On this page

Atomicorp WAF Rule 340029

Rule Summary

Description

This rule detects when a Linux command is used in a URL or an argument. It specifically looks for these types of commands:

  • process management tools (kill, nice, etc.)
  • file management tools (cp, chown, rm, etc.)
  • shells (bash, tcsh, etc.)
  • compilers (gcc, c++, etc.)
  • web downloading tools (wget, curl, etc.)
  • interpreters (perl, php, etc.)
  • other downloading tools (scp, ftp, etc.)

Some attack tools are known to blindly look for software tools and to see if it can use them. Therefore, the fact that this rule is triggered does not mean that the software tool is installed on the system.

If your system is being targeted with these kinds of attacks we do not recommend you disable this rule. This rule may be telling you that someone is attacking your system, and therefore you should block this source. Please see the blog post referenced below for information about leaving rules enabled for applications you may not have installed.

Troubleshooting

False Positives

A false positive could occur if an application either safely allows the use of these tools, or if the data is used in a non-command context such as in a document. The rule contains a large number of known safe applications that may either use these tools securely, or may allow this data in non-command mode. If you have confirmed that your application is safely using these commands, or this data in a non-command format, please let us know what the application is, how you confirmed this so we can duplicate this in our test environment, and report the issue as a False Positive per the article below:

Tuning Guidance

If you want to disable this rule, please see the Tuning the Atomicorp WAF Rules page for basic information.

