On this page

Atomicorp WAF Rule 344361

Rule Summary

Description

This rule detects behavior identified by its current alert as “Remote Command Execution: Unix Command Injection (2-3 chars)” in the request cookies, request argument names, request arguments, JSON request data, SOAP request data, XML request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2025-34037Linksys Routers E/WAG/WAP/WES/WET/WRT-SeriesE420010.0 (v4.0)Critical
CVE-2026-19188Haiwell IoT Cloud HMI Gateway OS Command InjectionHaiwell IoT Cloud HMI Gateway10.0 (v4.0)Critical
CVE-2026-34234CtrlPanel: Unauthenticated RCE using installer scriptpanel10.0 (v3.1)Critical
CVE-2026-44181Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Executionenterprise gateway10.0 (v4.0)Critical
CVE-2026-47668DbGate - Remote Code Execution via Anonymous JWTdbgate10.0 (v3.1)Critical
CVE-2026-49869Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in AuthenticationFilterkestra10.0 (v3.1)Critical
CVE-2026-81735UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command ExecutiUI-TARS-desktop10.0 (v4.0)Critical
CVE-2026-8984Unauthenticated RCEmaxicharger single charger firmware10.0 (v4.0)Critical
CVE-2026-8985Unauthenticated Command Injectionmaxicharger single charger firmware10.0 (v4.0)Critical
CVE-2026-42454Termix: OS Command Injection in Docker Container Management EndpointsTermix9.9 (v3.1)Critical
CVE-2026-44450Lumiverse: RCE via MCP stdio argument injectionLumiverse9.9 (v3.1)Critical
CVE-2026-45629Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpointdokploy9.9 (v3.1)Critical
CVE-2026-45632Dokploy: Schedule Authorization Bypass Enables Host/Server Command Executiondokploy9.9 (v3.1)Critical
CVE-2026-48030Pheditor 2.0.1-2.0.3 - OS Command Injectionpheditor9.9 (v3.1)Critical
CVE-2026-55565Yamcs: Authenticated remote code execution via unescaped StreamSQL LIKE pattern compiled by Janino (LikeExpression)yamcs9.9 (v3.1)Critical
CVE-2026-55634Pimcore: Remote Code Execution via DataObject Class-Definition Field Namepimcore9.9 (v3.1)Critical
CVE-2026-63298LXD arbitrary lxc.conf directive injection via NVIDIA instance configurationlxd9.9 (v3.1)Critical
CVE-2026-72738Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameterdokploy9.9 (v3.1)Critical
CVE-2026-72740Dokploy: OS Command Injection via SSH-form customGitUrl domain in ssh-keyscandokploy9.9 (v3.1)Critical
CVE-2026-72865Dokploy: OS Command Injection via compose composePathdokploy9.9 (v3.1)Critical
CVE-2026-72868Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injectiondokploy9.9 (v3.1)Critical
CVE-2026-72869Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCEdokploy9.9 (v3.1)Critical
CVE-2026-72872Dokploy: OS Command Injection via Bitbucket owner/repository in git clonedokploy9.9 (v3.1)Critical
CVE-2026-72876Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*dokploy9.9 (v3.1)Critical
CVE-2026-72882Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed serversdokploy9.9 (v3.1)Critical
CVE-2026-72902Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryByIddokploy9.9 (v3.1)Critical
CVE-2026-73263Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-pathprowler9.9 (v3.1)Critical
CVE-2026-73294Semaphore U: OS Command Injectionsemaphore9.9 (v3.1)Critical
CVE-2026-8481Remote Code Execution via Code Validation Endpointlangflow9.9 (v3.1)Critical
CVE-2013-2251Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Executionstruts9.8 (v3.1)Critical
CVE-2014-1203Eyou E-Mail <3.6 - Remote Code Executioneyou9.8 (v3.1)Critical
CVE-2015-4664Xceedium Xsuite - Multiple Vulnerabilitiesprivileged access manager9.8 (v3.0)Critical
CVE-2015-4667Xceedium Xsuite - Multiple Vulnerabilitiesxsuite9.8 (v3.0)Critical
CVE-2018-11686FlexPaper/FlowPaper 2.3.6 - Remote Code Executionflowpaper9.8 (v3.0)Critical
CVE-2018-17173LG Supersign EZ CMS - Remote Code Executionsupersign cms9.8 (v3.0)Critical
CVE-2018-17431Comodo Unified Threat Management Web Console - Remote Code Executionunified threat management firewall9.8 (v3.1)Critical
CVE-2018-18755K-iwi Framework 1775 - SQL Injectionk-iwi9.8 (v3.1)Critical
CVE-2018-19276OpenMRS Platform < 2.24.0 - Insecure Object Deserializationopenmrs9.8 (v3.1)Critical
CVE-2019-12725Zeroshell 3.9.0 - Remote Command Executionzeroshell9.8 (v3.0)Critical
CVE-2019-15107Webmin <= 1.920 - Unauthenticated Remote Command Executionwebmin9.8 (v3.1)Critical
CVE-2019-16662rConfig 3.9.2 - Remote Code Executionrconfig9.8 (v3.1)Critical
