On this page
Atomicorp WAF Rule 340023
Rule Summary
- Rule ID: 340023
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Attack Blocked - remote command execution
- Observed CWEs: CWE-20 (10), CWE-22 (9), CWE-59 (1), CWE-73 (2), CWE-74 (22), CWE-77 (80), CWE-78 (173), CWE-79 (5), CWE-88 (3), CWE-89 (6), CWE-93 (1), CWE-94 (64), CWE-95 (7), CWE-121 (2), CWE-183 (1), CWE-184 (3), CWE-200 (1), CWE-269 (3), CWE-284 (4), CWE-285 (1), CWE-287 (2), CWE-288 (1), CWE-306 (8), CWE-352 (5), CWE-434 (12), CWE-470 (3), CWE-494 (1), CWE-502 (8), CWE-601 (1), CWE-641 (1), CWE-644 (1), CWE-732 (1), CWE-791 (1), CWE-798 (1), CWE-829 (2), CWE-835 (1), CWE-862 (2), CWE-863 (2), CWE-913 (1), CWE-915 (1), CWE-918 (1), CWE-942 (2), CWE-1188 (1), CWE-1286 (1), CWE-1336 (4)
- Revision: 7
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request URI, Request arguments, JSON request data, SOAP request data
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Attack Blocked - remote command execution” in the request URI, request arguments, JSON request data, SOAP request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2025-34037 | Linksys Routers E/WAG/WAP/WES/WET/WRT-Series | E4200 | 10.0 (v4.0) | Critical |
| CVE-2026-19188 | Haiwell IoT Cloud HMI Gateway OS Command Injection | Haiwell IoT Cloud HMI Gateway | 10.0 (v4.0) | Critical |
| CVE-2026-34234 | CtrlPanel: Unauthenticated RCE using installer script | panel | 10.0 (v3.1) | Critical |
| CVE-2026-44181 | Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution | enterprise gateway | 10.0 (v4.0) | Critical |
| CVE-2026-47668 | DbGate - Remote Code Execution via Anonymous JWT | dbgate | 10.0 (v3.1) | Critical |
| CVE-2026-49869 | Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in AuthenticationFilter | kestra | 10.0 (v3.1) | Critical |
| CVE-2026-81735 | UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command Executi | UI-TARS-desktop | 10.0 (v4.0) | Critical |
| CVE-2026-8984 | Unauthenticated RCE | maxicharger single charger firmware | 10.0 (v4.0) | Critical |
| CVE-2026-8985 | Unauthenticated Command Injection | maxicharger single charger firmware | 10.0 (v4.0) | Critical |
| CVE-2026-34838 | Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in AbstractSettingsCollection | group-office | 9.9 (v3.1) | Critical |
| CVE-2026-44450 | Lumiverse: RCE via MCP stdio argument injection | Lumiverse | 9.9 (v3.1) | Critical |
| CVE-2026-45632 | Dokploy: Schedule Authorization Bypass Enables Host/Server Command Execution | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-63298 | LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration | LXD | 9.9 (v3.1) | Critical |
| CVE-2026-72868 | Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72869 | Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72882 | Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-73263 | Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-path | prowler | 9.9 (v3.1) | Critical |
| CVE-2026-73294 | Semaphore U: OS Command Injection | semaphore | 9.9 (v3.1) | Critical |
| CVE-2014-1203 | Eyou E-Mail <3.6 - Remote Code Execution | eyou | 9.8 (v3.1) | Critical |
| CVE-2015-4664 | Xceedium Xsuite - Multiple Vulnerabilities | privileged access manager | 9.8 (v3.0) | Critical |
| CVE-2015-4667 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 9.8 (v3.0) | Critical |
| CVE-2018-16763 | FUEL CMS 1.4.1 - Remote Code Execution | fuel cms | 9.8 (v3.1) | Critical |
| CVE-2019-12725 | Zeroshell 3.9.0 - Remote Command Execution | zeroshell | 9.8 (v3.0) | Critical |
| CVE-2019-15107 | Webmin <= 1.920 - Unauthenticated Remote Command Execution | webmin | 9.8 (v3.1) | Critical |
| CVE-2019-16920 | D-Link Routers - Remote Code Execution | dir-655 firmware | 9.8 (v3.1) | Critical |
| CVE-2020-15568 | TerraMaster TOS <.1.29 - Remote Code Execution | tos | 9.8 (v3.1) | Critical |
| CVE-2020-15920 | Mida eFramework <=2.9.0 - Remote Command Execution | eframework | 9.8 (v3.1) | Critical |
| CVE-2020-21224 | Inspur ClusterEngine 4.0 - Remote Code Execution | clusterengine | 9.8 (v3.1) | Critical |
| CVE-2020-29390 | Zeroshell 3.9.3 - Command Injection | zeroshell | 9.8 (v3.1) | Critical |
| CVE-2020-9054 | Zyxel NAS Firmware 5.21- Remote Code Execution | nas326 firmware | 9.8 (v3.1) | Critical |
| CVE-2022-31137 | Roxy-WI < 6.1.1.0 - Remote Code Execution | roxy-wi | 9.8 (v3.1) | Critical |
| CVE-2022-35914 | GLPI <=10.0.2 - Remote Command Execution | glpi | 9.8 (v3.1) | Critical |