Additional Information

Blog Articles

None.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2009-0545ZeroShell <= 1.0beta11 Remote Code Executionzeroshell10.0 (v2.0)High
CVE-2010-5286Joomla! Component Jstore - 'Controller' Local File Inclusioncom jstore10.0 (v2.0)High
CVE-2025-34037Linksys Routers E/WAG/WAP/WES/WET/WRT-SeriesE420010.0 (v4.0)Critical
CVE-2026-19188Haiwell IoT Cloud HMI Gateway OS Command InjectionHaiwell IoT Cloud HMI Gateway10.0 (v4.0)Critical
CVE-2026-34234CtrlPanel: Unauthenticated RCE using installer scriptpanel10.0 (v3.1)Critical
CVE-2026-44181Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Executionenterprise gateway10.0 (v4.0)Critical
CVE-2026-47668DbGate - Remote Code Execution via Anonymous JWTdbgate10.0 (v3.1)Critical
CVE-2026-49869Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in AuthenticationFilterkestra10.0 (v3.1)Critical
CVE-2026-81735UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command ExecutiUI-TARS-desktop10.0 (v4.0)Critical
CVE-2026-8984Unauthenticated RCEmaxicharger single charger firmware10.0 (v4.0)Critical
CVE-2026-42454Termix: OS Command Injection in Docker Container Management EndpointsTermix9.9 (v3.1)Critical
CVE-2026-44450Lumiverse: RCE via MCP stdio argument injectionLumiverse9.9 (v3.1)Critical
CVE-2026-45629Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpointdokploy9.9 (v3.1)Critical
CVE-2026-45632Dokploy: Schedule Authorization Bypass Enables Host/Server Command Executiondokploy9.9 (v3.1)Critical
CVE-2026-48030Pheditor 2.0.1-2.0.3 - OS Command Injectionpheditor9.9 (v3.1)Critical
CVE-2026-55565Yamcs: Authenticated remote code execution via unescaped StreamSQL LIKE pattern compiled by Janino (LikeExpression)yamcs9.9 (v3.1)Critical
CVE-2026-55634Pimcore: Remote Code Execution via DataObject Class-Definition Field Namepimcore9.9 (v3.1)Critical
CVE-2026-63298LXD arbitrary lxc.conf directive injection via NVIDIA instance configurationLXD9.9 (v3.1)Critical
CVE-2026-72738Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameterdokploy9.9 (v3.1)Critical
CVE-2026-72740Dokploy: OS Command Injection via SSH-form customGitUrl domain in ssh-keyscandokploy9.9 (v3.1)Critical
CVE-2026-72865Dokploy: OS Command Injection via compose composePathdokploy9.9 (v3.1)Critical
CVE-2026-72868Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injectiondokploy9.9 (v3.1)Critical
CVE-2026-72869Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCEdokploy9.9 (v3.1)Critical
CVE-2026-72872Dokploy: OS Command Injection via Bitbucket owner/repository in git clonedokploy9.9 (v3.1)Critical
CVE-2026-72876Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*dokploy9.9 (v3.1)Critical
CVE-2026-72882Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed serversdokploy9.9 (v3.1)Critical
CVE-2026-72902Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryByIddokploy9.9 (v3.1)Critical
CVE-2026-73263Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-pathprowler9.9 (v3.1)Critical
CVE-2026-73294Semaphore U: OS Command Injectionsemaphore9.9 (v3.1)Critical
CVE-2026-8481Remote Code Execution via Code Validation Endpointlangflow9.9 (v3.1)Critical
CVE-2009-1151PhpMyAdmin Scripts - Remote Code Executionphpmyadmin9.8 (v3.1)Critical
CVE-2017-12611Apache Struts2 S2-053 - Remote Code Executionstruts9.8 (v3.0)Critical
CVE-2018-11686FlexPaper/FlowPaper 2.3.6 - Remote Code Executionflowpaper9.8 (v3.0)Critical
CVE-2018-17173LG Supersign EZ CMS - Remote Code Executionsupersign cms9.8 (v3.0)Critical
CVE-2019-12725Zeroshell 3.9.0 - Remote Command Executionzeroshell9.8 (v3.0)Critical
CVE-2019-12985Citrix SD-WAN Center - Remote Command Injectionnetscaler sd-wan9.8 (v3.0)Critical
CVE-2019-12986Citrix SD-WAN Center - Remote Command Injectionnetscaler sd-wan9.8 (v3.0)Critical
CVE-2019-16662rConfig 3.9.2 - Remote Code Executionrconfig9.8 (v3.1)Critical
CVE-2019-20504Dell KACE Systems Management Appliance (K1000) 6.4.120756 - Remote Code Executionkace systems management9.8 (v3.1)Critical
CVE-2019-7256eMerge E3 1.00-06 - Remote Code Executionlinear emerge essential firmware9.8 (v3.1)Critical
CVE-2020-14750Oracle WebLogic Server - Remote Command Executionfusion middleware9.8 (v3.1)Critical
CVE-2020-29227Car Rental Management System 1.0 - Local File Inclusioncar rental management system9.8 (v3.1)Critical
CVE-2020-7209LinuxKI Toolset <= 6.01 - Remote Command Executionlinuxki9.8 (v3.1)Critical
CVE-2021-35395RealTek Jungle SDK - Arbitrary Command Injectionrealtek jungle sdk9.8 (v3.1)Critical
CVE-2022-1391WordPress Cab fare calculator < 1.0.4 - Local File Inclusioncab fare calculator9.8 (v3.1)Critical
CVE-2022-29303SolarView Compact 6.0 - OS Command Injectionsv-cpt-mc310 firmware9.8 (v3.1)Critical
CVE-2022-31137Roxy-WI < 6.1.1.0 - Remote Code Executionroxy-wi9.8 (v3.1)Critical
CVE-2022-40881SolarView 6.00 - Remote Command Executionsolarview compact9.8 (v3.1)Critical
CVE-2023-25826OpenTSDB <= 2.4.1 - Unauthenticated RCE via Gnuplot Injectionopentsdb9.8 (v3.1)Critical
CVE-2024-50603Aviatrix Controller - Remote Code Executioncontroller9.8 (v3.1)Critical
CVE-2024-5827Vanna - SQL injectionvanna-ai/vanna9.8 (v3.0)Critical
CVE-2026-12940Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpointlangflow9.8 (v3.1)Critical
CVE-2026-18482neo-mjs Command Injection Vulnerabilityneo-mjs9.8 (v3.1)Critical
CVE-2026-31040stata-mcp Code Injection Vulnerabilitystata-mcp9.8 (v3.1)Critical
CVE-2026-3296Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry MetadataEverest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder9.8 (v3.1)Critical
CVE-2026-35048Piwigo RCE via PHP Code Injection into Config File in InstallerPiwigo9.8 (v3.1)Critical
CVE-2026-35847dnsmgr 2.15 and Earlier Arbitrary Code Execution Vulnerability-9.8 (v3.1)Critical
CVE-2026-37281the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 Command Injection Vulnerabilitythe /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.09.8 (v3.1)Critical
CVE-2026-38428kestra SQL Injection Vulnerabilitykestra9.8 (v3.1)Critical
CVE-2026-38431erpnext Code Injection Vulnerabilityerpnext9.8 (v3.1)Critical
CVE-2026-45018Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code executionchainlit9.8 (v3.1)Critical
CVE-2026-46562Yamcs: Remote Code Execution via Mission Database algorithm overrideyamcs9.8 (v3.1)Critical
CVE-2026-47391PraisonAI's unauthenticated A2A official example can reach real LLM-driven eval() tool executionPraisonAI9.8 (v3.1)Critical
CVE-2026-48687fastnetmon Command Injection Vulnerabilityfastnetmon9.8 (v3.1)Critical
CVE-2026-49819UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmdUpSnap9.8 (v3.1)Critical
CVE-2026-53545Termix: Remote Code Execution via Tunnel Disconnect pkill Command InjectionTermix9.8 (v3.1)Critical
CVE-2026-67919Halo 2.25.4 Arbitrary Code Execution Vulnerability-9.8 (v3.1)Critical
CVE-2026-75411JeecgBoot v3.9.2 Code Injection Vulnerability-9.8 (v3.1)Critical
CVE-2026-75414In AntFlow V2.0.0, ActivitiTest.java Code Injection Vulnerability-9.8 (v3.1)Critical
CVE-2026-79408MetaGPT 0.8.1 Command Injection VulnerabilityMetaGPT 0.8.19.8 (v3.1)Critical
CVE-2026-8037Progress ADC LoadMaster - Command Injectionconnection manager for objectscale9.8 (v3.1)Critical
CVE-2026-84372Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connectionspredis9.8 (v3.1)Critical
CVE-2026-34449SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injectionsiyuan9.6 (v3.1)Critical
CVE-2026-35906An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 OS Command Injection Vulnerability-9.6 (v3.1)Critical
CVE-2026-72878Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell argumentsdokploy9.6 (v3.1)Critical
CVE-2026-70477Flowise: CSV Agent Prompt Injection Remote Code Execution VulnerabilityFlowise9.5 (v4.0)Critical
CVE-2025-62593Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attackray9.4 (v4.0)Critical
CVE-2026-33324SQLBot prompt injection allows arbitrary SQL execution and remote code executionsqlbot9.4 (v4.0)Critical
CVE-2026-39932OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injectionopenemr9.4 (v4.0)Critical
CVE-2026-45272MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config Filetalebook9.4 (v4.0)Critical
CVE-2026-47670DbGate - Remote Code Execution via Dynamic Import Bypassdbgate9.4 (v4.0)Critical
CVE-2026-637329router before 0.4.60 Remote Code Execution via default password9router9.4 (v4.0)Critical
CVE-2026-66398phpMyFAQ before 4.1.6 Remote Code Execution via Configuration APIphpMyFAQ9.4 (v4.0)Critical
CVE-2026-69256Flowise: Remote Code Execution Vulnerability in CSVAgentFlowise9.4 (v4.0)Critical
CVE-2026-72879Dokploy: Command Injection via Registry Credentials in Swarm Uploaddokploy9.4 (v4.0)Critical
CVE-2026-73041SiYuan before v3.7.4 Remote Code Execution via PDF Annotationssiyuan9.4 (v4.0)Critical
CVE-2026-73042SiYuan before v3.7.4 Remote Code Execution via Menu Metadatasiyuan9.4 (v4.0)Critical
CVE-2026-73483Flowise before 3.1.3 Sandbox Escape via Puppeteerflowise9.4 (v4.0)Critical
CVE-2018-25357Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.phpdolibarr erp/crm9.3 (v4.0)Critical
CVE-2019-25687Pegasus CMS 1.0 Remote Code Execution via extra_fields.phppegasus cms9.3 (v4.0)Critical
CVE-2025-31114Fooocus webui vulnerable to Remote Code ExecutionFooocus9.3 (v4.0)Critical
CVE-2026-19586Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gatewayser7212pc firmware9.3 (v4.0)Critical
CVE-2026-41939Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFlyCare Everywhere Gateway9.3 (v4.0)Critical
CVE-2026-44402Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgiSNMP Web Pro9.3 (v4.0)Critical
CVE-2026-53975OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/execOpenChamber9.3 (v4.0)Critical
CVE-2026-60121Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.phpflamingo9.3 (v4.0)Critical