CVE-2019-16920D-Link Routers - Remote Code Executiondir-655 firmware9.8 (v3.1)Critical
CVE-2019-2729Oracle WebLogic Server Administration Console - Remote Code Executioncommunications diameter signaling router9.8 (v3.1)Critical
CVE-2019-7256eMerge E3 1.00-06 - Remote Code Executionlinear emerge essential firmware9.8 (v3.1)Critical
CVE-2020-14750Oracle WebLogic Server - Remote Command Executionfusion middleware9.8 (v3.1)Critical
CVE-2020-15920Mida eFramework <=2.9.0 - Remote Command Executioneframework9.8 (v3.1)Critical
CVE-2020-21224Inspur ClusterEngine 4.0 - Remote Code Executionclusterengine9.8 (v3.1)Critical
CVE-2020-28429geojson2kml - Command Injectiongeojson2kml9.8 (v3.1)Critical
CVE-2020-29390Zeroshell 3.9.3 - Command Injectionzeroshell9.8 (v3.1)Critical
CVE-2020-7209LinuxKI Toolset <= 6.01 - Remote Command Executionlinuxki9.8 (v3.1)Critical
CVE-2020-9054Zyxel NAS Firmware 5.21- Remote Code Executionnas326 firmware9.8 (v3.1)Critical
CVE-2021-24915Contest Gallery < 13.1.0.6 - SQL injectioncontest gallery9.8 (v3.1)Critical
CVE-2021-35395RealTek Jungle SDK - Arbitrary Command Injectionrealtek jungle sdk9.8 (v3.1)Critical
CVE-2022-0332Moodle 3.11.4 - SQL Injectionmoodle9.8 (v3.1)Critical
CVE-2022-1388F5 BIG-IP iControl - REST Auth Bypass RCEbig-ip access policy manager9.8 (v3.1)Critical
CVE-2022-1609The School Management < 9.9.7 - Remote Code Executionschool management9.8 (v3.1)Critical
CVE-2022-22954VMware Workspace ONE Access - Server-Side Template Injectionidentity manager9.8 (v3.1)Critical
CVE-2022-25082TOTOLink - Unauthenticated Command Injectiona950rg firmware9.8 (v3.1)Critical
CVE-2022-29303SolarView Compact 6.0 - OS Command Injectionsv-cpt-mc310 firmware9.8 (v3.1)Critical
CVE-2022-31137Roxy-WI < 6.1.1.0 - Remote Code Executionroxy-wi9.8 (v3.1)Critical
CVE-2022-3236Sophos Firewall <= 19.0 MR1 - Remote Code Executionfirewall9.8 (v3.1)Critical
CVE-2023-23333SolarView Compact 6.00 - OS Command Injectionsolarview compact firmware9.8 (v3.1)Critical
CVE-2023-26802DCBI-Netlog-LAB v1.0 - Command Injectiondcbi-netlog-lab firmware9.8 (v3.1)Critical
CVE-2023-31465TimeKeeper by FSMLabs - Remote Code Executiontimekeeper9.8 (v3.1)Critical
CVE-2023-34960Chamilo Command Injectionchamilo9.8 (v3.1)Critical
CVE-2023-3710Honeywell PM43 Printers - Command Injectionpm43 firmware9.8 (v3.1)Critical
CVE-2023-45852Viessmann Vitogate 300 - Remote Code Executionvitogate 300 firmware9.8 (v3.1)Critical
CVE-2024-53584OpenPanel 0.3.4 - OS Command Injectionopenpanel9.8 (v3.1)Critical
CVE-2026-12940Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpointlangflow9.8 (v3.1)Critical
CVE-2026-18482neo-mjs Command Injection Vulnerabilityneo-mjs9.8 (v3.1)Critical
CVE-2026-31040stata-mcp Code Injection Vulnerabilitystata-mcp9.8 (v3.1)Critical
CVE-2026-3296Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry MetadataEverest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder9.8 (v3.1)Critical
CVE-2026-34243wenxian: Command Injection in GitHub Actions Workflow via issue_comment.bodywenxian9.8 (v3.1)Critical
CVE-2026-35048Piwigo RCE via PHP Code Injection into Config File in InstallerPiwigo9.8 (v3.1)Critical
CVE-2026-35847the CheckUils.php file Arbitrary Code Execution Vulnerabilitythe CheckUils.php file9.8 (v3.1)Critical
CVE-2026-37281the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 Command Injection Vulnerabilitythe /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.09.8 (v3.1)Critical
CVE-2026-38428kestra SQL Injection Vulnerabilitykestra9.8 (v3.1)Critical
CVE-2026-38431erpnext Code Injection Vulnerabilityerpnext9.8 (v3.1)Critical
CVE-2026-45018Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code executionchainlit9.8 (v3.1)Critical
CVE-2026-46562Yamcs: Remote Code Execution via Mission Database algorithm overrideyamcs9.8 (v3.1)Critical
CVE-2026-47391PraisonAI's unauthenticated A2A official example can reach real LLM-driven eval() tool executionPraisonAI9.8 (v3.1)Critical
CVE-2026-48687fastnetmon Command Injection Vulnerabilityfastnetmon9.8 (v3.1)Critical
CVE-2026-49819UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmdUpSnap9.8 (v3.1)Critical
CVE-2026-53545Termix: Remote Code Execution via Tunnel Disconnect pkill Command InjectionTermix9.8 (v3.1)Critical
CVE-2026-55559Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance)yamcs9.8 (v3.1)Critical
CVE-2026-67919Halo 2.25.4 Arbitrary Code Execution Vulnerability-9.8 (v3.1)Critical