| CVE-2024-53584 | OpenPanel 0.3.4 - OS Command Injection | openpanel | 9.8 (v3.1) | Critical |
| CVE-2024-7954 | SPIP Porte Plume Plugin - Remote Code Execution | SPIP | 9.8 (v3.1) | Critical |
| CVE-2025-24893 | XWiki Platform - Remote Code Execution | xwiki | 9.8 (v3.1) | Critical |
| CVE-2026-12940 | Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoint | langflow | 9.8 (v3.1) | Critical |
| CVE-2026-18482 | neo-mjs Command Injection Vulnerability | neo-mjs | 9.8 (v3.1) | Critical |
| CVE-2026-19912 | Kaltura HTML5 Video Player, html5 library Arbitrary Code Execution Vulnerability | Kaltura HTML5 Video Player, html5 library | 9.8 (v3.1) | Critical |
| CVE-2026-31040 | stata-mcp Code Injection Vulnerability | stata-mcp | 9.8 (v3.1) | Critical |
| CVE-2026-3296 | Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | 9.8 (v3.1) | Critical |
| CVE-2026-35048 | Piwigo RCE via PHP Code Injection into Config File in Installer | Piwigo | 9.8 (v3.1) | Critical |
| CVE-2026-35847 | dnsmgr 2.15 and Earlier Arbitrary Code Execution Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-37281 | the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 Command Injection Vulnerability | the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 | 9.8 (v3.1) | Critical |
| CVE-2026-38431 | erpnext Code Injection Vulnerability | erpnext | 9.8 (v3.1) | Critical |
| CVE-2026-45018 | Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution | chainlit | 9.8 (v3.1) | Critical |
| CVE-2026-46562 | Yamcs: Remote Code Execution via Mission Database algorithm override | yamcs | 9.8 (v3.1) | Critical |
| CVE-2026-47391 | PraisonAI's unauthenticated A2A official example can reach real LLM-driven eval() tool execution | PraisonAI | 9.8 (v3.1) | Critical |
| CVE-2026-48687 | fastnetmon Command Injection Vulnerability | fastnetmon | 9.8 (v3.1) | Critical |
| CVE-2026-67919 | Halo 2.25.4 Arbitrary Code Execution Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-72592 | dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload | phpfm | 9.8 (v3.1) | Critical |
| CVE-2026-75411 | JeecgBoot v3.9.2 Code Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-75414 | In AntFlow V2.0.0, ActivitiTest.java Code Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-79408 | MetaGPT 0.8.1 Command Injection Vulnerability | MetaGPT 0.8.1 | 9.8 (v3.1) | Critical |
| CVE-2026-84372 | Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections | predis | 9.8 (v3.1) | Critical |
| CVE-2026-34449 | SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection | siyuan | 9.6 (v3.1) | Critical |
| CVE-2026-53649 | Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE | joro | 9.6 (v3.1) | Critical |
| CVE-2026-72878 | Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments | dokploy | 9.6 (v3.1) | Critical |
| CVE-2026-8986 | Command Injection via Malicious OCPP Server | maxicharger single charger firmware | 9.5 (v4.0) | Critical |
| CVE-2025-62593 | Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack | ray | 9.4 (v4.0) | Critical |
| CVE-2026-33324 | SQLBot prompt injection allows arbitrary SQL execution and remote code execution | sqlbot | 9.4 (v4.0) | Critical |
| CVE-2026-45272 | MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File | talebook | 9.4 (v4.0) | Critical |
| CVE-2026-47670 | DbGate - Remote Code Execution via Dynamic Import Bypass | dbgate | 9.4 (v4.0) | Critical |
| CVE-2026-66398 | phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API | phpMyFAQ | 9.4 (v4.0) | Critical |
| CVE-2026-72879 | Dokploy: Command Injection via Registry Credentials in Swarm Upload | dokploy | 9.4 (v4.0) | Critical |
| CVE-2026-73041 | SiYuan before v3.7.4 Remote Code Execution via PDF Annotations | siyuan | 9.4 (v4.0) | Critical |
| CVE-2026-73042 | SiYuan before v3.7.4 Remote Code Execution via Menu Metadata | siyuan | 9.4 (v4.0) | Critical |
| CVE-2026-73483 | Flowise before 3.1.3 Sandbox Escape via Puppeteer | flowise | 9.4 (v4.0) | Critical |
| CVE-2026-82244 | Budibase before 3.41.3 Remote Code Execution via Plugin eval() | server | 9.4 (v4.0) | Critical |
| CVE-2018-25114 | osCommerce 2.3.4.1 - Remote Code Execution | Online Merchant | 9.3 (v4.0) | Critical |
| CVE-2018-25357 | Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php | dolibarr erp/crm | 9.3 (v4.0) | Critical |
| CVE-2019-25687 | Pegasus CMS 1.0 Remote Code Execution via extra_fields.php | pegasus cms | 9.3 (v4.0) | Critical |
