.phpICEcoder8.7 (v4.0)High
CVE-2026-67206Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Uploadwolfcms8.7 (v4.0)High
CVE-2026-69096OpenWrt luci-app-dockerman Read ACL Remote Code Executionluci8.7 (v4.0)High
CVE-2026-69100LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Executionlamp-cloud8.7 (v4.0)High
CVE-2026-71966CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfercyberpanel8.7 (v4.0)High
CVE-2026-71981Cypht < 2.12.2 PHP Object Injection RCE via back_query Parametercypht8.7 (v4.0)High
CVE-2026-72819Grav CMS before 2.0.13 Remote Code Execution via ZIP Uploadgrav8.7 (v4.0)High
CVE-2026-72830Grav API Plugin before 1.0.13 RCE via ConfigController scope bypassgrav8.7 (v4.0)High
CVE-2026-72870Dokploy: Command Injection via Docker Credentials in buildRemoteDockerdokploy8.7 (v4.0)High
CVE-2026-73680Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg FilenameCockpit CMS8.7 (v4.0)High
CVE-2026-76060OS Command Injection in PayRange APIZoneminder8.7 (v4.0)High
CVE-2026-78416Authenticated RCE via condition.config JSON cleanse bypasscms8.7 (v4.0)High
CVE-2026-79756Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platformnuclio8.7 (v4.0)High
CVE-2026-82278BISHENG Authenticated Arbitrary Python Code Execution via Workflow run_oncebisheng8.7 (v4.0)High
CVE-2026-86732Craft CMS before 5.10.12 Remote Code Execution via element-indexcms8.7 (v4.0)High
CVE-2024-20353adaptive security appliance software Denial of Service Vulnerabilityadaptive security appliance software8.6 (v3.1)High
CVE-2026-40187Authenticated RCE via Malicious eTemplate Upload in EGroupwareegroupware8.6 (v4.0)High
CVE-2026-42785OpenKM 6.3.12 Remote Code Execution via Administrative ScriptingOpenKM Community Edition8.6 (v4.0)High
CVE-2026-55182LibreNMS: Remote Code Execution by Signal Alert Transportation Modulelibrenms8.6 (v4.0)High
CVE-2026-56703Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTOadminer8.6 (v4.0)High
CVE-2026-61517Netis NX10 OS Command Injection via Ping Diagnostic HandlerNX108.6 (v4.0)High
CVE-2026-61523WebsiteBaker CMS < 2.13.10 Code Injection via Droplets EditorWebsiteBaker CMS8.6 (v4.0)High
CVE-2026-63725sysPass FileBackupService Authenticated OS Command Injection via Backup PathsysPass8.6 (v4.0)High
CVE-2026-65693Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templatesmicroweber8.6 (v4.0)High
CVE-2026-65711sysPass 3.2.11 Authenticated OS Command Injection via Backup PathsysPass8.6 (v4.0)High
CVE-2026-67599ClearOS 7.9 OS Command Injection via Log Viewer filter parameterClearOS8.6 (v4.0)High
CVE-2026-67608Telenia TVox 26.5.3 OS Command Injection via action_audio.phpTVox8.6 (v4.0)High
CVE-2026-69088Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprintgrav8.6 (v4.0)High
CVE-2026-71906DrayTek VigorAP Multiple Models OS Command Injection via setLanVigorAP 918R8.6 (v4.0)High
CVE-2026-71907DrayTek VigorAP Multiple Models OS Command Injection via setcamsetVigorAP 918R8.6 (v4.0)High
CVE-2026-71908DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_testVigorAP 918R8.6 (v4.0)High
CVE-2026-71913DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgiVigorAP 918R8.6 (v4.0)High