CVE-2026-72592dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Uploadphpfm9.8 (v3.1)Critical
CVE-2026-75411JeecgBoot v3.9.2 Code Injection Vulnerability-9.8 (v3.1)Critical
CVE-2026-75414In AntFlow V2.0.0, ActivitiTest.java Code Injection Vulnerability-9.8 (v3.1)Critical
CVE-2026-79408MetaGPT 0.8.1 Command Injection VulnerabilityMetaGPT 0.8.19.8 (v3.1)Critical
CVE-2026-8037Progress ADC LoadMaster - Command Injectionconnection manager for objectscale9.8 (v3.1)Critical
CVE-2026-84372Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connectionspredis9.8 (v3.1)Critical
CVE-2026-34449SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injectionsiyuan9.6 (v3.1)Critical
CVE-2026-35906An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 OS Command Injection Vulnerability-9.6 (v3.1)Critical
CVE-2026-53649Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCEjoro9.6 (v3.1)Critical
CVE-2026-72878Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell argumentsdokploy9.6 (v3.1)Critical
CVE-2026-70477Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerabilityflowise9.5 (v4.0)Critical
CVE-2026-88062OmniRoute ACP Custom-Agent Remote Code Execution (RCE)OmniRoute9.5 (v4.0)Critical
CVE-2026-8986Command Injection via Malicious OCPP Servermaxicharger single charger firmware9.5 (v4.0)Critical
CVE-2025-62593Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attackray9.4 (v4.0)Critical
CVE-2026-33324SQLBot prompt injection allows arbitrary SQL execution and remote code executionsqlbot9.4 (v4.0)Critical
CVE-2026-39932OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injectionopenemr9.4 (v4.0)Critical
CVE-2026-45272MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config Filetalebook9.4 (v4.0)Critical
CVE-2026-47670DbGate - Remote Code Execution via Dynamic Import Bypassdbgate9.4 (v4.0)Critical
CVE-2026-637329router before 0.4.60 Remote Code Execution via default password9router9.4 (v4.0)Critical
CVE-2026-66398phpMyFAQ before 4.1.6 Remote Code Execution via Configuration APIphpMyFAQ9.4 (v4.0)Critical
CVE-2026-69256Flowise: Remote Code Execution Vulnerability in CSVAgentFlowise9.4 (v4.0)Critical
CVE-2026-72879Dokploy: Command Injection via Registry Credentials in Swarm Uploaddokploy9.4 (v4.0)Critical
CVE-2026-73041SiYuan before v3.7.4 Remote Code Execution via PDF Annotationssiyuan9.4 (v4.0)Critical
CVE-2026-73042SiYuan before v3.7.4 Remote Code Execution via Menu Metadatasiyuan9.4 (v4.0)Critical
CVE-2026-73483Flowise before 3.1.3 Sandbox Escape via Puppeteerflowise9.4 (v4.0)Critical
CVE-2026-82244Budibase before 3.41.3 Remote Code Execution via Plugin eval()server9.4 (v4.0)Critical
CVE-2017-20251WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST APIWoody Code Snippets9.3 (v4.0)Critical
CVE-2018-25357Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.phpdolibarr erp/crm9.3 (v4.0)Critical
CVE-2019-25687Pegasus CMS 1.0 Remote Code Execution via extra_fields.phppegasus cms9.3 (v4.0)Critical
CVE-2024-58348WordPress Background Image Cropper 1.2 Remote Code ExecutionBackground Image Cropper9.3 (v4.0)Critical
CVE-2025-2611ICTBroadcast - Command InjectionICTBroadcast9.3 (v4.0)Critical
CVE-2025-31114Fooocus webui vulnerable to Remote Code ExecutionFooocus9.3 (v4.0)Critical
CVE-2026-19586Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gatewayser7212pc firmware9.3 (v4.0)Critical
CVE-2026-41939Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFlyCare Everywhere Gateway9.3 (v4.0)Critical
CVE-2026-44402Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgiSNMP Web Pro9.3 (v4.0)Critical
CVE-2026-53975OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/execOpenChamber9.3 (v4.0)Critical
CVE-2026-60121Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.phpflamingo9.3 (v4.0)Critical
CVE-2026-61498Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.phpflamingo9.3 (v4.0)Critical
CVE-2026-61511vBulletin 6.x - Remote Code ExecutionvBulletin9.3 (v4.0)Critical
CVE-2026-63766GPT-SoVITS 20250606v2pro OS Command Injection via webui.pyGPT-SoVITS9.3 (v4.0)Critical
CVE-2026-64625AVideo before 29.0 OS Command Injection via execAsyncAVideo9.3 (v4.0)Critical
CVE-2026-64824Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restoreHome Assistant Core9.3 (v4.0)Critical
CVE-2026-65008Grav before 2.0.7 Remote Code Execution via Blueprint dynamicDatagrav9.3 (v4.0)Critical
CVE-2026-67308Wazuh GitHub Actions Shell Injection via Fork Pull Requestwazuh9.3 (v4.0)Critical