| CVE-2024-58348 | WordPress Background Image Cropper 1.2 Remote Code Execution | Background Image Cropper | 9.3 (v4.0) | Critical |
| CVE-2025-31114 | Fooocus webui vulnerable to Remote Code Execution | Fooocus | 9.3 (v4.0) | Critical |
| CVE-2026-19586 | Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways | er7212pc firmware | 9.3 (v4.0) | Critical |
| CVE-2026-44402 | Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi | SNMP Web Pro | 9.3 (v4.0) | Critical |
| CVE-2026-53975 | OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec | OpenChamber | 9.3 (v4.0) | Critical |
| CVE-2026-60121 | Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php | flamingo | 9.3 (v4.0) | Critical |
| CVE-2026-61498 | Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php | flamingo | 9.3 (v4.0) | Critical |
| CVE-2026-61511 | vBulletin 6.x - Remote Code Execution | vBulletin | 9.3 (v4.0) | Critical |
| CVE-2026-63766 | GPT-SoVITS 20250606v2pro OS Command Injection via webui.py | GPT-SoVITS | 9.3 (v4.0) | Critical |
| CVE-2026-64625 | AVideo before 29.0 OS Command Injection via execAsync | AVideo | 9.3 (v4.0) | Critical |
| CVE-2026-64824 | Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore | Home Assistant Core | 9.3 (v4.0) | Critical |
| CVE-2026-70553 | MaxSite CMS Unauthenticated RCE via Install Endpoint | MaxSite CMS | 9.3 (v4.0) | Critical |
| CVE-2026-71921 | DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi | VigorSwitch G2540xs | 9.3 (v4.0) | Critical |
| CVE-2026-71956 | D-Link DWR-M961 Command Injection via app.cgi | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71984 | MSI Radix AXE6600 v781521 Command Injection via urlfilter | Radix AXE6600 | 9.3 (v4.0) | Critical |
| CVE-2026-71992 | MSI Radix AXE6600 v781521 Command Injection via macfilter | Radix AXE6600 | 9.3 (v4.0) | Critical |
| CVE-2026-76071 | Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter | NC63 | 9.3 (v4.0) | Critical |
| CVE-2026-10042 | manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model | manga-image-translator | 9.2 (v4.0) | Critical |
| CVE-2026-63304 | AVideo through 29.0 OS Command Injection via listFFmpegProcesses | AVideo | 9.2 (v4.0) | Critical |
| CVE-2026-63305 | AVideo through 29.0 OS Command Injection via ffmpeg.json.php | AVideo | 9.2 (v4.0) | Critical |
| CVE-2026-80138 | ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameter | clipbucket-v5 | 9.2 (v4.0) | Critical |
| CVE-2026-87930 | MaxSite CMS through 109.6 PHP Object Injection via ci_session | MaxSite CMS | 9.2 (v4.0) | Critical |
| CVE-2026-46621 | Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection | yamcs | 9.1 (v3.1) | Critical |
| CVE-2026-55511 | Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs executeSql | yamcs | 9.1 (v3.1) | Critical |
| CVE-2026-57499 | Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE) | core | 9.1 (v3.1) | Critical |
| CVE-2026-58400 | GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter | core-geonetwork | 9.1 (v3.1) | Critical |
| CVE-2026-14602 | Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter | Remote API | 9.0 (v3.1) | Critical |
| CVE-2026-45630 | Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo Statement | dokploy | 9.0 (v3.1) | Critical |
| CVE-2026-73485 | Flowise before 3.1.3 Remote Code Execution via Airtable Agent | flowise | 9.0 (v4.0) | Critical |
| CVE-2026-73486 | Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV | flowise | 9.0 (v4.0) | Critical |
| CVE-2026-73487 | Flowise before 3.1.3 Prompt Injection RCE via CSV Agent | flowise | 9.0 (v4.0) | Critical |
| CVE-2026-43945 | FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection | FUXA | 8.9 (v4.0) | High |
| CVE-2026-7202 | Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-7203 | Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-7204 | Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-73570 | zimbra collaboration suite Arbitrary Code Execution Vulnerability | zimbra collaboration suite | 8.9 (v3.1) | High |