CVE-2026-61498Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.phpflamingo9.3 (v4.0)Critical
CVE-2026-61511vBulletin 6.x - Remote Code ExecutionvBulletin9.3 (v4.0)Critical
CVE-2026-63766GPT-SoVITS 20250606v2pro OS Command Injection via webui.pyGPT-SoVITS9.3 (v4.0)Critical
CVE-2026-64625AVideo before 29.0 OS Command Injection via execAsyncAVideo9.3 (v4.0)Critical
CVE-2026-64824Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restoreHome Assistant Core9.3 (v4.0)Critical
CVE-2026-65008Grav before 2.0.7 Remote Code Execution via Blueprint dynamicDatagrav9.3 (v4.0)Critical
CVE-2026-67308Wazuh GitHub Actions Shell Injection via Fork Pull Requestwazuh9.3 (v4.0)Critical
CVE-2026-70553MaxSite CMS Unauthenticated RCE via Install EndpointMaxSite CMS9.3 (v4.0)Critical
CVE-2026-71921DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgiVigorSwitch G2540xs9.3 (v4.0)Critical
CVE-2026-71944D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectelDWR-M9619.3 (v4.0)Critical
CVE-2026-71945D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocomDWR-M9619.3 (v4.0)Critical
CVE-2026-71946D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRunDWR-M9619.3 (v4.0)Critical
CVE-2026-71947D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRunDWR-M9619.3 (v4.0)Critical
CVE-2026-71948D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRunDWR-M9619.3 (v4.0)Critical
CVE-2026-71949D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetupDWR-M9619.3 (v4.0)Critical
CVE-2026-71950D-Link DWR-M961 Command Injection via /boafrm/formSmsManageDWR-M9619.3 (v4.0)Critical
CVE-2026-71951D-Link DWR-M961 Command Injection via /boafrm/formIMEISetupDWR-M9619.3 (v4.0)Critical
CVE-2026-71952D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetupDWR-M9619.3 (v4.0)Critical
CVE-2026-71953D-Link DWR-M961 Command Injection via /boafrm/formNtpDWR-M9619.3 (v4.0)Critical
CVE-2026-71954D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetupDWR-M9619.3 (v4.0)Critical
CVE-2026-71955D-Link DWR-M961 Command Injection via /boafrm/formWscDWR-M9619.3 (v4.0)Critical
CVE-2026-71956D-Link DWR-M961 Command Injection via app.cgiDWR-M9619.3 (v4.0)Critical
CVE-2026-71984MSI Radix AXE6600 v781521 Command Injection via urlfilterRadix AXE66009.3 (v4.0)Critical
CVE-2026-71992MSI Radix AXE6600 v781521 Command Injection via macfilterRadix AXE66009.3 (v4.0)Critical
CVE-2026-76070Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password ParameterNC639.3 (v4.0)Critical
CVE-2026-76071Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost ParameterNC639.3 (v4.0)Critical
CVE-2023-7305SmartBI RMIServlet Unrestricted File Upload RCESmartBI9.2 (v4.0)Critical
CVE-2026-63304AVideo through 29.0 OS Command Injection via listFFmpegProcessesAVideo9.2 (v4.0)Critical
CVE-2026-63305AVideo through 29.0 OS Command Injection via ffmpeg.json.phpAVideo9.2 (v4.0)Critical
CVE-2026-80138ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameterclipbucket-v59.2 (v4.0)Critical
CVE-2026-46621Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injectionyamcs9.1 (v3.1)Critical
CVE-2026-55511Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs executeSqlyamcs9.1 (v3.1)Critical
CVE-2026-57499Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE)core9.1 (v3.1)Critical
CVE-2026-58400GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formattercore-geonetwork9.1 (v3.1)Critical
CVE-2026-34612Kestra: Remote Code Execution via SQL Injectionkestra9.0 (v3.1)Critical
CVE-2026-45630Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo Statementdokploy9.0 (v3.1)Critical
CVE-2026-62674Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCEomnigent9.0 (v3.1)Critical
CVE-2026-69251Flowise RCE via TypeORM DataSourceFlowise9.0 (v4.0)Critical
CVE-2026-73485Flowise before 3.1.3 Remote Code Execution via Airtable Agentflowise9.0 (v4.0)Critical
CVE-2026-73486Flowise before 3.1.3 Code Injection via CSV Agent customReadCSVflowise9.0 (v4.0)Critical
CVE-2026-73487Flowise before 3.1.3 Prompt Injection RCE via CSV Agentflowise9.0 (v4.0)Critical
CVE-2026-43945FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration InjectionFUXA8.9 (v4.0)High
CVE-2026-7202Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injectionA8000RU8.9 (v4.0)High
CVE-2026-7203Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injectionA8000RU8.9 (v4.0)High
CVE-2026-7204Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-73570zimbra collaboration suite Arbitrary Code Execution Vulnerabilityzimbra collaboration suite8.9 (v3.1)High
CVE-2026-9384Totolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9385Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9386Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9387Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9388Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9404Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9405Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9406Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9407Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9408Totolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9432Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9433Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9434Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9435Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9436Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9454Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9455Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9456Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9457Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9458Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9475Totolink A8000RU Web Management cstecgi.cgi setIpQosRules os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9476Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9477Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9478Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injectionA8000RU8.9 (v4.0)High
CVE-2017-6884Zyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command Injectionemg2926 firmware8.8 (v3.1)High
CVE-2018-15142OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actionsopenemr8.8 (v3.0)High
CVE-2020-15874Command Injection-8.8 (v3.1)High
CVE-2020-8641Lotus Core CMS 1.0.1 - Local File Inclusionlotus core cms8.8 (v3.1)High
CVE-2024-39024In Packetfence 13.2.0, the WebGui interface setting Arbitrary Code Execution Vulnerability-8.8 (v3.1)High
CVE-2025-59710biztalk360 Arbitrary Code Execution Vulnerabilitybiztalk3608.8 (v3.1)High
CVE-2026-24893openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansionopenitcockpit8.8 (v3.1)High
CVE-2026-26899OS Command Injection-8.8 (v3.1)High
CVE-2026-34197Apache ActiveMQ - Remote Code Executionactivemq8.8 (v3.1)High
CVE-2026-35031Jellyfin: Potential RCE via subtitle upload path traversal + .strm chainjellyfin8.8 (v3.1)High
CVE-2026-35196Chamilo LMS has OS Command Injection via export_all_certificates actionchamilo lms8.8 (v3.1)High
CVE-2026-45505Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia addNetworkConnector Discovery Wrapper Bypassactivemq8.8 (v3.1)High
CVE-2026-45578WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URLavideo8.8 (v3.1)High
CVE-2026-45662Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion)dokploy8.8 (v3.1)High
CVE-2026-48017DbGate: Remote Code Execution via functionName injection in loadReader endpointdbgate8.8 (v3.1)High
CVE-2026-55585QWED: Authenticated Remote Code Execution via Unsafe SymPy parse_expr()qwed-verification8.8 (v3.1)High
CVE-2026-58195Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into exagentic-flow8.8 (v3.1)High
CVE-2026-62675Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Toolsomnigent8.8 (v3.1)High
CVE-2026-72875Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFiledokploy8.8 (v3.1)High
CVE-2026-73222Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (–studio)claude-code-templates8.8 (v3.1)High
CVE-2026-78834Security Vulnerability-8.8 (v3.1)High
CVE-2026-79423the admin_config.php component of seacms v13.6 Arbitrary Code Execution Vulnerabilitythe admin config.php component of seacms v13.68.8 (v3.1)High
CVE-2026-82217Eclipse Theia Path Traversal VulnerabilityEclipse Theia8.8 (v3.1)High
CVE-2019-25671VA MAX 8.3.4 Remote Code Execution via changeip.phpVA MAX8.7 (v4.0)High
CVE-2021-47938ImpressCMS 1.4.2 Remote Code Execution via AutotasksImpressCMS8.7 (v4.0)High
CVE-2021-47943TextPattern CMS 4.8.7 Remote Code Execution via File UploadTextPattern CMS8.7 (v4.0)High
CVE-2022-50944Aero CMS 0.0.1 PHP Code Injection via posts.phpAero CMS8.7 (v4.0)High
CVE-2023-54350WordPress Augmented-Reality Plugin Remote Code Execution UnauthenticatedAugmented Reality8.7 (v4.0)High
CVE-2025-30007HestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record Managementcontrol panel8.7 (v4.0)High
CVE-2025-34115OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.phpOP5 Monitor8.7 (v4.0)High
CVE-2026-28797RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Componeragflow8.7 (v4.0)High
CVE-2026-34228Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Writeemlog8.7 (v4.0)High
CVE-2026-34735Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileControllerwiki8.7 (v4.0)High
CVE-2026-34792Endian Firewall /cgi-bin/logs_clamav.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34793Endian Firewall /cgi-bin/logs_firewall.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34794Endian Firewall /cgi-bin/logs_ids.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34795Endian Firewall /cgi-bin/logs_log.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34796Endian Firewall /cgi-bin/logs_openvpn.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34797Endian Firewall /cgi-bin/logs_smtp.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-39352Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path Traversalfrappe8.7 (v4.0)High