CVE-2026-70553MaxSite CMS Unauthenticated RCE via Install EndpointMaxSite CMS9.3 (v4.0)Critical
CVE-2026-71921DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgiVigorSwitch G2540xs9.3 (v4.0)Critical
CVE-2026-71944D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectelDWR-M9619.3 (v4.0)Critical
CVE-2026-71945D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocomDWR-M9619.3 (v4.0)Critical
CVE-2026-71946D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRunDWR-M9619.3 (v4.0)Critical
CVE-2026-71947D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRunDWR-M9619.3 (v4.0)Critical
CVE-2026-71948D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRunDWR-M9619.3 (v4.0)Critical
CVE-2026-71949D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetupDWR-M9619.3 (v4.0)Critical
CVE-2026-71950D-Link DWR-M961 Command Injection via /boafrm/formSmsManageDWR-M9619.3 (v4.0)Critical
CVE-2026-71951D-Link DWR-M961 Command Injection via /boafrm/formIMEISetupDWR-M9619.3 (v4.0)Critical
CVE-2026-71952D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetupDWR-M9619.3 (v4.0)Critical
CVE-2026-71953D-Link DWR-M961 Command Injection via /boafrm/formNtpDWR-M9619.3 (v4.0)Critical
CVE-2026-71954D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetupDWR-M9619.3 (v4.0)Critical
CVE-2026-71955D-Link DWR-M961 Command Injection via /boafrm/formWscDWR-M9619.3 (v4.0)Critical
CVE-2026-71956D-Link DWR-M961 Command Injection via app.cgiDWR-M9619.3 (v4.0)Critical
CVE-2026-71984MSI Radix AXE6600 v781521 Command Injection via urlfilterRadix AXE66009.3 (v4.0)Critical
CVE-2026-71992MSI Radix AXE6600 v781521 Command Injection via macfilterRadix AXE66009.3 (v4.0)Critical
CVE-2026-72710SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue InjectionSPIP9.3 (v4.0)Critical
CVE-2026-76070Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password ParameterNC639.3 (v4.0)Critical
CVE-2026-76071Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost ParameterNC639.3 (v4.0)Critical
CVE-2023-7305SmartBI RMIServlet Unrestricted File Upload RCESmartBI9.2 (v4.0)Critical
CVE-2026-58455Dockwatch <= 0.6.567 - OS Command Injectiondockwatch9.2 (v4.0)Critical
CVE-2026-63304AVideo through 29.0 OS Command Injection via listFFmpegProcessesAVideo9.2 (v4.0)Critical
CVE-2026-63305AVideo through 29.0 OS Command Injection via ffmpeg.json.phpAVideo9.2 (v4.0)Critical
CVE-2026-80138ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameterclipbucket-v59.2 (v4.0)Critical
CVE-2019-13462Lansweeper Unauthenticated SQL Injectionlansweeper9.1 (v3.0)Critical
CVE-2019-9880WPEngine WPGraphQL 0.2.3 - Unauthenticated User Information Disclosurewpgraphql9.1 (v3.0)Critical
CVE-2026-40887Vendure Core - SQL Injectionvendure9.1 (v3.1)Critical
CVE-2026-46621Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injectionyamcs9.1 (v3.1)Critical
CVE-2026-55511Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs executeSqlyamcs9.1 (v3.1)Critical
CVE-2026-57499Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE)core9.1 (v3.1)Critical
CVE-2026-58400GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formattercore-geonetwork9.1 (v3.1)Critical
CVE-2026-34612Kestra: Remote Code Execution via SQL Injectionkestra9.0 (v3.1)Critical
CVE-2026-45630Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo Statementdokploy9.0 (v3.1)Critical
CVE-2026-62674Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCEomnigent9.0 (v3.1)Critical
CVE-2026-69251Flowise RCE via TypeORM DataSourceFlowise9.0 (v4.0)Critical
CVE-2026-73485Flowise before 3.1.3 Remote Code Execution via Airtable Agentflowise9.0 (v4.0)Critical
CVE-2026-73486Flowise before 3.1.3 Code Injection via CSV Agent customReadCSVflowise9.0 (v4.0)Critical
CVE-2026-73487Flowise before 3.1.3 Prompt Injection RCE via CSV Agentflowise9.0 (v4.0)Critical
CVE-2026-43945FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration InjectionFUXA8.9 (v4.0)High
CVE-2026-7202Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injectionA8000RU8.9 (v4.0)High
CVE-2026-7203Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injectionA8000RU8.9 (v4.0)High
CVE-2026-7204Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-73570zimbra collaboration suite Arbitrary Code Execution Vulnerabilityzimbra collaboration suite8.9 (v3.1)High
CVE-2026-77956EEx template evaluation of prompt content in AshAi enables remote code executionash ai8.9 (v4.0)High