| CVE-2026-9384 | Totolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9385 | Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9386 | Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9387 | Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9388 | Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9404 | Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9405 | Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9406 | Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9407 | Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9432 | Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9433 | Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9434 | Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9435 | Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9436 | Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9454 | Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9455 | Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9456 | Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9457 | Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9458 | Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9476 | Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9477 | Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9478 | Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2017-14535 | Trixbox - 2.8.0.4 OS Command Injection | trixbox | 8.8 (v3.1) | High |
| CVE-2017-6884 | Zyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection | emg2926 firmware | 8.8 (v3.1) | High |
| CVE-2020-15874 | Command Injection | - | 8.8 (v3.1) | High |
| CVE-2020-8163 | Ruby on Rails <5.0.1 - Remote Code Execution | rails | 8.8 (v3.1) | High |
| CVE-2024-39024 | In Packetfence 13.2.0, the WebGui interface setting Arbitrary Code Execution Vulnerability | - | 8.8 (v3.1) | High |
| CVE-2025-59710 | biztalk360 Arbitrary Code Execution Vulnerability | biztalk360 | 8.8 (v3.1) | High |
| CVE-2026-24893 | openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansion | openitcockpit | 8.8 (v3.1) | High |
| CVE-2026-34197 | Apache ActiveMQ - Remote Code Execution | activemq | 8.8 (v3.1) | High |
| CVE-2026-35196 | Chamilo LMS has OS Command Injection via export_all_certificates action | chamilo lms | 8.8 (v3.1) | High |
| CVE-2026-45505 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia addNetworkConnector Discovery Wrapper Bypass | activemq | 8.8 (v3.1) | High |
| CVE-2026-45578 | WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URL | avideo | 8.8 (v3.1) | High |
| CVE-2026-45662 | Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion) | dokploy | 8.8 (v3.1) | High |
| CVE-2026-48017 | DbGate: Remote Code Execution via functionName injection in loadReader endpoint | dbgate | 8.8 (v3.1) | High |
| CVE-2026-55585 | QWED: Authenticated Remote Code Execution via Unsafe SymPy parse_expr() | qwed-verification | 8.8 (v3.1) | High |
| CVE-2026-58195 | Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into ex | agentic-flow | 8.8 (v3.1) | High |
| CVE-2026-62675 | Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools | omnigent | 8.8 (v3.1) | High |
| CVE-2026-72875 | Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFile | dokploy | 8.8 (v3.1) | High |
| CVE-2026-73222 | Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (–studio) | claude-code-templates | 8.8 (v3.1) | High |
| CVE-2026-78834 | Security Vulnerability | - | 8.8 (v3.1) | High |
| CVE-2026-79423 | the admin_config.php component of seacms v13.6 Arbitrary Code Execution Vulnerability | the admin config.php component of seacms v13.6 | 8.8 (v3.1) | High |
| CVE-2026-82217 | Eclipse Theia Path Traversal Vulnerability | Eclipse Theia | 8.8 (v3.1) | High |
| CVE-2019-25671 | VA MAX 8.3.4 Remote Code Execution via changeip.php | VA MAX | 8.7 (v4.0) | High |
| CVE-2021-47938 | ImpressCMS 1.4.2 Remote Code Execution via Autotasks | ImpressCMS | 8.7 (v4.0) | High |
| CVE-2021-47943 | TextPattern CMS 4.8.7 Remote Code Execution via File Upload | TextPattern CMS | 8.7 (v4.0) | High |
| CVE-2022-50944 | Aero CMS 0.0.1 PHP Code Injection via posts.php | Aero CMS | 8.7 (v4.0) | High |
| CVE-2023-54350 | WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated | Augmented Reality | 8.7 (v4.0) | High |
| CVE-2025-30007 | HestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record Management | control panel | 8.7 (v4.0) | High |
| CVE-2025-71260 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE | footprints | 8.7 (v4.0) | High |
| CVE-2026-34228 | Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write | emlog | 8.7 (v4.0) | High |
| CVE-2026-34735 | Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileController | wiki | 8.7 (v4.0) | High |