CVE-2026-71915DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatusVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71918DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupActionVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71919DrayTek VigorSwitch Multiple Models OS Command Injection via sysrebootVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71923DrayTek VigorSwitch Multiple Models OS Command Injection via auth_setVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71925DrayTek VigorSwitch Multiple Models OS Command Injection via getDetailVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71926DrayTek VigorSwitch Multiple Models OS Command Injection via setDeviceVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71927DrayTek VigorSwitch Multiple Models OS Command Injection via rebDeviceVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71928DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDeviceVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71929DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProtoVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71930DrayTek VigorSwitch Multiple Models OS Command Injection via setTimeVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71943DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNetVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-73664FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Modulebackup8.6 (v4.0)High
CVE-2026-75121PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_postPLANET GS-4210-16P2S V38.6 (v4.0)High
CVE-2026-75123PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_postPLANET GS-4210-16P2S V38.6 (v4.0)High
CVE-2026-84194LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostnamelibrenms8.6 (v4.0)High
CVE-2026-85223D-Link DNS-340L CGI dropbox.cgi os command injectionDNS-340L8.6 (v4.0)High
CVE-2026-86437Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Uploadlaradashboard8.6 (v4.0)High
CVE-2026-86733Snipe-IT before 8.7.0 Remote Code Execution via Backup Restoresnipe-it8.6 (v4.0)High
CVE-2026-22244OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCEopenmetadata8.5 (v4.0)High
CVE-2026-82691D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injectionDNS-320L8.5 (v4.0)High
CVE-2025-59711biztalk360 Path Traversal Vulnerabilitybiztalk3608.3 (v3.1)High
CVE-2026-49471Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCEserena8.3 (v3.1)High
CVE-2026-42588Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnectoractivemq8.1 (v3.1)High
CVE-2026-47398PraisonAI: Arbitrary code execution via unguarded spec.loader.exec_module in agents_generator.py - sibling of CVE-20PraisonAI8.1 (v3.1)High
CVE-2026-48695fastnetmon Command Injection Vulnerabilityfastnetmon8.1 (v3.1)High
CVE-2026-71320Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Propsnuxt8.1 (v3.1)High
CVE-2015-4669Xceedium Xsuite - Multiple Vulnerabilitiesxsuite7.8 (v3.0)High
CVE-2026-67179Genkit improper host header validationgenkit7.8 (v3.1)High
CVE-2025-27621UpTrain has a Constant Default API Keyuptrain7.7 (v4.0)High
CVE-2026-40519Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()nginx-proxy-manager7.7 (v4.0)High
CVE-2026-66738SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLiteSPIP7.7 (v4.0)High
CVE-2026-19913Kaltura HTML5 Video Player, html5lib library Improper Input Validation VulnerabilityKaltura HTML5 Video Player, html5lib library7.5 (v3.1)High