CVE-2026-9384Totolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9385Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9386Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9387Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9388Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9404Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9405Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9406Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9407Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9408Totolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9432Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9433Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9434Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9435Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9436Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9454Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9455Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9456Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9457Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9458Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9475Totolink A8000RU Web Management cstecgi.cgi setIpQosRules os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9476Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9477Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9478Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injectionA8000RU8.9 (v4.0)High
CVE-2017-14535Trixbox - 2.8.0.4 OS Command Injectiontrixbox8.8 (v3.1)High
CVE-2017-6884Zyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command Injectionemg2926 firmware8.8 (v3.1)High
CVE-2018-11442EasyService Billing 1.0 - Cross-Site Request Forgeryeasyservice billing8.8 (v3.0)High
CVE-2018-11445EasyService Billing 1.0 - Cross-Site Request Forgeryeasyservice billing8.8 (v3.0)High
CVE-2019-9082ThinkPHP < 3.2.4 - Remote Code Executionthinkphp8.8 (v3.1)High
CVE-2020-10173Comtrend VR-3033 - Command Injectionvr-3033 firmware8.8 (v3.1)High
CVE-2020-15874Command Injection-8.8 (v3.1)High
CVE-2021-25646Apache Druid - Remote Code Executiondruid8.8 (v3.1)High
CVE-2022-33891Apache Spark UI - Remote Command Injectionspark8.8 (v3.1)High
CVE-2024-39024In Packetfence 13.2.0, the WebGui interface setting Arbitrary Code Execution Vulnerability-8.8 (v3.1)High
CVE-2025-59710biztalk360 Arbitrary Code Execution Vulnerabilitybiztalk3608.8 (v3.1)High
CVE-2025-68613n8n - Remote Code Execution via Expression Injectionn8n8.8 (v3.1)High
CVE-2026-24893openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansionopenitcockpit8.8 (v3.1)High
CVE-2026-26899OS Command Injection-8.8 (v3.1)High
CVE-2026-34197Apache ActiveMQ - Remote Code Executionactivemq8.8 (v3.1)High
CVE-2026-35031Jellyfin: Potential RCE via subtitle upload path traversal + .strm chainjellyfin8.8 (v3.1)High
CVE-2026-35196Chamilo LMS has OS Command Injection via export_all_certificates actionchamilo lms8.8 (v3.1)High
CVE-2026-45505Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia addNetworkConnector Discovery Wrapper Bypassactivemq8.8 (v3.1)High
CVE-2026-45578WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URLavideo8.8 (v3.1)High
CVE-2026-45662Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion)dokploy8.8 (v3.1)High
CVE-2026-48017DbGate: Remote Code Execution via functionName injection in loadReader endpointdbgate8.8 (v3.1)High
CVE-2026-55585QWED: Authenticated Remote Code Execution via Unsafe SymPy parse_expr()qwed-verification8.8 (v3.1)High
CVE-2026-58195Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into exagentic-flow8.8 (v3.1)High
CVE-2026-62675Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Toolsomnigent8.8 (v3.1)High
CVE-2026-72875Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFiledokploy8.8 (v3.1)High
CVE-2026-73222Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (–studio)claude-code-templates8.8 (v3.1)High
CVE-2026-78834Code Injection-8.8 (v3.1)High
CVE-2026-79423seacms v13.6 Arbitrary Code Execution Vulnerabilityseacms v13.68.8 (v3.1)High
CVE-2026-82217Eclipse Theia Path Traversal VulnerabilityEclipse Theia8.8 (v3.1)High
CVE-2019-25671VA MAX 8.3.4 Remote Code Execution via changeip.phpVA MAX8.7 (v4.0)High
CVE-2021-47938ImpressCMS 1.4.2 Remote Code Execution via AutotasksImpressCMS8.7 (v4.0)High
CVE-2021-47939Evolution CMS 3.1.6 Authenticated Remote Code Execution via Module CreationEvolution CMS8.7 (v4.0)High