| CVE-2026-34792 | Endian Firewall /cgi-bin/logs_clamav.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34793 | Endian Firewall /cgi-bin/logs_firewall.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34795 | Endian Firewall /cgi-bin/logs_log.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34796 | Endian Firewall /cgi-bin/logs_openvpn.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34797 | Endian Firewall /cgi-bin/logs_smtp.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-47722 | nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml | nebula-mesh | 8.7 (v4.0) | High |
| CVE-2026-49143 | BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handler | browserstack-runner | 8.7 (v4.0) | High |
| CVE-2026-63722 | ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.php | ICEcoder | 8.7 (v4.0) | High |
| CVE-2026-67206 | Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload | wolfcms | 8.7 (v4.0) | High |
| CVE-2026-69096 | OpenWrt luci-app-dockerman Read ACL Remote Code Execution | luci | 8.7 (v4.0) | High |
| CVE-2026-69100 | LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution | lamp-cloud | 8.7 (v4.0) | High |
| CVE-2026-71966 | CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer | cyberpanel | 8.7 (v4.0) | High |
| CVE-2026-71981 | Cypht < 2.12.2 PHP Object Injection RCE via back_query Parameter | cypht | 8.7 (v4.0) | High |
| CVE-2026-72819 | Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload | grav | 8.7 (v4.0) | High |
| CVE-2026-72830 | Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass | grav | 8.7 (v4.0) | High |
| CVE-2026-72870 | Dokploy: Command Injection via Docker Credentials in buildRemoteDocker | dokploy | 8.7 (v4.0) | High |
| CVE-2026-73680 | Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename | Cockpit CMS | 8.7 (v4.0) | High |
| CVE-2026-76060 | OS Command Injection in PayRange API | Zoneminder | 8.7 (v4.0) | High |
| CVE-2026-78416 | Authenticated RCE via condition.config JSON cleanse bypass | cms | 8.7 (v4.0) | High |
| CVE-2026-79756 | Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platform | nuclio | 8.7 (v4.0) | High |
| CVE-2026-82278 | BISHENG Authenticated Arbitrary Python Code Execution via Workflow run_once | bisheng | 8.7 (v4.0) | High |
| CVE-2026-86732 | Craft CMS before 5.10.12 Remote Code Execution via element-index | cms | 8.7 (v4.0) | High |
| CVE-2024-20353 | adaptive security appliance software Denial of Service Vulnerability | adaptive security appliance software | 8.6 (v3.1) | High |
| CVE-2026-40187 | Authenticated RCE via Malicious eTemplate Upload in EGroupware | egroupware | 8.6 (v4.0) | High |
| CVE-2026-42785 | OpenKM 6.3.12 Remote Code Execution via Administrative Scripting | OpenKM Community Edition | 8.6 (v4.0) | High |
| CVE-2026-55182 | LibreNMS: Remote Code Execution by Signal Alert Transportation Module | librenms | 8.6 (v4.0) | High |
| CVE-2026-56703 | Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTO | adminer | 8.6 (v4.0) | High |
| CVE-2026-61517 | Netis NX10 OS Command Injection via Ping Diagnostic Handler | NX10 | 8.6 (v4.0) | High |
| CVE-2026-61523 | WebsiteBaker CMS < 2.13.10 Code Injection via Droplets Editor | WebsiteBaker CMS | 8.6 (v4.0) | High |
| CVE-2026-63725 | sysPass FileBackupService Authenticated OS Command Injection via Backup Path | sysPass | 8.6 (v4.0) | High |
| CVE-2026-65693 | Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates | microweber | 8.6 (v4.0) | High |
| CVE-2026-65711 | sysPass 3.2.11 Authenticated OS Command Injection via Backup Path | sysPass | 8.6 (v4.0) | High |
| CVE-2026-67599 | ClearOS 7.9 OS Command Injection via Log Viewer filter parameter | ClearOS | 8.6 (v4.0) | High |
| CVE-2026-67608 | Telenia TVox 26.5.3 OS Command Injection via action_audio.php | TVox | 8.6 (v4.0) | High |
| CVE-2026-69088 | Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint | grav | 8.6 (v4.0) | High |