CVE-2026-34239Chamilo Authenticated Remote Code Executionchamilo-lms7.5 (v4.0)High
CVE-2026-36783Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to Denial of Service Vulnerability-7.5 (v3.1)High
CVE-2026-46581mojarra Path Traversal Vulnerabilitymojarra7.5 (v3.1)High
CVE-2026-51078Dede CMS v.5.7.118 Information Disclosure Vulnerability-7.5 (v3.1)High
CVE-2026-53599Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mocore7.5 (v3.1)High
CVE-2026-10870Shibby Tomato Web UI rc start_dhcpc os command injectionTomato7.3 (v4.0)High
CVE-2026-10871Shibby Tomato Web UI rc start_6rd_tunnel os command injectionTomato7.3 (v4.0)High
CVE-2026-10873Shibby Tomato Web UI rstats rstats_path os command injectionTomato7.3 (v4.0)High
CVE-2026-18900H3C NX15 Backend RPC esps file.exec os command injectionNX157.3 (v4.0)High
CVE-2026-19771Baicells EG3661M LuCI Web luci os command injectionEG3661M7.3 (v4.0)High
CVE-2026-71284Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filenamefledge7.2 (v3.1)High
CVE-2026-71964CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Uploadcyberpanel7.1 (v4.0)High
CVE-2026-77939Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpointflextype7.1 (v4.0)High
CVE-2025-71257BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypassfootprints itsm6.9 (v4.0)Medium
CVE-2026-11450GL.iNet GL-MT3000 Path Normalization dlopen command injectionGL-MT30006.9 (v4.0)Medium
CVE-2026-19983GL.iNet XE3000 NAS Command Service gl_nas_sys os command injectionA13006.9 (v4.0)Medium
CVE-2026-5739PowerJob OpenAPI Endpoint addWorkflowNode GroovyEvaluator.evaluate code injectionPowerJob6.9 (v4.0)Medium
CVE-2025-59709biztalk360 Path Traversal Vulnerabilitybiztalk3606.8 (v3.1)Medium
CVE-2026-10821Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCEYoast SEO Premium6.6 (v3.1)Medium
CVE-2026-34216CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in SettingsController.phppanel6.6 (v3.1)Medium
CVE-2026-72739Dokploy: Command Injection via Compose Shell Executiondokploy6.5 (v3.1)Medium
CVE-2026-44287FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*(/ is bypassableFastGPT6.3 (v3.1)Medium
CVE-2026-45626Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameterarcane6.3 (v3.1)Medium
CVE-2015-4668Xceedium Xsuite - Multiple Vulnerabilitiesxsuite6.1 (v3.0)Medium
CVE-2025-13786taosir WTCMS index.php fetch code injectionwtcms5.5 (v4.0)Medium
CVE-2025-13792Qualitor getResumo.php eval code injectionQualitor5.5 (v4.0)Medium
CVE-2026-10214zhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injectionchatgpt-on-wechat5.5 (v4.0)Medium
CVE-2026-18641Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginCOperation and Maintenance Security Management System5.5 (v4.0)Medium
CVE-2026-19379EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injectionipTIME AX8004M5.5 (v4.0)Medium
CVE-2026-54611InstantCMS has Remote Code Execution in package installericms25.5 (v3.1)Medium
CVE-2026-5631assafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injectiongpt-researcher5.5 (v4.0)Medium