CVE-2026-46746sinec ins OS Command Injection Vulnerabilitysinec ins8.7 (v4.0)High
CVE-2026-49143BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handlerbrowserstack-runner8.7 (v4.0)High
CVE-2026-63722ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.phpICEcoder8.7 (v4.0)High
CVE-2026-64850Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()grav8.7 (v4.0)High
CVE-2026-67206Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Uploadwolfcms8.7 (v4.0)High
CVE-2026-69096OpenWrt luci-app-dockerman Read ACL Remote Code Executionluci8.7 (v4.0)High
CVE-2026-71966CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfercyberpanel8.7 (v4.0)High
CVE-2026-72819Grav CMS before 2.0.13 Remote Code Execution via ZIP Uploadgrav8.7 (v4.0)High
CVE-2026-72830Grav API Plugin before 1.0.13 RCE via ConfigController scope bypassgrav8.7 (v4.0)High
CVE-2026-72870Dokploy: Command Injection via Docker Credentials in buildRemoteDockerdokploy8.7 (v4.0)High
CVE-2026-72874Dokploy: Command Injection via Unescaped Git URL in Clone Commandsdokploy8.7 (v4.0)High
CVE-2026-73680Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg FilenameCockpit CMS8.7 (v4.0)High
CVE-2026-76060OS Command Injection in PayRange APIZoneminder8.7 (v4.0)High
CVE-2026-76836AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group BypassAzuraCast8.7 (v4.0)High
CVE-2026-78416Authenticated RCE via condition.config JSON cleanse bypasscms8.7 (v4.0)High
CVE-2026-79756Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platformnuclio8.7 (v4.0)High
CVE-2026-82278BISHENG Authenticated Arbitrary Python Code Execution via Workflow run_oncebisheng8.7 (v4.0)High
CVE-2026-85610OpenPanel before 2.3.0 Remote Code Execution via chart formulasopenpanel8.7 (v4.0)High
CVE-2026-86732Craft CMS before 5.10.12 Remote Code Execution via element-indexcms8.7 (v4.0)High
CVE-2024-20353adaptive security appliance software Denial of Service Vulnerabilityadaptive security appliance software8.6 (v3.1)High
CVE-2024-48766NetAlert X - Arbitary File Readnetalertx8.6 (v3.1)High
CVE-2026-40187Authenticated RCE via Malicious eTemplate Upload in EGroupwareegroupware8.6 (v4.0)High
CVE-2026-42785OpenKM 6.3.12 Remote Code Execution via Administrative ScriptingOpenKM Community Edition8.6 (v4.0)High
CVE-2026-53804OTRS Community Edition OS Command Injection via PGP ConfigurationOTRS Community Edition8.6 (v4.0)High
CVE-2026-55182LibreNMS: Remote Code Execution by Signal Alert Transportation Modulelibrenms8.6 (v4.0)High
CVE-2026-56703Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTOadminer8.6 (v4.0)High
CVE-2026-61517Netis NX10 OS Command Injection via Ping Diagnostic HandlerNX108.6 (v4.0)High
CVE-2026-61523WebsiteBaker CMS < 2.13.10 Code Injection via Droplets EditorWebsiteBaker CMS8.6 (v4.0)High
CVE-2026-63725sysPass FileBackupService Authenticated OS Command Injection via Backup PathsysPass8.6 (v4.0)High
CVE-2026-65693Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templatesmicroweber8.6 (v4.0)High
CVE-2026-65711sysPass 3.2.11 Authenticated OS Command Injection via Backup PathsysPass8.6 (v4.0)High
CVE-2026-67599ClearOS 7.9 OS Command Injection via Log Viewer filter parameterClearOS8.6 (v4.0)High
CVE-2026-67608Telenia TVox 26.5.3 OS Command Injection via action_audio.phpTVox8.6 (v4.0)High
CVE-2026-69088Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprintgrav8.6 (v4.0)High
CVE-2026-71906DrayTek VigorAP Multiple Models OS Command Injection via setLanVigorAP 918R8.6 (v4.0)High
CVE-2026-71907DrayTek VigorAP Multiple Models OS Command Injection via setcamsetVigorAP 918R8.6 (v4.0)High
CVE-2026-71908DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_testVigorAP 918R8.6 (v4.0)High
CVE-2026-71913DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgiVigorAP 918R8.6 (v4.0)High
CVE-2026-71915DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatusVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71918DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupActionVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71919DrayTek VigorSwitch Multiple Models OS Command Injection via sysrebootVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71923DrayTek VigorSwitch Multiple Models OS Command Injection via auth_setVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71924DrayTek VigorSwitch Multiple Models OS Command Injection via getVidVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71925DrayTek VigorSwitch Multiple Models OS Command Injection via getDetailVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71926DrayTek VigorSwitch Multiple Models OS Command Injection via setDeviceVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71927DrayTek VigorSwitch Multiple Models OS Command Injection via rebDeviceVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71928DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDeviceVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71929DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProtoVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71930DrayTek VigorSwitch Multiple Models OS Command Injection via setTimeVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71931DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgradeVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71943DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNetVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-73664FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Modulebackup8.6 (v4.0)High
CVE-2026-75121PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_postPLANET GS-4210-16P2S V38.6 (v4.0)High
CVE-2026-75122PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgiPLANET GS-4210-16P2S V38.6 (v4.0)High
CVE-2026-75123PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_postPLANET GS-4210-16P2S V38.6 (v4.0)High
CVE-2026-80214LibreNMS Virtualisation Discovery Module RCElibrenms8.6 (v4.0)High
CVE-2026-82692D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injectionDNS-340L8.6 (v4.0)High
CVE-2026-84194LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostnamelibrenms8.6 (v4.0)High
CVE-2026-85223D-Link DNS-340L CGI dropbox.cgi os command injectionDNS-340L8.6 (v4.0)High
CVE-2026-86299Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injectionRE70008.6 (v4.0)High
CVE-2026-86437Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Uploadlaradashboard8.6 (v4.0)High
CVE-2026-86438Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Actionlaradashboard8.6 (v4.0)High
CVE-2026-86733Snipe-IT before 8.7.0 Remote Code Execution via Backup Restoresnipe-it8.6 (v4.0)High
CVE-2026-22244OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCEopenmetadata8.5 (v4.0)High
CVE-2026-82690D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injectionDNS-327L8.5 (v4.0)High
CVE-2026-82691D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injectionDNS-320L8.5 (v4.0)High
CVE-2026-85222D-Link DNS-340L Add-On Center addon_center.cgi os command injectionDNS-340L8.5 (v4.0)High
CVE-2026-85224D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injectionDNS-320 ShareCenter8.5 (v4.0)High
CVE-2025-59711biztalk360 Path Traversal Vulnerabilitybiztalk3608.3 (v3.1)High
CVE-2026-49471Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCEserena8.3 (v3.1)High
CVE-2026-75842ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSVarcadedb8.3 (v4.0)High
CVE-2025-69755Neterbit NW-431F Router vNW-431F-20241014-IR03 Arbitrary Code Execution Vulnerability-8.2 (v3.1)High
CVE-2026-42588Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnectoractivemq8.1 (v3.1)High
CVE-2026-45344LinkAce: Setup database password newline injection enables pre-auth RCE on uninitialized instancesLinkAce8.1 (v3.1)High
CVE-2026-47398PraisonAI: Arbitrary code execution via unguarded spec.loader.exec_module in agents_generator.py - sibling of CVE-20PraisonAI8.1 (v3.1)High
CVE-2026-48695fastnetmon Command Injection Vulnerabilityfastnetmon8.1 (v3.1)High
CVE-2026-79755Nuclio: Unauthenticated OS command injection via function namespace in docker ps –filter label (local Docker platform)nuclio8.0 (v3.1)High
CVE-2021-21315Node.JS System Information Library <5.3.1 - Remote Command Injectionsysteminformation7.8 (v3.1)High
CVE-2026-67179Genkit improper host header validationgenkit7.8 (v3.1)High
CVE-2025-27621UpTrain has a Constant Default API Keyuptrain7.7 (v4.0)High
CVE-2026-40519Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()nginx-proxy-manager7.7 (v4.0)High
CVE-2026-66738SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLiteSPIP7.7 (v4.0)High
CVE-2006-2842Squirrelmail <=1.4.6 - Local File Inclusionsquirrelmail7.5 (v2.0)High
CVE-2010-0972Joomla! Component com_gcalendar Suite 2.1.5 - Local File Inclusioncom gcalendar7.5 (v2.0)High
CVE-2010-0985Joomla! Component com_abbrev - Local File Inclusioncom abbrev7.5 (v2.0)High
CVE-2010-1306Joomla! Component Picasa 2.0 - Local File Inclusioncom joomlapicasa27.5 (v2.0)High
CVE-2010-1470Joomla! Component Web TV 1.0 - Local File Inclusioncom webtv7.5 (v2.0)High
CVE-2010-1471Joomla! Component Address Book 1.5.0 - Local File Inclusioncom addressbook7.5 (v2.0)High
CVE-2010-1472Joomla! Component Horoscope 1.5.0 - Local File Inclusioncom horoscope7.5 (v2.0)High
CVE-2010-1495Joomla! Component Matamko 1.01 - Local File Inclusioncom matamko7.5 (v2.0)High
CVE-2010-1531Joomla! Component redSHOP 1.0 - Local File Inclusioncom redshop7.5 (v2.0)High
CVE-2010-1533Joomla! Component TweetLA 1.0.1 - Local File Inclusioncom tweetla7.5 (v2.0)High
CVE-2010-1535Joomla! Component TRAVELbook 1.0.1 - Local File Inclusioncom travelbook7.5 (v2.0)High
CVE-2010-1602Joomla! Component ZiMB Comment 0.8.1 - Local File Inclusioncom zimbcomment7.5 (v2.0)High
CVE-2010-1603Joomla! Component ZiMBCore 0.1 - Local File Inclusioncom zimbcore7.5 (v2.0)High