| CVE-2026-71906 | DrayTek VigorAP Multiple Models OS Command Injection via setLan | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71907 | DrayTek VigorAP Multiple Models OS Command Injection via setcamset | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71908 | DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_test | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71913 | DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgi | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71915 | DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatus | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71918 | DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupAction | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71919 | DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71923 | DrayTek VigorSwitch Multiple Models OS Command Injection via auth_set | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71925 | DrayTek VigorSwitch Multiple Models OS Command Injection via getDetail | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71926 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevice | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71927 | DrayTek VigorSwitch Multiple Models OS Command Injection via rebDevice | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71928 | DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDevice | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71929 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProto | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71930 | DrayTek VigorSwitch Multiple Models OS Command Injection via setTime | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71943 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNet | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-73664 | FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module | backup | 8.6 (v4.0) | High |
| CVE-2026-75121 | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_post | PLANET GS-4210-16P2S V3 | 8.6 (v4.0) | High |
| CVE-2026-75123 | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_post | PLANET GS-4210-16P2S V3 | 8.6 (v4.0) | High |
| CVE-2026-84194 | LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostname | librenms | 8.6 (v4.0) | High |
| CVE-2026-85223 | D-Link DNS-340L CGI dropbox.cgi os command injection | DNS-340L | 8.6 (v4.0) | High |
| CVE-2026-86437 | Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload | laradashboard | 8.6 (v4.0) | High |
| CVE-2026-86733 | Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore | snipe-it | 8.6 (v4.0) | High |
| CVE-2026-22244 | OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCE | openmetadata | 8.5 (v4.0) | High |
| CVE-2026-82691 | D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection | DNS-320L | 8.5 (v4.0) | High |
| CVE-2025-59711 | biztalk360 Path Traversal Vulnerability | biztalk360 | 8.3 (v3.1) | High |
| CVE-2026-49471 | Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE | serena | 8.3 (v3.1) | High |
| CVE-2026-42588 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector | activemq | 8.1 (v3.1) | High |
| CVE-2026-47398 | PraisonAI: Arbitrary code execution via unguarded spec.loader.exec_module in agents_generator.py - sibling of CVE-20 | PraisonAI | 8.1 (v3.1) | High |
| CVE-2026-48695 | fastnetmon Command Injection Vulnerability | fastnetmon | 8.1 (v3.1) | High |
| CVE-2026-71320 | Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props | nuxt | 8.1 (v3.1) | High |
| CVE-2015-4669 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 7.8 (v3.0) | High |
| CVE-2026-67179 | Genkit improper host header validation | genkit | 7.8 (v3.1) | High |
| CVE-2025-27621 | UpTrain has a Constant Default API Key | uptrain | 7.7 (v4.0) | High |
| CVE-2026-40519 | Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins() | nginx-proxy-manager | 7.7 (v4.0) | High |
| CVE-2026-66738 | SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLite | SPIP | 7.7 (v4.0) | High |
| CVE-2026-19913 | Kaltura HTML5 Video Player, html5lib library Improper Input Validation Vulnerability | Kaltura HTML5 Video Player, html5lib library | 7.5 (v3.1) | High |
| CVE-2026-34239 | Chamilo Authenticated Remote Code Execution | chamilo-lms | 7.5 (v4.0) | High |
| CVE-2026-36783 | Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to Denial of Service Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-46581 | mojarra Path Traversal Vulnerability | mojarra | 7.5 (v3.1) | High |
| CVE-2026-51078 | Dede CMS v.5.7.118 Information Disclosure Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-53599 | Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mo | core | 7.5 (v3.1) | High |
| CVE-2026-10870 | Shibby Tomato Web UI rc start_dhcpc os command injection | Tomato | 7.3 (v4.0) | High |
| CVE-2026-10871 | Shibby Tomato Web UI rc start_6rd_tunnel os command injection | Tomato | 7.3 (v4.0) | High |
| CVE-2026-10873 | Shibby Tomato Web UI rstats rstats_path os command injection | Tomato | 7.3 (v4.0) | High |