CVE-2026-5677Totolink A7100RU cstecgi.cgi CsteSystem os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5678Totolink A7100RU cstecgi.cgi setScheduleCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5688Totolink A7100RU cstecgi.cgi setDdnsCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5689Totolink A7100RU cstecgi.cgi setNtpCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5690Totolink A7100RU cstecgi.cgi setRemoteCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5691Totolink A7100RU cstecgi.cgi setFirewallType os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5692Totolink A7100RU cstecgi.cgi setGameSpeedCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5736PowerJob detailPlus Endpoint InstanceController.java sql injectionPowerJob5.5 (v4.0)Medium
CVE-2026-5741suvarchal docker-mcp-server HTTP index.ts pull_image os command injectiondocker-mcp-server5.5 (v4.0)Medium
CVE-2026-5802idachev mcp-javadc HTTP os command injectionmcp-javadc5.5 (v4.0)Medium
CVE-2026-7220jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injectionFastlyMCP5.5 (v4.0)Medium
CVE-2026-76760chenhg5 cc-connect webhook.go authenticate code injectioncc-connect5.5 (v4.0)Medium
CVE-2026-76761chenhg5 cc-connect Management API engine.go shellExecCommand os command injectioncc-connect5.5 (v4.0)Medium
CVE-2026-82598SeaCMS Template search.php parseIf code injectionSeaCMS5.5 (v4.0)Medium
CVE-2026-85137SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injectionSeaCMS5.5 (v4.0)Medium
CVE-2026-9474yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injectionStudentManagementSystem5.5 (v4.0)Medium
CVE-2026-54543Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fieldsfroxlor5.4 (v3.1)Medium
CVE-2023-7299DataGear resolveSql sql injectiondatagear5.3 (v4.0)Medium
CVE-2026-19785francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injectionRosarioSIS5.3 (v4.0)Medium
CVE-2015-4666Xceedium Xsuite - Multiple Vulnerabilitiesxsuite5.0 (v2.0)Medium
CVE-2015-4665Xceedium Xsuite - Multiple Vulnerabilitiesxsuite4.3 (v2.0)Medium
CVE-2026-36239PbootCMS v.3.2.11 Cross-site Scripting VulnerabilityPbootCMS v.3.2.114.3 (v3.1)Medium
CVE-2026-16297Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings ImportClearfy Cache4.1 (v3.1)Medium
CVE-2023-3360Weaver Show Posts < 1.8.1 - Admin+ PHP Object InjectionWeaver Show Posts3.3 (v3.1)Low
CVE-2026-10172Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted uploadMulti-Store Inventory Management System2.1 (v4.0)Low
CVE-2026-10279hiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injectionwezterm-mcp2.1 (v4.0)Low
CVE-2026-11408vertex-app vertex Log Viewer Endpoint LogMod.js os command injectionvertex2.1 (v4.0)Low
CVE-2026-19932DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.evaluate code injectionNotice-System-Managent2.1 (v4.0)Low
CVE-2026-19958iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injectionpptr-mcp2.1 (v4.0)Low
CVE-2026-5351Trendnet TEW-657BRM setup.cgi add_wps_client os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5352Trendnet TEW-657BRM setup.cgi edit os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5353Trendnet TEW-657BRM setup.cgi ping_test os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5354Trendnet TEW-657BRM setup.cgi vpn_connect os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5355Trendnet TEW-657BRM setup.cgi vpn_drop os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-78166provectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest code injectionkafka-ui2.1 (v4.0)Low