CVE-2010-1653Joomla! Component Graphics 1.0.6 - Local File Inclusioncom graphics7.5 (v2.0)High
CVE-2010-1717Joomla! Component iF surfALERT 1.2 - Local File Inclusionif surfalert7.5 (v2.0)High
CVE-2010-1875Joomla! Component Property - Local File Inclusioncom properties7.5 (v2.0)High
CVE-2010-1878Joomla! Component OrgChart 1.0.0 - Local File Inclusioncom orgchart7.5 (v2.0)High
CVE-2010-1952Joomla! Component BeeHeard 1.0 - Local File Inclusioncom beeheard7.5 (v2.0)High
CVE-2010-1953Joomla! Component iNetLanka Multiple Map 1.0 - Local File Inclusioncom multimap7.5 (v2.0)High
CVE-2010-1954Joomla! Component iNetLanka Multiple root 1.0 - Local File Inclusioncom multiroot7.5 (v2.0)High
CVE-2010-1955Joomla! Component Deluxe Blog Factory 1.1.2 - Local File Inclusioncom blogfactory7.5 (v2.0)High
CVE-2010-1956Joomla! Component Gadget Factory 1.0.0 - Local File Inclusioncom gadgetfactory7.5 (v2.0)High
CVE-2010-1957Joomla! Component Love Factory 1.3.4 - Local File Inclusioncom lovefactory7.5 (v2.0)High
CVE-2010-1977Joomla! Component J!WHMCS Integrator 1.5.0 - Local File Inclusioncom jwhmcs7.5 (v2.0)High
CVE-2010-1980Joomla! Component Joomla! Flickr 1.0 - Local File Inclusioncom joomlaflickr7.5 (v2.0)High
CVE-2010-1983Joomla! Component redTWITTER 1.0 - Local File Inclusioncom redtwitter7.5 (v2.0)High
CVE-2010-2033Joomla! Percha Categories Tree 0.6 - Local File Inclusioncom perchacategoriestree7.5 (v2.0)High
CVE-2010-2034Joomla! Component Percha Image Attach 1.1 - Directory Traversalcom perchaimageattach7.5 (v2.0)High
CVE-2010-2035Joomla! Component Percha Gallery 1.6 Beta - Directory Traversalcom perchagallery7.5 (v2.0)High
CVE-2010-2036Joomla! Component Percha Fields Attach 1.0 - Directory Traversalcom perchafieldsattach7.5 (v2.0)High
CVE-2010-2037Joomla! Component Percha Downloads Attach 1.1 - Directory Traversalcom perchadownloadsattach7.5 (v2.0)High
CVE-2010-2045Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusioncom dioneformwizard7.5 (v2.0)High
CVE-2010-2050Joomla! Component MS Comment 0.8.0b - Local File Inclusioncom mscomment7.5 (v2.0)High
CVE-2010-2128Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusioncom jequoteform7.5 (v2.0)High
CVE-2010-2259Joomla! Component com_bfsurvey - Local File Inclusioncom bfsurvey profree7.5 (v2.0)High
CVE-2010-2682Joomla! Component Realtyna Translator 1.0.15 - Local File Inclusioncom realtyna7.5 (v2.0)High
CVE-2010-3426Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusioncom jphone7.5 (v2.0)High
CVE-2010-4719Joomla! Component JRadio - Local File Inclusioncom jradio7.5 (v2.0)High
CVE-2010-4769Joomla! Component Jimtawl 1.0.2 - Local File Inclusioncom jimtawl7.5 (v2.0)High
CVE-2010-4977Joomla! Component Canteen 1.0 - Local File Inclusioncom canteen7.5 (v2.0)High
CVE-2010-5028Joomla! Component JE Job 1.0 - Local File Inclusioncom jejob7.5 (v2.0)High
CVE-2014-10037DomPHP 0.83 - Directory Traversaldomphp7.5 (v2.0)High
CVE-2017-9833BOA Web Server 0.94.14 - Arbitrary File Accessboa7.5 (v3.1)High
CVE-2018-15138LG-Ericsson iPECS NMS 30M - Local File Inclusionipecs nms7.5 (v3.0)High
CVE-2019-7254eMerge E3 1.00-06 - Local File Inclusionlinear emerge essential firmware7.5 (v3.1)High
CVE-2019-9757LabKey Server 19.1.0 - XML External Entity (XXE)labkey server7.5 (v3.1)High
CVE-2020-35598Advanced Comment System 1.0 - Local File Inclusionadvanced comment system7.5 (v3.1)High
CVE-2022-29298SolarView Compact 6.00 - Local File Inclusionsv-cpt-mc310 firmware7.5 (v3.1)High
CVE-2023-40924SolarView Compact < 6.00 - Directory Traversalsolarview compact firmware7.5 (v3.1)High
CVE-2026-34239Chamilo Authenticated Remote Code Executionchamilo-lms7.5 (v4.0)High
CVE-2026-36783Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to Denial of Service Vulnerability-7.5 (v3.1)High
CVE-2026-36796Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to Denial of Service Vulnerability-7.5 (v3.1)High
CVE-2026-46581mojarra Path Traversal Vulnerabilitymojarra7.5 (v3.1)High
CVE-2026-51078Dede CMS v.5.7.118 Information Disclosure Vulnerability-7.5 (v3.1)High
CVE-2026-53599Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mocore7.5 (v3.1)High
CVE-2026-10870Shibby Tomato Web UI rc start_dhcpc os command injectionTomato7.3 (v4.0)High
CVE-2026-10871Shibby Tomato Web UI rc start_6rd_tunnel os command injectionTomato7.3 (v4.0)High
CVE-2026-10873Shibby Tomato Web UI rstats rstats_path os command injectionTomato7.3 (v4.0)High
CVE-2026-18900H3C NX15 Backend RPC esps file.exec os command injectionNX157.3 (v4.0)High
CVE-2026-19771Baicells EG3661M LuCI Web luci os command injectionEG3661M7.3 (v4.0)High
CVE-2026-13392ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite)ElementsKit Elementor Addons7.2 (v3.1)High
CVE-2026-15686Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution VulnerabilityAdminer7.2 (v3.0)High
CVE-2026-27891Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanismfacturascripts7.2 (v3.1)High
CVE-2026-71284Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filenamefledge7.2 (v3.1)High
CVE-2026-71964CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Uploadcyberpanel7.1 (v4.0)High
CVE-2026-77939Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpointflextype7.1 (v4.0)High
CVE-2026-11450GL.iNet GL-MT3000 Path Normalization dlopen command injectionGL-MT30006.9 (v4.0)Medium
CVE-2026-19983GL.iNet XE3000 NAS Command Service gl_nas_sys os command injectionA13006.9 (v4.0)Medium
CVE-2026-5739PowerJob OpenAPI Endpoint addWorkflowNode GroovyEvaluator.evaluate code injectionPowerJob6.9 (v4.0)Medium
CVE-2008-2650CMSimple 3.1 - Local File Inclusioncmsimple6.8 (v2.0)Medium
CVE-2008-6172Joomla! Component RWCards 3.0.11 - Local File Inclusionrwcards6.8 (v2.0)Medium
CVE-2010-1056Joomla! Component com_rokdownloads - Local File Inclusioncom rokdownloads6.8 (v2.0)Medium
CVE-2010-1219Joomla! Component com_janews - Local File Inclusioncom janews6.8 (v2.0)Medium
CVE-2010-1469Joomla! Component JProject Manager 1.0 - Local File Inclusioncom jprojectmanager6.8 (v2.0)Medium
CVE-2010-1473Joomla! Component Advertising 0.25 - Local File Inclusioncom advertising6.8 (v2.0)Medium
CVE-2010-1474Joomla! Component Sweetykeeper 1.5 - Local File Inclusioncom sweetykeeper6.8 (v2.0)Medium
CVE-2010-1475Joomla! Component Preventive And Reservation 1.0.5 - Local File Inclusioncom preventive6.8 (v2.0)Medium
CVE-2010-1476Joomla! Component AlphaUserPoints 1.5.5 - Local File Inclusioncom alphauserpoints6.8 (v2.0)Medium
CVE-2010-1478Joomla! Component Jfeedback 1.2 - Local File Inclusioncom jfeedback6.8 (v2.0)Medium
CVE-2010-1607Joomla! Component WMI 1.5.0 - Local File Inclusioncom wmi6.8 (v2.0)Medium
CVE-2010-1715Joomla! Component Online Exam 1.5.0 - Local File Inclusioncom onlineexam6.8 (v2.0)Medium
CVE-2010-1718Joomla! Component Archery Scores 1.0.6 - Local File Inclusioncom archeryscores6.8 (v2.0)Medium
CVE-2010-1719Joomla! Component MT Fire Eagle 1.2 - Local File Inclusioncom mtfireeagle6.8 (v2.0)Medium
CVE-2010-1722Joomla! Component Online Market 2.x - Local File Inclusioncom market6.8 (v2.0)Medium
CVE-2010-1723Joomla! Component iNetLanka Contact Us Draw Root Map 1.1 - Local File Inclusioncom drawroot6.8 (v2.0)Medium
CVE-2010-1979Joomla! Component Affiliate Datafeeds 880 - Local File Inclusioncom datafeeds6.8 (v2.0)Medium
CVE-2010-1981Joomla! Component Fabrik 2.0 - Local File Inclusionfabrik6.8 (v2.0)Medium
CVE-2010-2122Joomla! Component simpledownload <=0.9.5 - Arbitrary File Retrievalcom simpledownload6.8 (v2.0)Medium
CVE-2010-2507Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusioncom picasa2gallery6.8 (v2.0)Medium
CVE-2010-2857Joomla! Component Music Manager - Local File Inclusioncom music6.8 (v2.0)Medium
CVE-2010-2920Joomla! Component Foobla Suggestions 1.5.1.2 - Local File Inclusioncom foobla suggestions6.8 (v2.0)Medium
CVE-2010-4617Joomla! Component JotLoader 2.2.1 - Local File Inclusioncom jotloader6.8 (v2.0)Medium
CVE-2011-2744Chyrp 2.x - Local File Inclusionchyrp6.8 (v2.0)Medium
CVE-2025-59709biztalk360 Path Traversal Vulnerabilitybiztalk3606.8 (v3.1)Medium
CVE-2026-34216CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in SettingsController.phppanel6.6 (v3.1)Medium
CVE-2016-6435Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusionsecure firewall management center6.5 (v3.0)Medium
CVE-2017-14537Trixbox 2.8.0 - Path Traversaltrixbox6.5 (v3.1)Medium
CVE-2018-15140OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actionsopenemr6.5 (v3.0)Medium
CVE-2018-15141OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actionsopenemr6.5 (v3.0)Medium
CVE-2021-36749Apache Druid - Local File Inclusiondruid6.5 (v3.1)Medium
CVE-2024-24565CrateDB Database - Arbitrary File Readcratedb6.5 (v3.1)Medium
CVE-2026-72739Dokploy: Command Injection via Compose Shell Executiondokploy6.5 (v3.1)Medium
CVE-2009-0932Horde/Horde Groupware - Local File Inclusionhorde6.4 (v2.0)Medium
CVE-2026-45626Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameterarcane6.3 (v3.1)Medium
CVE-2010-0467Joomla! Component CCNewsLetter - Local File Inclusioncom ccnewsletter5.8 (v3.1)Medium
CVE-2025-13786taosir WTCMS index.php fetch code injectionwtcms5.5 (v4.0)Medium
CVE-2025-13792Qualitor getResumo.php eval code injectionQualitor5.5 (v4.0)Medium
CVE-2026-10214zhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injectionchatgpt-on-wechat5.5 (v4.0)Medium
CVE-2026-18641Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginCOperation and Maintenance Security Management System5.5 (v4.0)Medium
CVE-2026-19379EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injectionipTIME AX8004M5.5 (v4.0)Medium
CVE-2026-54611InstantCMS has Remote Code Execution in package installericms25.5 (v3.1)Medium
CVE-2026-5631assafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injectiongpt-researcher5.5 (v4.0)Medium