CVE-2021-47943TextPattern CMS 4.8.7 Remote Code Execution via File UploadTextPattern CMS8.7 (v4.0)High
CVE-2022-50944Aero CMS 0.0.1 PHP Code Injection via posts.phpAero CMS8.7 (v4.0)High
CVE-2023-54350WordPress Augmented-Reality Plugin Remote Code Execution UnauthenticatedAugmented Reality8.7 (v4.0)High
CVE-2025-30007HestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record Managementcontrol panel8.7 (v4.0)High
CVE-2025-34115OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.phpOP5 Monitor8.7 (v4.0)High
CVE-2026-28797RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Componeragflow8.7 (v4.0)High
CVE-2026-34228Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Writeemlog8.7 (v4.0)High
CVE-2026-34735Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileControllerwiki8.7 (v4.0)High
CVE-2026-34792Endian Firewall /cgi-bin/logs_clamav.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34793Endian Firewall /cgi-bin/logs_firewall.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34794Endian Firewall /cgi-bin/logs_ids.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34795Endian Firewall /cgi-bin/logs_log.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34796Endian Firewall /cgi-bin/logs_openvpn.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34797Endian Firewall /cgi-bin/logs_smtp.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-46746sinec ins OS Command Injection Vulnerabilitysinec ins8.7 (v4.0)High
CVE-2026-49143BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handlerbrowserstack-runner8.7 (v4.0)High
CVE-2026-63722ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.phpICEcoder8.7 (v4.0)High
CVE-2026-64837ICEcoder through 8.1 OS Command Injection via lib/properties.phpICEcoder8.7 (v4.0)High
CVE-2026-64850Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()grav8.7 (v4.0)High
CVE-2026-67206Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Uploadwolfcms8.7 (v4.0)High
CVE-2026-69096OpenWrt luci-app-dockerman Read ACL Remote Code Executionluci8.7 (v4.0)High
CVE-2026-69100LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Executionlamp-cloud8.7 (v4.0)High
CVE-2026-71966CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfercyberpanel8.7 (v4.0)High
CVE-2026-72819Grav CMS before 2.0.13 Remote Code Execution via ZIP Uploadgrav8.7 (v4.0)High
CVE-2026-72827Grav CMS before 2.0.13 Remote Code Execution via Twiggrav8.7 (v4.0)High
CVE-2026-72830Grav API Plugin before 1.0.13 RCE via ConfigController scope bypassgrav8.7 (v4.0)High
CVE-2026-72870Dokploy: Command Injection via Docker Credentials in buildRemoteDockerdokploy8.7 (v4.0)High
CVE-2026-72874Dokploy: Command Injection via Unescaped Git URL in Clone Commandsdokploy8.7 (v4.0)High
CVE-2026-73680Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg FilenameCockpit CMS8.7 (v4.0)High
CVE-2026-75574Grav before 4.2.2 Remote Code Execution via Email Twiggrav8.7 (v4.0)High
CVE-2026-76060OS Command Injection in PayRange APIZoneminder8.7 (v4.0)High
CVE-2026-76836AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group BypassAzuraCast8.7 (v4.0)High
CVE-2026-78416Authenticated RCE via condition.config JSON cleanse bypasscms8.7 (v4.0)High
CVE-2026-79756Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platformnuclio8.7 (v4.0)High
CVE-2026-79987Low-privilege RCE through element-search eager loadingcms8.7 (v4.0)High
CVE-2026-82278BISHENG Authenticated Arbitrary Python Code Execution via Workflow run_oncebisheng8.7 (v4.0)High
CVE-2026-85604Grav before 2.0.19 Remote Code Execution via sort filtergrav8.7 (v4.0)High
CVE-2026-85610OpenPanel before 2.3.0 Remote Code Execution via chart formulasopenpanel8.7 (v4.0)High
CVE-2026-86732Craft CMS before 5.10.12 Remote Code Execution via element-indexcms8.7 (v4.0)High
CVE-2024-20353adaptive security appliance software Denial of Service Vulnerabilityadaptive security appliance software8.6 (v3.1)High
CVE-2026-40187Authenticated RCE via Malicious eTemplate Upload in EGroupwareegroupware8.6 (v4.0)High
CVE-2026-42785OpenKM 6.3.12 Remote Code Execution via Administrative ScriptingOpenKM Community Edition8.6 (v4.0)High
CVE-2026-53804OTRS Community Edition OS Command Injection via PGP ConfigurationOTRS Community Edition8.6 (v4.0)High
CVE-2026-55182LibreNMS: Remote Code Execution by Signal Alert Transportation Modulelibrenms8.6 (v4.0)High
CVE-2026-56703Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTOadminer8.6 (v4.0)High
CVE-2026-61517Netis NX10 OS Command Injection via Ping Diagnostic HandlerNX108.6 (v4.0)High