CVE-2026-8188Wavlink NU516U1 adm.cgi change_wifi_password os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8189Wavlink NU516U1 adm.cgi wzdrepeater os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8190Wavlink NU516U1 adm.cgi wan os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8191Wavlink NU516U1 adm.cgi wifi_region os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8192Wavlink NU516U1 adm.cgi wzdap os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8227Wavlink NU516U1 adm.cgi wzdapMesh os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8228Wavlink NU516U1 wireless.cgi advance os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8229Wavlink NU516U1 wireless.cgi WifiBasic os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8230Wavlink NU516U1 login.cgi sys_login1 os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-9302546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injectionvps-inventory-monitoring2.1 (v4.0)Low
CVE-2026-9511Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9512Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9514Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9515Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9531Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9532Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9533Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9534Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-19964Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injectionJij-MCP-Server2.0 (v4.0)Low
CVE-2026-78140Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engineUJCMS2.0 (v4.0)Low
CVE-2026-85040ZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injectionCRMEB2.0 (v4.0)Low
CVE-2026-16129princezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklistSafestClaw1.9 (v4.0)Low
CVE-2026-5621ChrisChinchilla Vale-MCP HTTP index.ts os command injectionVale-MCP1.9 (v4.0)Low
CVE-2026-19353DedeCMS Installation Wizard index.php _4_Setup file inclusionDedeCMS1.3 (v4.0)Low

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-20CVE-2026-47668 , CVE-2015-4664 , CVE-2026-19912 , CVE-2026-35048 , CVE-2026-57499 , CVE-2026-24893 , CVE-2026-34197 , CVE-2026-45505 , CVE-2026-42588 , CVE-2026-19913
CWE-22CVE-2026-19912 , CVE-2019-25687 , CVE-2026-64824 , CVE-2026-82217 , CVE-2019-25671 , CVE-2025-59711 , CVE-2026-46581 , CVE-2025-59709 , CVE-2015-4666
CWE-59CVE-2026-71964
CWE-73CVE-2026-19913 , CVE-2026-19353
CWE-74CVE-2018-16763 , CVE-2022-35914 , CVE-2026-71320 , CVE-2026-11450 , CVE-2026-5739 , CVE-2026-10821 , CVE-2025-13786 , CVE-2025-13792 , CVE-2026-5631 , CVE-2026-5736 , CVE-2026-76760 , CVE-2026-82598 , CVE-2026-85137 , CVE-2026-9474 , CVE-2026-54543 , CVE-2023-7299 , CVE-2026-19785 , CVE-2026-19932 , CVE-2026-19958 , CVE-2026-78166 , CVE-2026-9302 , CVE-2026-19964
CWE-77CVE-2026-72869 , CVE-2014-1203 , CVE-2026-35847 , CVE-2026-47670 , CVE-2026-7202 , CVE-2026-7203 , CVE-2026-7204 , CVE-2026-9384 , CVE-2026-9385 , CVE-2026-9386 , CVE-2026-9387 , CVE-2026-9388 , CVE-2026-9404 , CVE-2026-9405 , CVE-2026-9406 , CVE-2026-9407 , CVE-2026-9432 , CVE-2026-9433 , CVE-2026-9434 , CVE-2026-9435 , CVE-2026-9436 , CVE-2026-9454 , CVE-2026-9455 , CVE-2026-9456 , CVE-2026-9457 , CVE-2026-9458 , CVE-2026-9476 , CVE-2026-9477 , CVE-2026-9478 , CVE-2020-15874 , CVE-2026-55182 , CVE-2026-85223 , CVE-2026-82691 , CVE-2026-10870 , CVE-2026-10871 , CVE-2026-10873 , CVE-2026-18900 , CVE-2026-19771 , CVE-2026-11450 , CVE-2026-19983 , CVE-2026-10214 , CVE-2026-18641 , CVE-2026-19379 , CVE-2026-5677 , CVE-2026-5678 , CVE-2026-5688 , CVE-2026-5689 , CVE-2026-5690 , CVE-2026-5691 , CVE-2026-5692 , CVE-2026-5741 , CVE-2026-5802 , CVE-2026-7220 , CVE-2026-76761 , CVE-2026-10279 , CVE-2026-11408 , CVE-2026-5351 , CVE-2026-5352 , CVE-2026-5353 , CVE-2026-5354 , CVE-2026-5355 , CVE-2026-8188 , CVE-2026-8189 , CVE-2026-8190 , CVE-2026-8191 , CVE-2026-8192 , CVE-2026-8227 , CVE-2026-8228 , CVE-2026-8229 , CVE-2026-8230 , CVE-2026-9511 , CVE-2026-9512 , CVE-2026-9514 , CVE-2026-9515 , CVE-2026-9531 , CVE-2026-9532 , CVE-2026-9533 , CVE-2026-9534 , CVE-2026-85040 , CVE-2026-5621
CWE-78CVE-2025-34037 , CVE-2026-19188 , CVE-2026-34234 , CVE-2026-49869 , CVE-2026-8985 , CVE-2026-45632 , CVE-2026-63298 , CVE-2026-72868 , CVE-2026-72869 , CVE-2026-72882 , CVE-2026-73263 , CVE-2026-73294 , CVE-2019-12725 , CVE-2019-15107 , CVE-2019-16920 , CVE-2020-15920 , CVE-2020-29390 , CVE-2020-9054 , CVE-2022-31137 , CVE-2024-53584 , CVE-2026-12940 , CVE-2026-18482 , CVE-2026-37281 , CVE-2026-45018 , CVE-2026-48687 , CVE-2026-79408 , CVE-2026-72878 , CVE-2026-8986 , CVE-2026-47670 , CVE-2026-72879 , CVE-2026-73483 , CVE-2026-19586 , CVE-2026-53975 , CVE-2026-60121 , CVE-2026-61498 , CVE-2026-63766 , CVE-2026-64625 , CVE-2026-71921 , CVE-2026-71956 , CVE-2026-71984 , CVE-2026-71992 , CVE-2026-63304 , CVE-2026-63305 , CVE-2026-80138 , CVE-2026-57499 , CVE-2026-45630 , CVE-2026-7202 , CVE-2026-7203 , CVE-2026-7204 , CVE-2026-73570 , CVE-2026-9384 , CVE-2026-9385 , CVE-2026-9386 , CVE-2026-9387 , CVE-2026-9388 , CVE-2026-9404 , CVE-2026-9405 , CVE-2026-9406 , CVE-2026-9407 , CVE-2026-9432 , CVE-2026-9433 , CVE-2026-9434 , CVE-2026-9435 , CVE-2026-9436 , CVE-2026-9454 , CVE-2026-9455 , CVE-2026-9456 , CVE-2026-9457 , CVE-2026-9458 , CVE-2026-9476 , CVE-2026-9477 , CVE-2026-9478 , CVE-2017-14535 , CVE-2017-6884 , CVE-2026-24893 , CVE-2026-34197 , CVE-2026-35196 , CVE-2026-45578 , CVE-2026-45662 , CVE-2026-58195 , CVE-2026-72875 , CVE-2026-73222 , CVE-2026-79423 , CVE-2025-30007 , CVE-2026-34792 , CVE-2026-34793 , CVE-2026-34795 , CVE-2026-34796 , CVE-2026-34797 , CVE-2026-69096 , CVE-2026-71966 , CVE-2026-72870 , CVE-2026-73680 , CVE-2026-76060 , CVE-2026-79756 , CVE-2026-40187 , CVE-2026-61517 , CVE-2026-63725 , CVE-2026-65711 , CVE-2026-67599 , CVE-2026-67608 , CVE-2026-71906 , CVE-2026-71907 , CVE-2026-71908 , CVE-2026-71913 , CVE-2026-71915 , CVE-2026-71918 , CVE-2026-71919 , CVE-2026-71923 , CVE-2026-71925 , CVE-2026-71926 , CVE-2026-71927 , CVE-2026-71928 , CVE-2026-71929 , CVE-2026-71930 , CVE-2026-71943 , CVE-2026-75121 , CVE-2026-75123 , CVE-2026-84194 , CVE-2026-85223 , CVE-2026-86733 , CVE-2026-82691 , CVE-2026-48695 , CVE-2026-40519 , CVE-2026-10870 , CVE-2026-10871 , CVE-2026-10873 , CVE-2026-18900 , CVE-2026-19771 , CVE-2026-71284 , CVE-2026-19983 , CVE-2026-72739 , CVE-2026-45626 , CVE-2026-10214 , CVE-2026-18641 , CVE-2026-19379 , CVE-2026-5677 , CVE-2026-5678 , CVE-2026-5688 , CVE-2026-5689 , CVE-2026-5690 , CVE-2026-5691 , CVE-2026-5692 , CVE-2026-5741 , CVE-2026-5802 , CVE-2026-7220 , CVE-2026-76761 , CVE-2026-10279 , CVE-2026-11408 , CVE-2026-5351 , CVE-2026-5352 , CVE-2026-5353 , CVE-2026-5354 , CVE-2026-5355 , CVE-2026-8188 , CVE-2026-8189 , CVE-2026-8190 , CVE-2026-8191 , CVE-2026-8192 , CVE-2026-8227 , CVE-2026-8228 , CVE-2026-8229 , CVE-2026-8230 , CVE-2026-9511 , CVE-2026-9512 , CVE-2026-9514 , CVE-2026-9515 , CVE-2026-9531 , CVE-2026-9532 , CVE-2026-9533 , CVE-2026-9534 , CVE-2026-85040 , CVE-2026-5621