CVE-2026-5677Totolink A7100RU cstecgi.cgi CsteSystem os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5678Totolink A7100RU cstecgi.cgi setScheduleCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5688Totolink A7100RU cstecgi.cgi setDdnsCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5689Totolink A7100RU cstecgi.cgi setNtpCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5690Totolink A7100RU cstecgi.cgi setRemoteCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5691Totolink A7100RU cstecgi.cgi setFirewallType os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5692Totolink A7100RU cstecgi.cgi setGameSpeedCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5736PowerJob detailPlus Endpoint InstanceController.java sql injectionPowerJob5.5 (v4.0)Medium
CVE-2026-5741suvarchal docker-mcp-server HTTP index.ts pull_image os command injectiondocker-mcp-server5.5 (v4.0)Medium
CVE-2026-5802idachev mcp-javadc HTTP os command injectionmcp-javadc5.5 (v4.0)Medium
CVE-2026-7220jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injectionFastlyMCP5.5 (v4.0)Medium
CVE-2026-76760chenhg5 cc-connect webhook.go authenticate code injectioncc-connect5.5 (v4.0)Medium
CVE-2026-76761chenhg5 cc-connect Management API engine.go shellExecCommand os command injectioncc-connect5.5 (v4.0)Medium
CVE-2026-82598SeaCMS Template search.php parseIf code injectionSeaCMS5.5 (v4.0)Medium
CVE-2026-85137SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injectionSeaCMS5.5 (v4.0)Medium
CVE-2026-9474yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injectionStudentManagementSystem5.5 (v4.0)Medium
CVE-2026-54543Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fieldsfroxlor5.4 (v3.1)Medium
CVE-2023-7299DataGear resolveSql sql injectiondatagear5.3 (v4.0)Medium
CVE-2026-19785francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injectionRosarioSIS5.3 (v4.0)Medium
CVE-2026-5547Tenda AC10 httpd formAddMacfilterRule os command injectionac10 firmware5.3 (v4.0)Medium
CVE-2010-0942Joomla! Component com_jvideodirect - Directory Traversalcom jvideodirect5.0 (v2.0)Medium
CVE-2010-0943Joomla! Component com_jashowcase - Directory Traversalcom jashowcase5.0 (v2.0)Medium
CVE-2010-0944Joomla! Component com_jcollection - Directory Traversalcom jcollection5.0 (v2.0)Medium
CVE-2010-1081Joomla! Component com_communitypolls 1.5.2 - Local File Inclusioncom communitypolls5.0 (v2.0)Medium
CVE-2010-1302Joomla! Component DW Graph - Local File Inclusioncom dwgraphs5.0 (v2.0)Medium
CVE-2010-1304Joomla! Component User Status - Local File Inclusioncom userstatus5.0 (v2.0)Medium
CVE-2010-1305Joomla! Component JInventory 1.23.02 - Local File Inclusioncom jinventory5.0 (v2.0)Medium
CVE-2010-1307Joomla! Component Magic Updater - Local File Inclusioncom joomlaupdater5.0 (v2.0)Medium
CVE-2010-1308Joomla! Component SVMap 1.1.1 - Local File Inclusioncom svmap5.0 (v2.0)Medium
CVE-2010-1312Joomla! Component News Portal 1.5.x - Local File Inclusioncom news portal5.0 (v2.0)Medium
CVE-2010-1314Joomla! Component Highslide 1.5 - Local File Inclusioncom hsconfig5.0 (v2.0)Medium
CVE-2010-1315Joomla! Component webERPcustomer - Local File Inclusioncom weberpcustomer5.0 (v2.0)Medium
CVE-2010-1340Joomla! Component com_jresearch - 'Controller' Local File Inclusioncom jresearch5.0 (v2.0)Medium
CVE-2010-1345Joomla! Component Cookex Agency CKForms - Local File Inclusioncom ckforms5.0 (v2.0)Medium
CVE-2010-1352Joomla! Component Juke Box 1.7 - Local File Inclusioncom jukebox5.0 (v2.0)Medium
CVE-2010-1353Joomla! Component LoginBox - Local File Inclusioncom loginbox5.0 (v2.0)Medium
CVE-2010-1354Joomla! Component VJDEO 1.0 - Local File Inclusioncom vjdeo5.0 (v2.0)Medium
CVE-2010-1461Joomla! Component Photo Battle 1.0.1 - Local File Inclusioncom photobattle5.0 (v2.0)Medium
CVE-2010-1491Joomla! Component MMS Blog 2.3.0 - Local File Inclusioncom mmsblog5.0 (v2.0)Medium
CVE-2010-1494Joomla! Component AWDwall 1.5.4 - Local File Inclusioncom awdwall5.0 (v2.0)Medium
CVE-2010-1532Joomla! Component PowerMail Pro 1.5.3 - Local File Inclusioncom powermail5.0 (v2.0)Medium
CVE-2010-1534Joomla! Component Shoutbox Pro - Local File Inclusioncom shoutbox5.0 (v2.0)Medium
CVE-2010-1540Joomla! Component com_blog - Directory Traversalcom myblog5.0 (v2.0)Medium
CVE-2010-1601Joomla! Component JA Comment - Local File Inclusioncom jacomment5.0 (v2.0)Medium
CVE-2010-1657Joomla! Component SmartSite 1.0.0 - Local File Inclusioncom smartsite5.0 (v2.0)Medium
CVE-2010-1658Joomla! Component NoticeBoard 1.3 - Local File Inclusioncom noticeboard5.0 (v2.0)Medium
CVE-2010-1659Joomla! Component Ultimate Portfolio 1.0 - Local File Inclusioncom ultimateportfolio5.0 (v2.0)Medium
CVE-2010-1714Joomla! Component Arcade Games 1.0 - Local File Inclusioncom arcadegames5.0 (v2.0)Medium
CVE-2010-1858Joomla! Component SMEStorage - Local File Inclusioncom smestorage5.0 (v2.0)Medium
CVE-2010-1982Joomla! Component JA Voice 2.0 - Local File Inclusioncom javoice5.0 (v2.0)Medium
CVE-2011-4804Joomla! Component com_kp - 'Controller' Local File Inclusioncom obsuggest5.0 (v2.0)Medium
CVE-2012-099611in1 CMS 1.2.1 - Local File Inclusion (LFI)11in15.0 (v2.0)Medium
CVE-2013-5979Xibo 1.2.2/1.4.1 - Directory Traversalxibo5.0 (v2.0)Medium
CVE-2013-7091Zimbra Collaboration Server 7.2.2/8.0.2 Local File Inclusionzimbra collaboration suite5.0 (v2.0)Medium
CVE-2014-5111Fonality trixbox - Local File Inclusiontrixbox5.0 (v2.0)Medium
CVE-2008-5587phpPgAdmin <=4.2.1 - Local File Inclusionphppgadmin4.3 (v2.0)Medium
CVE-2010-1217Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusionje form creator4.3 (v2.0)Medium
CVE-2010-1313Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusioncom sebercart4.3 (v2.0)Medium
CVE-2012-4253MySQLDumper 1.24.4 - Directory Traversalmysqldumper4.3 (v2.0)Medium
CVE-2012-0991OpenEMR 4.1 - Local File Inclusionopenemr3.5 (v2.0)Low
CVE-2026-10172Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted uploadMulti-Store Inventory Management System2.1 (v4.0)Low
CVE-2026-10279hiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injectionwezterm-mcp2.1 (v4.0)Low
CVE-2026-11408vertex-app vertex Log Viewer Endpoint LogMod.js os command injectionvertex2.1 (v4.0)Low
CVE-2026-19958iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injectionpptr-mcp2.1 (v4.0)Low
CVE-2026-5351Trendnet TEW-657BRM setup.cgi add_wps_client os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5352Trendnet TEW-657BRM setup.cgi edit os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5353Trendnet TEW-657BRM setup.cgi ping_test os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5354Trendnet TEW-657BRM setup.cgi vpn_connect os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5355Trendnet TEW-657BRM setup.cgi vpn_drop os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-78166provectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest code injectionkafka-ui2.1 (v4.0)Low
CVE-2026-8188Wavlink NU516U1 adm.cgi change_wifi_password os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8189Wavlink NU516U1 adm.cgi wzdrepeater os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8190Wavlink NU516U1 adm.cgi wan os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8191Wavlink NU516U1 adm.cgi wifi_region os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8192Wavlink NU516U1 adm.cgi wzdap os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8227Wavlink NU516U1 adm.cgi wzdapMesh os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8228Wavlink NU516U1 wireless.cgi advance os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8229Wavlink NU516U1 wireless.cgi WifiBasic os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8230Wavlink NU516U1 login.cgi sys_login1 os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8264Tenda AC6 httpd WifiApScan formWifiApScan os command injectionac6 firmware2.1 (v4.0)Low
CVE-2026-9302546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injectionvps-inventory-monitoring2.1 (v4.0)Low
CVE-2026-9343Edimax EW-7438RPn webs formWpsStart os command injectionEW-7438RPn2.1 (v4.0)Low
CVE-2026-9347Edimax EW-7438RPn webs formWizSurvey os command injectionEW-7438RPn2.1 (v4.0)Low
CVE-2026-9424Edimax EW-7438RPn Content-Type formWlanMP os command injectionEW-7438RPn2.1 (v4.0)Low
CVE-2026-9511Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9512Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9514Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9515Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9531Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9532Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9533Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9534Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-19964Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injectionJij-MCP-Server2.0 (v4.0)Low
CVE-2026-78140Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engineUJCMS2.0 (v4.0)Low
CVE-2026-8259Tenda AC6 httpd telnet os command injectionac6 firmware2.0 (v4.0)Low
CVE-2026-8265Tenda AC6 httpd getLogFile get_log_file os command injectionac6 firmware2.0 (v4.0)Low
CVE-2026-82678diem-project diem Administrative Console actions.class.php executeCommand os command injectiondiem2.0 (v4.0)Low
CVE-2026-82702Edimax BR-6214K asp_WlanMP Endpoint wlanMP.asp system os command injectionBR-6214K2.0 (v4.0)Low
CVE-2026-82703Edimax BR-6214K asp_setPing Endpoint ping.asp system os command injectionBR-6214K2.0 (v4.0)Low
CVE-2026-85040ZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injectionCRMEB2.0 (v4.0)Low
CVE-2026-16129princezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklistSafestClaw1.9 (v4.0)Low
CVE-2026-5621ChrisChinchilla Vale-MCP HTTP index.ts os command injectionVale-MCP1.9 (v4.0)Low
CVE-2026-19353DedeCMS Installation Wizard index.php _4_Setup file inclusionDedeCMS1.3 (v4.0)Low