CVE-2026-61523WebsiteBaker CMS < 2.13.10 Code Injection via Droplets EditorWebsiteBaker CMS8.6 (v4.0)High
CVE-2026-63725sysPass FileBackupService Authenticated OS Command Injection via Backup PathsysPass8.6 (v4.0)High
CVE-2026-65693Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templatesmicroweber8.6 (v4.0)High
CVE-2026-65711sysPass 3.2.11 Authenticated OS Command Injection via Backup PathsysPass8.6 (v4.0)High
CVE-2026-67599ClearOS 7.9 OS Command Injection via Log Viewer filter parameterClearOS8.6 (v4.0)High
CVE-2026-67608Telenia TVox 26.5.3 OS Command Injection via action_audio.phpTVox8.6 (v4.0)High
CVE-2026-69088Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprintgrav8.6 (v4.0)High
CVE-2026-71906DrayTek VigorAP Multiple Models OS Command Injection via setLanVigorAP 918R8.6 (v4.0)High
CVE-2026-71907DrayTek VigorAP Multiple Models OS Command Injection via setcamsetVigorAP 918R8.6 (v4.0)High
CVE-2026-71908DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_testVigorAP 918R8.6 (v4.0)High
CVE-2026-71913DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgiVigorAP 918R8.6 (v4.0)High
CVE-2026-71915DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatusVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71918DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupActionVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71919DrayTek VigorSwitch Multiple Models OS Command Injection via sysrebootVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71923DrayTek VigorSwitch Multiple Models OS Command Injection via auth_setVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71924DrayTek VigorSwitch Multiple Models OS Command Injection via getVidVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71925DrayTek VigorSwitch Multiple Models OS Command Injection via getDetailVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71926DrayTek VigorSwitch Multiple Models OS Command Injection via setDeviceVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71927DrayTek VigorSwitch Multiple Models OS Command Injection via rebDeviceVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71928DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDeviceVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71929DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProtoVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71930DrayTek VigorSwitch Multiple Models OS Command Injection via setTimeVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71931DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgradeVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71943DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNetVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-73664FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Modulebackup8.6 (v4.0)High
CVE-2026-75121PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_postPLANET GS-4210-16P2S V38.6 (v4.0)High
CVE-2026-75122PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgiPLANET GS-4210-16P2S V38.6 (v4.0)High
CVE-2026-75123PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_postPLANET GS-4210-16P2S V38.6 (v4.0)High
CVE-2026-80214LibreNMS Virtualisation Discovery Module RCElibrenms8.6 (v4.0)High
CVE-2026-82692D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injectionDNS-340L8.6 (v4.0)High
CVE-2026-84194LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostnamelibrenms8.6 (v4.0)High
CVE-2026-85223D-Link DNS-340L CGI dropbox.cgi os command injectionDNS-340L8.6 (v4.0)High
CVE-2026-86299Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injectionRE70008.6 (v4.0)High
CVE-2026-86437Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Uploadlaradashboard8.6 (v4.0)High
CVE-2026-86438Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Actionlaradashboard8.6 (v4.0)High
CVE-2026-86733Snipe-IT before 8.7.0 Remote Code Execution via Backup Restoresnipe-it8.6 (v4.0)High
CVE-2026-22244OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCEopenmetadata8.5 (v4.0)High
CVE-2026-82690D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injectionDNS-327L8.5 (v4.0)High
CVE-2026-82691D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injectionDNS-320L8.5 (v4.0)High
CVE-2026-85222D-Link DNS-340L Add-On Center addon_center.cgi os command injectionDNS-340L8.5 (v4.0)High
CVE-2026-85224D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injectionDNS-320 ShareCenter8.5 (v4.0)High