CWE-79CVE-2026-73041 , CVE-2026-73042 , CVE-2024-39024 , CVE-2015-4665 , CVE-2026-36239
CWE-88CVE-2026-44450 , CVE-2026-73294 , CVE-2020-21224
CWE-89CVE-2026-33324 , CVE-2015-4669 , CVE-2026-5736 , CVE-2026-9474 , CVE-2023-7299 , CVE-2026-19785
CWE-93CVE-2026-84372
CWE-94CVE-2026-47668 , CVE-2026-8984 , CVE-2025-24893 , CVE-2026-31040 , CVE-2026-38431 , CVE-2026-46562 , CVE-2026-67919 , CVE-2026-75411 , CVE-2026-75414 , CVE-2025-62593 , CVE-2026-45272 , CVE-2026-82244 , CVE-2018-25114 , CVE-2018-25357 , CVE-2026-70553 , CVE-2026-46621 , CVE-2026-55511 , CVE-2026-58400 , CVE-2026-14602 , CVE-2026-73485 , CVE-2026-73486 , CVE-2026-73487 , CVE-2026-43945 , CVE-2020-8163 , CVE-2026-34197 , CVE-2026-45505 , CVE-2026-48017 , CVE-2026-55585 , CVE-2026-62675 , CVE-2026-78834 , CVE-2021-47938 , CVE-2022-50944 , CVE-2026-47722 , CVE-2026-49143 , CVE-2026-69100 , CVE-2026-72819 , CVE-2026-82278 , CVE-2026-86732 , CVE-2026-42785 , CVE-2026-56703 , CVE-2026-61523 , CVE-2026-65693 , CVE-2026-69088 , CVE-2026-22244 , CVE-2026-42588 , CVE-2026-47398 , CVE-2026-71320 , CVE-2026-66738 , CVE-2026-46581 , CVE-2026-77939 , CVE-2026-5739 , CVE-2026-44287 , CVE-2025-13786 , CVE-2025-13792 , CVE-2026-54611 , CVE-2026-5631 , CVE-2026-76760 , CVE-2026-82598 , CVE-2026-85137 , CVE-2026-19932 , CVE-2026-19958 , CVE-2026-78166 , CVE-2026-9302 , CVE-2026-19964
CWE-95CVE-2024-7954 , CVE-2025-24893 , CVE-2026-46562 , CVE-2026-47391 , CVE-2025-31114 , CVE-2026-61511 , CVE-2026-40187
CWE-121CVE-2026-76071 , CVE-2026-36783
CWE-183CVE-2026-16129
CWE-184CVE-2026-49869 , CVE-2026-44287 , CVE-2026-16129
CWE-200CVE-2026-51078
CWE-269CVE-2026-45632 , CVE-2026-72830 , CVE-2026-73664
CWE-284CVE-2026-34234 , CVE-2026-43945 , CVE-2026-73664 , CVE-2026-10172
CWE-285CVE-2026-34239
CWE-287CVE-2026-49869 , CVE-2025-27621
CWE-288CVE-2026-43945
CWE-306CVE-2026-81735 , CVE-2026-47391 , CVE-2026-53649 , CVE-2026-73222 , CVE-2023-54350 , CVE-2026-63722 , CVE-2026-49471 , CVE-2025-71257
CWE-352CVE-2026-53649 , CVE-2025-62593 , CVE-2026-73222 , CVE-2026-34228 , CVE-2026-49471
CWE-434CVE-2026-72592 , CVE-2026-53649 , CVE-2018-25114 , CVE-2024-58348 , CVE-2026-44402 , CVE-2025-59710 , CVE-2021-47943 , CVE-2026-34735 , CVE-2026-67206 , CVE-2026-53599 , CVE-2026-54611 , CVE-2026-10172
CWE-470CVE-2026-46562 , CVE-2026-58400 , CVE-2026-34216
CWE-494CVE-2026-66398
CWE-502CVE-2026-34838 , CVE-2026-3296 , CVE-2026-10042 , CVE-2026-87930 , CVE-2025-71260 , CVE-2026-71981 , CVE-2026-16297 , CVE-2023-3360
CWE-601CVE-2015-4668
CWE-641CVE-2026-46581
CWE-644CVE-2026-67179
CWE-732CVE-2026-73664
CWE-791CVE-2026-78140
CWE-798CVE-2015-4667
CWE-829CVE-2026-45272 , CVE-2026-47398
CWE-835CVE-2024-20353
CWE-862CVE-2026-45632 , CVE-2026-72868
CWE-863CVE-2026-43945 , CVE-2026-86437
CWE-913CVE-2020-15568
CWE-915CVE-2026-78416
CWE-918CVE-2026-49869
CWE-942CVE-2026-34449 , CVE-2026-53649
CWE-1188CVE-2026-47668
CWE-1286CVE-2024-7954
CWE-1336CVE-2026-44181 , CVE-2026-22244 , CVE-2026-77939 , CVE-2026-78140