| CVE-2026-18900 | H3C NX15 Backend RPC esps file.exec os command injection | NX15 | 7.3 (v4.0) | High |
| CVE-2026-19771 | Baicells EG3661M LuCI Web luci os command injection | EG3661M | 7.3 (v4.0) | High |
| CVE-2026-71284 | Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filename | fledge | 7.2 (v3.1) | High |
| CVE-2026-71964 | CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload | cyberpanel | 7.1 (v4.0) | High |
| CVE-2026-77939 | Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint | flextype | 7.1 (v4.0) | High |
| CVE-2025-71257 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass | footprints itsm | 6.9 (v4.0) | Medium |
| CVE-2026-11450 | GL.iNet GL-MT3000 Path Normalization dlopen command injection | GL-MT3000 | 6.9 (v4.0) | Medium |
| CVE-2026-19983 | GL.iNet XE3000 NAS Command Service gl_nas_sys os command injection | A1300 | 6.9 (v4.0) | Medium |
| CVE-2026-5739 | PowerJob OpenAPI Endpoint addWorkflowNode GroovyEvaluator.evaluate code injection | PowerJob | 6.9 (v4.0) | Medium |
| CVE-2025-59709 | biztalk360 Path Traversal Vulnerability | biztalk360 | 6.8 (v3.1) | Medium |
| CVE-2026-10821 | Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE | Yoast SEO Premium | 6.6 (v3.1) | Medium |
| CVE-2026-34216 | CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in SettingsController.php | panel | 6.6 (v3.1) | Medium |
| CVE-2026-72739 | Dokploy: Command Injection via Compose Shell Execution | dokploy | 6.5 (v3.1) | Medium |
| CVE-2026-44287 | FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*(/ is bypassable | FastGPT | 6.3 (v3.1) | Medium |
| CVE-2026-45626 | Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameter | arcane | 6.3 (v3.1) | Medium |
| CVE-2015-4668 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 6.1 (v3.0) | Medium |
| CVE-2025-13786 | taosir WTCMS index.php fetch code injection | wtcms | 5.5 (v4.0) | Medium |
| CVE-2025-13792 | Qualitor getResumo.php eval code injection | Qualitor | 5.5 (v4.0) | Medium |
| CVE-2026-10214 | zhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injection | chatgpt-on-wechat | 5.5 (v4.0) | Medium |
| CVE-2026-18641 | Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginC | Operation and Maintenance Security Management System | 5.5 (v4.0) | Medium |
| CVE-2026-19379 | EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection | ipTIME AX8004M | 5.5 (v4.0) | Medium |
| CVE-2026-54611 | InstantCMS has Remote Code Execution in package installer | icms2 | 5.5 (v3.1) | Medium |
| CVE-2026-5631 | assafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injection | gpt-researcher | 5.5 (v4.0) | Medium |
| CVE-2026-5677 | Totolink A7100RU cstecgi.cgi CsteSystem os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5678 | Totolink A7100RU cstecgi.cgi setScheduleCfg os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5688 | Totolink A7100RU cstecgi.cgi setDdnsCfg os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5689 | Totolink A7100RU cstecgi.cgi setNtpCfg os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5690 | Totolink A7100RU cstecgi.cgi setRemoteCfg os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5691 | Totolink A7100RU cstecgi.cgi setFirewallType os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5692 | Totolink A7100RU cstecgi.cgi setGameSpeedCfg os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5736 | PowerJob detailPlus Endpoint InstanceController.java sql injection | PowerJob | 5.5 (v4.0) | Medium |
| CVE-2026-5741 | suvarchal docker-mcp-server HTTP index.ts pull_image os command injection | docker-mcp-server | 5.5 (v4.0) | Medium |
| CVE-2026-5802 | idachev mcp-javadc HTTP os command injection | mcp-javadc | 5.5 (v4.0) | Medium |
| CVE-2026-7220 | jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injection | FastlyMCP | 5.5 (v4.0) | Medium |
| CVE-2026-76760 | chenhg5 cc-connect webhook.go authenticate code injection | cc-connect | 5.5 (v4.0) | Medium |
| CVE-2026-76761 | chenhg5 cc-connect Management API engine.go shellExecCommand os command injection | cc-connect | 5.5 (v4.0) | Medium |
| CVE-2026-82598 | SeaCMS Template search.php parseIf code injection | SeaCMS | 5.5 (v4.0) | Medium |
| CVE-2026-85137 | SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injection | SeaCMS | 5.5 (v4.0) | Medium |
| CVE-2026-9474 | yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injection | StudentManagementSystem | 5.5 (v4.0) | Medium |