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-20CVE-2009-0545 , CVE-2026-47668 , CVE-2017-12611 , CVE-2018-11686 , CVE-2026-35048 , CVE-2026-57499 , CVE-2026-24893 , CVE-2026-34197 , CVE-2026-35031 , CVE-2026-45505 , CVE-2025-34115 , CVE-2026-28797 , CVE-2026-42588 , CVE-2026-27891
CWE-22CVE-2010-5286 , CVE-2022-1391 , CVE-2019-25687 , CVE-2026-64824 , CVE-2018-15142 , CVE-2020-8641 , CVE-2026-35031 , CVE-2026-82217 , CVE-2019-25671 , CVE-2026-39352 , CVE-2024-48766 , CVE-2025-59711 , CVE-2026-75842 , CVE-2010-0972 , CVE-2010-0985 , CVE-2010-1306 , CVE-2010-1470 , CVE-2010-1471 , CVE-2010-1472 , CVE-2010-1495 , CVE-2010-1531 , CVE-2010-1533 , CVE-2010-1535 , CVE-2010-1602 , CVE-2010-1603 , CVE-2010-1653 , CVE-2010-1717 , CVE-2010-1875 , CVE-2010-1878 , CVE-2010-1952 , CVE-2010-1953 , CVE-2010-1954 , CVE-2010-1955 , CVE-2010-1956 , CVE-2010-1957 , CVE-2010-1977 , CVE-2010-1980 , CVE-2010-1983 , CVE-2010-2033 , CVE-2010-2034 , CVE-2010-2035 , CVE-2010-2036 , CVE-2010-2037 , CVE-2010-2045 , CVE-2010-2050 , CVE-2010-2128 , CVE-2010-2259 , CVE-2010-2682 , CVE-2010-3426 , CVE-2010-4719 , CVE-2010-4769 , CVE-2014-10037 , CVE-2017-9833 , CVE-2018-15138 , CVE-2019-7254 , CVE-2020-35598 , CVE-2022-29298 , CVE-2023-40924 , CVE-2026-46581 , CVE-2008-2650 , CVE-2008-6172 , CVE-2010-1056 , CVE-2010-1219 , CVE-2010-1469 , CVE-2010-1473 , CVE-2010-1474 , CVE-2010-1475 , CVE-2010-1476 , CVE-2010-1478 , CVE-2010-1607 , CVE-2010-1715 , CVE-2010-1718 , CVE-2010-1719 , CVE-2010-1722 , CVE-2010-1723 , CVE-2010-1979 , CVE-2010-1981 , CVE-2010-2122 , CVE-2010-2507 , CVE-2010-2857 , CVE-2010-2920 , CVE-2010-4617 , CVE-2011-2744 , CVE-2025-59709 , CVE-2017-14537 , CVE-2018-15140 , CVE-2018-15141 , CVE-2024-24565 , CVE-2009-0932 , CVE-2010-0467 , CVE-2010-0942 , CVE-2010-0943 , CVE-2010-0944 , CVE-2010-1081 , CVE-2010-1302 , CVE-2010-1304 , CVE-2010-1305 , CVE-2010-1307 , CVE-2010-1308 , CVE-2010-1312 , CVE-2010-1314 , CVE-2010-1315 , CVE-2010-1340 , CVE-2010-1345 , CVE-2010-1352 , CVE-2010-1353 , CVE-2010-1354 , CVE-2010-1461 , CVE-2010-1491 , CVE-2010-1494 , CVE-2010-1532 , CVE-2010-1534 , CVE-2010-1540 , CVE-2010-1601 , CVE-2010-1657 , CVE-2010-1658 , CVE-2010-1659 , CVE-2010-1714 , CVE-2010-1858 , CVE-2010-1982 , CVE-2011-4804 , CVE-2012-0996 , CVE-2013-5979 , CVE-2013-7091 , CVE-2014-5111 , CVE-2008-5587 , CVE-2010-1217 , CVE-2010-1313 , CVE-2012-4253 , CVE-2012-0991
CWE-59CVE-2026-71964
CWE-73CVE-2026-19353
CWE-74CVE-2026-45344 , CVE-2026-11450 , CVE-2026-5739 , CVE-2025-13786 , CVE-2025-13792 , CVE-2026-5631 , CVE-2026-5736 , CVE-2026-76760 , CVE-2026-82598 , CVE-2026-85137 , CVE-2026-9474 , CVE-2026-54543 , CVE-2023-7299 , CVE-2026-19785 , CVE-2026-19958 , CVE-2026-78166 , CVE-2026-9302 , CVE-2026-19964
CWE-77CVE-2026-72869 , CVE-2022-40881 , CVE-2026-35847 , CVE-2026-8037 , CVE-2026-47670 , CVE-2026-7202 , CVE-2026-7203 , CVE-2026-7204 , CVE-2026-9384 , CVE-2026-9385 , CVE-2026-9386 , CVE-2026-9387 , CVE-2026-9388 , CVE-2026-9404 , CVE-2026-9405 , CVE-2026-9406 , CVE-2026-9407 , CVE-2026-9408 , CVE-2026-9432 , CVE-2026-9433 , CVE-2026-9434 , CVE-2026-9435 , CVE-2026-9436 , CVE-2026-9454 , CVE-2026-9455 , CVE-2026-9456 , CVE-2026-9457 , CVE-2026-9458 , CVE-2026-9475 , CVE-2026-9476 , CVE-2026-9477 , CVE-2026-9478 , CVE-2020-15874 , CVE-2026-55182 , CVE-2026-82692 , CVE-2026-85223 , CVE-2026-86299 , CVE-2026-82690 , CVE-2026-82691 , CVE-2026-85222 , CVE-2026-85224 , CVE-2026-10870 , CVE-2026-10871 , CVE-2026-10873 , CVE-2026-18900 , CVE-2026-19771 , CVE-2026-11450 , CVE-2026-19983 , CVE-2026-10214 , CVE-2026-18641 , CVE-2026-19379 , CVE-2026-5677 , CVE-2026-5678 , CVE-2026-5688 , CVE-2026-5689 , CVE-2026-5690 , CVE-2026-5691 , CVE-2026-5692 , CVE-2026-5741 , CVE-2026-5802 , CVE-2026-7220 , CVE-2026-76761 , CVE-2026-5547 , CVE-2026-10279 , CVE-2026-11408 , CVE-2026-5351 , CVE-2026-5352 , CVE-2026-5353 , CVE-2026-5354 , CVE-2026-5355 , CVE-2026-8188 , CVE-2026-8189 , CVE-2026-8190 , CVE-2026-8191 , CVE-2026-8192 , CVE-2026-8227 , CVE-2026-8228 , CVE-2026-8229 , CVE-2026-8230 , CVE-2026-8264 , CVE-2026-9343 , CVE-2026-9347 , CVE-2026-9424 , CVE-2026-9511 , CVE-2026-9512 , CVE-2026-9514 , CVE-2026-9515 , CVE-2026-9531 , CVE-2026-9532 , CVE-2026-9533 , CVE-2026-9534 , CVE-2026-8259 , CVE-2026-8265 , CVE-2026-82678 , CVE-2026-82702 , CVE-2026-82703 , CVE-2026-85040 , CVE-2026-5621
CWE-78CVE-2025-34037 , CVE-2026-19188 , CVE-2026-34234 , CVE-2026-49869 , CVE-2026-42454 , CVE-2026-45629 , CVE-2026-45632 , CVE-2026-48030 , CVE-2026-63298 , CVE-2026-72738 , CVE-2026-72740 , CVE-2026-72865 , CVE-2026-72868 , CVE-2026-72869 , CVE-2026-72872 , CVE-2026-72876 , CVE-2026-72882 , CVE-2026-72902 , CVE-2026-73263 , CVE-2026-73294 , CVE-2019-12725 , CVE-2019-12985 , CVE-2019-12986 , CVE-2019-16662 , CVE-2019-20504 , CVE-2019-7256 , CVE-2022-29303 , CVE-2022-31137 , CVE-2023-25826 , CVE-2024-50603 , CVE-2026-12940 , CVE-2026-18482 , CVE-2026-37281 , CVE-2026-45018 , CVE-2026-48687 , CVE-2026-49819 , CVE-2026-53545 , CVE-2026-79408 , CVE-2026-35906 , CVE-2026-72878 , CVE-2026-47670 , CVE-2026-63732 , CVE-2026-72879 , CVE-2026-73483 , CVE-2026-19586 , CVE-2026-53975 , CVE-2026-60121 , CVE-2026-61498 , CVE-2026-63766 , CVE-2026-64625 , CVE-2026-67308 , CVE-2026-71921 , CVE-2026-71944 , CVE-2026-71945 , CVE-2026-71946 , CVE-2026-71947 , CVE-2026-71948 , CVE-2026-71949 , CVE-2026-71950 , CVE-2026-71951 , CVE-2026-71952 , CVE-2026-71953 , CVE-2026-71954 , CVE-2026-71955 , CVE-2026-71956 , CVE-2026-71984 , CVE-2026-71992 , CVE-2026-63304 , CVE-2026-63305 , CVE-2026-80138 , CVE-2026-57499 , CVE-2026-45630 , CVE-2026-7202 , CVE-2026-7203 , CVE-2026-7204 , CVE-2026-73570 , CVE-2026-9384 , CVE-2026-9385 , CVE-2026-9386 , CVE-2026-9387 , CVE-2026-9388 , CVE-2026-9404 , CVE-2026-9405 , CVE-2026-9406 , CVE-2026-9407 , CVE-2026-9408 , CVE-2026-9432 , CVE-2026-9433 , CVE-2026-9434 , CVE-2026-9435 , CVE-2026-9436 , CVE-2026-9454 , CVE-2026-9455 , CVE-2026-9456 , CVE-2026-9457 , CVE-2026-9458 , CVE-2026-9475 , CVE-2026-9476 , CVE-2026-9477 , CVE-2026-9478 , CVE-2017-6884 , CVE-2026-24893 , CVE-2026-26899 , CVE-2026-34197 , CVE-2026-35196 , CVE-2026-45578 , CVE-2026-45662 , CVE-2026-58195 , CVE-2026-72875 , CVE-2026-73222 , CVE-2026-79423 , CVE-2025-30007 , CVE-2025-34115 , CVE-2026-28797 , CVE-2026-34792 , CVE-2026-34793 , CVE-2026-34794 , CVE-2026-34795 , CVE-2026-34796 , CVE-2026-34797 , CVE-2026-46746 , CVE-2026-69096 , CVE-2026-71966 , CVE-2026-72870 , CVE-2026-72874 , CVE-2026-73680 , CVE-2026-76060 , CVE-2026-79756 , CVE-2026-40187 , CVE-2026-53804 , CVE-2026-61517 , CVE-2026-63725 , CVE-2026-65711 , CVE-2026-67599 , CVE-2026-67608 , CVE-2026-71906 , CVE-2026-71907 , CVE-2026-71908 , CVE-2026-71913 , CVE-2026-71915 , CVE-2026-71918 , CVE-2026-71919 , CVE-2026-71923 , CVE-2026-71924 , CVE-2026-71925 , CVE-2026-71926 , CVE-2026-71927 , CVE-2026-71928 , CVE-2026-71929 , CVE-2026-71930 , CVE-2026-71931 , CVE-2026-71943 , CVE-2026-75121 , CVE-2026-75122 , CVE-2026-75123 , CVE-2026-80214 , CVE-2026-82692 , CVE-2026-84194 , CVE-2026-85223 , CVE-2026-86299 , CVE-2026-86733 , CVE-2026-82690 , CVE-2026-82691 , CVE-2026-85222 , CVE-2026-85224 , CVE-2025-69755 , CVE-2026-48695 , CVE-2026-79755 , CVE-2021-21315 , CVE-2026-40519 , CVE-2026-10870 , CVE-2026-10871 , CVE-2026-10873 , CVE-2026-18900 , CVE-2026-19771 , CVE-2026-71284 , CVE-2026-19983 , CVE-2026-72739 , CVE-2026-45626 , CVE-2026-10214 , CVE-2026-18641 , CVE-2026-19379 , CVE-2026-5677 , CVE-2026-5678 , CVE-2026-5688 , CVE-2026-5689 , CVE-2026-5690 , CVE-2026-5691 , CVE-2026-5692 , CVE-2026-5741 , CVE-2026-5802 , CVE-2026-7220 , CVE-2026-76761 , CVE-2026-5547 , CVE-2026-10279 , CVE-2026-11408 , CVE-2026-5351 , CVE-2026-5352 , CVE-2026-5353 , CVE-2026-5354 , CVE-2026-5355 , CVE-2026-8188 , CVE-2026-8189 , CVE-2026-8190 , CVE-2026-8191 , CVE-2026-8192 , CVE-2026-8227 , CVE-2026-8228 , CVE-2026-8229 , CVE-2026-8230 , CVE-2026-8264 , CVE-2026-9343 , CVE-2026-9347 , CVE-2026-9424 , CVE-2026-9511 , CVE-2026-9512 , CVE-2026-9514 , CVE-2026-9515 , CVE-2026-9531 , CVE-2026-9532 , CVE-2026-9533 , CVE-2026-9534 , CVE-2026-8259 , CVE-2026-8265 , CVE-2026-82678 , CVE-2026-82702 , CVE-2026-82703 , CVE-2026-85040 , CVE-2026-5621
CWE-79CVE-2026-73041 , CVE-2026-73042 , CVE-2024-39024
CWE-88CVE-2026-44450 , CVE-2026-73294
CWE-89CVE-2026-55634 , CVE-2024-5827 , CVE-2026-38428 , CVE-2026-33324 , CVE-2026-34612 , CVE-2010-4977 , CVE-2010-5028 , CVE-2026-5736 , CVE-2026-9474 , CVE-2023-7299 , CVE-2026-19785
CWE-93CVE-2026-84372
CWE-94CVE-2026-47668 , CVE-2026-8984 , CVE-2026-55565 , CVE-2026-55634 , CVE-2026-8481 , CVE-2009-1151 , CVE-2018-17173 , CVE-2026-31040 , CVE-2026-38431 , CVE-2026-46562 , CVE-2026-67919 , CVE-2026-75411 , CVE-2026-75414 , CVE-2026-70477 , CVE-2025-62593 , CVE-2026-45272 , CVE-2026-69256 , CVE-2018-25357 , CVE-2026-65008 , CVE-2026-70553 , CVE-2026-46621 , CVE-2026-55511 , CVE-2026-58400 , CVE-2026-62674 , CVE-2026-69251 , CVE-2026-73485 , CVE-2026-73486 , CVE-2026-73487 , CVE-2026-43945 , CVE-2026-34197 , CVE-2026-45505 , CVE-2026-48017 , CVE-2026-55585 , CVE-2026-62675 , CVE-2026-78834 , CVE-2021-47938 , CVE-2022-50944 , CVE-2026-28797 , CVE-2026-49143 , CVE-2026-64850 , CVE-2026-72819 , CVE-2026-76836 , CVE-2026-82278 , CVE-2026-85610 , CVE-2026-86732 , CVE-2026-42785 , CVE-2026-56703 , CVE-2026-61523 , CVE-2026-65693 , CVE-2026-69088 , CVE-2026-22244 , CVE-2026-42588 , CVE-2026-47398 , CVE-2026-66738 , CVE-2026-46581 , CVE-2026-13392 , CVE-2026-77939 , CVE-2026-5739 , CVE-2025-13786 , CVE-2025-13792 , CVE-2026-54611 , CVE-2026-5631 , CVE-2026-76760 , CVE-2026-82598 , CVE-2026-85137 , CVE-2026-19958 , CVE-2026-78166 , CVE-2026-9302 , CVE-2026-19964
CWE-95CVE-2026-46562 , CVE-2026-47391 , CVE-2026-39932 , CVE-2025-31114 , CVE-2026-61511 , CVE-2026-40187
CWE-120CVE-2026-36796
CWE-121CVE-2026-76070 , CVE-2026-76071 , CVE-2026-36783
CWE-183CVE-2026-16129
CWE-184CVE-2026-49869 , CVE-2026-16129
CWE-187CVE-2026-35031
CWE-200CVE-2025-69755 , CVE-2026-51078 , CVE-2016-6435
CWE-253CVE-2026-15686
CWE-269CVE-2026-45632 , CVE-2026-49819 , CVE-2026-72830 , CVE-2026-73664
CWE-284CVE-2026-34234 , CVE-2026-43945 , CVE-2026-73664 , CVE-2026-10172
CWE-285CVE-2026-34239
CWE-287CVE-2026-49869 , CVE-2025-27621
CWE-288CVE-2026-43945
CWE-306CVE-2026-81735 , CVE-2026-47391 , CVE-2026-49819 , CVE-2026-73222 , CVE-2023-54350 , CVE-2025-34115 , CVE-2026-63722 , CVE-2026-49471
CWE-352CVE-2025-62593 , CVE-2026-73222 , CVE-2026-34228 , CVE-2026-49471
CWE-434CVE-2026-44402 , CVE-2023-7305 , CVE-2025-59710 , CVE-2021-47943 , CVE-2026-34735 , CVE-2026-67206 , CVE-2026-53599 , CVE-2026-27891 , CVE-2026-54611 , CVE-2026-10172
CWE-470CVE-2026-46562 , CVE-2026-58400 , CVE-2026-34216
CWE-494CVE-2026-66398
CWE-502CVE-2026-3296
CWE-611CVE-2019-9757
CWE-639CVE-2026-72876
CWE-641CVE-2026-46581
CWE-644CVE-2026-67179
CWE-698CVE-2024-48766
CWE-732CVE-2026-73664
CWE-791CVE-2026-78140
CWE-829CVE-2026-45272 , CVE-2026-47398
CWE-835CVE-2024-20353
CWE-862CVE-2026-45632 , CVE-2026-72868 , CVE-2026-72876 , CVE-2026-49819 , CVE-2026-86438
CWE-863CVE-2026-43945 , CVE-2026-76836 , CVE-2026-86437 , CVE-2021-36749
CWE-915CVE-2026-78416
CWE-918CVE-2026-49869
CWE-942CVE-2026-34449
CWE-1188CVE-2026-47668
CWE-1336CVE-2026-44181 , CVE-2026-28797 , CVE-2026-22244 , CVE-2026-77939 , CVE-2026-78140
CWE-1392CVE-2026-41939

Documentation Source

  • Original wiki page: WAF 340029
  • Source revision: 4329
  • Source revision date: 2013-12-12