| CVE-2026-54543 | Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields | froxlor | 5.4 (v3.1) | Medium |
| CVE-2023-7299 | DataGear resolveSql sql injection | datagear | 5.3 (v4.0) | Medium |
| CVE-2026-19785 | francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection | RosarioSIS | 5.3 (v4.0) | Medium |
| CVE-2015-4666 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 5.0 (v2.0) | Medium |
| CVE-2015-4665 | Xceedium Xsuite - Multiple Vulnerabilities | xsuite | 4.3 (v2.0) | Medium |
| CVE-2026-36239 | PbootCMS v.3.2.11 Cross-site Scripting Vulnerability | PbootCMS v.3.2.11 | 4.3 (v3.1) | Medium |
| CVE-2026-16297 | Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import | Clearfy Cache | 4.1 (v3.1) | Medium |
| CVE-2023-3360 | Weaver Show Posts < 1.8.1 - Admin+ PHP Object Injection | Weaver Show Posts | 3.3 (v3.1) | Low |
| CVE-2026-10172 | Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted upload | Multi-Store Inventory Management System | 2.1 (v4.0) | Low |
| CVE-2026-10279 | hiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injection | wezterm-mcp | 2.1 (v4.0) | Low |
| CVE-2026-11408 | vertex-app vertex Log Viewer Endpoint LogMod.js os command injection | vertex | 2.1 (v4.0) | Low |
| CVE-2026-19932 | DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.evaluate code injection | Notice-System-Managent | 2.1 (v4.0) | Low |
| CVE-2026-19958 | iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injection | pptr-mcp | 2.1 (v4.0) | Low |
| CVE-2026-5351 | Trendnet TEW-657BRM setup.cgi add_wps_client os command injection | tew-657brm firmware | 2.1 (v4.0) | Low |
| CVE-2026-5352 | Trendnet TEW-657BRM setup.cgi edit os command injection | tew-657brm firmware | 2.1 (v4.0) | Low |
| CVE-2026-5353 | Trendnet TEW-657BRM setup.cgi ping_test os command injection | tew-657brm firmware | 2.1 (v4.0) | Low |
| CVE-2026-5354 | Trendnet TEW-657BRM setup.cgi vpn_connect os command injection | tew-657brm firmware | 2.1 (v4.0) | Low |
| CVE-2026-5355 | Trendnet TEW-657BRM setup.cgi vpn_drop os command injection | tew-657brm firmware | 2.1 (v4.0) | Low |
| CVE-2026-78166 | provectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest code injection | kafka-ui | 2.1 (v4.0) | Low |
| CVE-2026-8188 | Wavlink NU516U1 adm.cgi change_wifi_password os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8189 | Wavlink NU516U1 adm.cgi wzdrepeater os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8190 | Wavlink NU516U1 adm.cgi wan os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8191 | Wavlink NU516U1 adm.cgi wifi_region os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8192 | Wavlink NU516U1 adm.cgi wzdap os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8227 | Wavlink NU516U1 adm.cgi wzdapMesh os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8228 | Wavlink NU516U1 wireless.cgi advance os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8229 | Wavlink NU516U1 wireless.cgi WifiBasic os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8230 | Wavlink NU516U1 login.cgi sys_login1 os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-9302 | 546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injection | vps-inventory-monitoring | 2.1 (v4.0) | Low |
| CVE-2026-9511 | Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9512 | Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9514 | Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9515 | Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9531 | Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9532 | Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9533 | Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9534 | Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-19964 | Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injection | Jij-MCP-Server | 2.0 (v4.0) | Low |
| CVE-2026-78140 | Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine | UJCMS | 2.0 (v4.0) | Low |
| CVE-2026-85040 | ZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injection | CRMEB | 2.0 (v4.0) | Low |
| CVE-2026-16129 | princezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklist | SafestClaw | 1.9 (v4.0) | Low |
| CVE-2026-5621 | ChrisChinchilla Vale-MCP HTTP index.ts os command injection | Vale-MCP | 1.9 (v4.0) | Low |
| CVE-2026-19353 | DedeCMS Installation Wizard index.php _4_Setup file inclusion | DedeCMS | 1.3 (v4.0) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.