CVE-2025-59711biztalk360 Path Traversal Vulnerabilitybiztalk3608.3 (v3.1)High
CVE-2026-49471Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCEserena8.3 (v3.1)High
CVE-2025-69755Neterbit NW-431F Router vNW-431F-20241014-IR03 Arbitrary Code Execution Vulnerability-8.2 (v3.1)High
CVE-2026-42588Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnectoractivemq8.1 (v3.1)High
CVE-2026-45344LinkAce: Setup database password newline injection enables pre-auth RCE on uninitialized instancesLinkAce8.1 (v3.1)High
CVE-2026-47398PraisonAI: Arbitrary code execution via unguarded spec.loader.exec_module in agents_generator.py - sibling of CVE-20PraisonAI8.1 (v3.1)High
CVE-2026-48695fastnetmon Command Injection Vulnerabilityfastnetmon8.1 (v3.1)High
CVE-2026-71320Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Propsnuxt8.1 (v3.1)High
CVE-2025-6204DELMIA Apriso - Command Injectiondelmia apriso8.0 (v3.1)High
CVE-2026-52831Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCEnuclio8.0 (v3.1)High
CVE-2026-79755Nuclio: Unauthenticated OS command injection via function namespace in docker ps –filter label (local Docker platform)nuclio8.0 (v3.1)High
CVE-2015-4669Xceedium Xsuite - Multiple Vulnerabilitiesxsuite7.8 (v3.0)High
CVE-2019-20499D-Link DWL-2600AP - Multiple OS Command Injectiondwl-2600ap firmware7.8 (v3.1)High
CVE-2019-20500D-Link DWL-2600AP - Multiple OS Command Injectiondwl-2600ap firmware7.8 (v3.1)High
CVE-2019-20501D-Link DWL-2600AP - Multiple OS Command Injectiondwl-2600ap firmware7.8 (v3.1)High
CVE-2026-67179Genkit improper host header validationgenkit7.8 (v3.1)High
CVE-2025-27621UpTrain has a Constant Default API Keyuptrain7.7 (v4.0)High
CVE-2026-40519Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()nginx-proxy-manager7.7 (v4.0)High
CVE-2026-66738SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLiteSPIP7.7 (v4.0)High
CVE-2011-4448WikkaWiki 1.3.2 - Multiple Vulnerabilitieswikkawiki7.5 (v2.0)High
CVE-2013-6041Webuzo 2.1.3 - Multiple Vulnerabilitieswebuzo7.5 (v2.0)High
CVE-2015-2080Inductive Automation Ignition 7.8.1 - Remote Leakage Of Shared Buffersfedora7.5 (v3.0)High
CVE-2015-2824WordPress Plugin Simple Ads Manager - Multiple SQL Injectionssimple ads manager7.5 (v2.0)High
CVE-2026-34239Chamilo Authenticated Remote Code Executionchamilo-lms7.5 (v4.0)High
CVE-2026-36783Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to Denial of Service Vulnerability-7.5 (v3.1)High
CVE-2026-36796Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to Denial of Service Vulnerability-7.5 (v3.1)High
CVE-2026-46581mojarra Path Traversal Vulnerabilitymojarra7.5 (v3.1)High
CVE-2026-51078Dede CMS v.5.7.118 Information Disclosure Vulnerability-7.5 (v3.1)High
CVE-2026-53599Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mocore7.5 (v3.1)High
CVE-2026-10870Shibby Tomato Web UI rc start_dhcpc os command injectionTomato7.3 (v4.0)High
CVE-2026-10871Shibby Tomato Web UI rc start_6rd_tunnel os command injectionTomato7.3 (v4.0)High
CVE-2026-10873Shibby Tomato Web UI rstats rstats_path os command injectionTomato7.3 (v4.0)High
CVE-2026-18900H3C NX15 Backend RPC esps file.exec os command injectionNX157.3 (v4.0)High
CVE-2026-19771Baicells EG3661M LuCI Web luci os command injectionEG3661M7.3 (v4.0)High
CVE-2019-18396Technicolor TD5130.2 - Remote Command Executiontd5130v2 firmware7.2 (v3.1)High
CVE-2026-13392ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite)ElementsKit Elementor Addons7.2 (v3.1)High
CVE-2026-15686Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution VulnerabilityAdminer7.2 (v3.0)High
CVE-2026-27891Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanismfacturascripts7.2 (v3.1)High
CVE-2026-71284Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filenamefledge7.2 (v3.1)High
CVE-2026-71964CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Uploadcyberpanel7.1 (v4.0)High
CVE-2026-77939Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpointflextype7.1 (v4.0)High
CVE-2026-11450GL.iNet GL-MT3000 Path Normalization dlopen command injectionGL-MT30006.9 (v4.0)Medium
CVE-2026-19983GL.iNet XE3000 NAS Command Service gl_nas_sys os command injectionA13006.9 (v4.0)Medium
CVE-2026-5739PowerJob OpenAPI Endpoint addWorkflowNode GroovyEvaluator.evaluate code injectionPowerJob6.9 (v4.0)Medium
CVE-2011-4449WikkaWiki 1.3.2 - Multiple Vulnerabilitieswikkawiki6.8 (v2.0)Medium
CVE-2011-4452WikkaWiki 1.3.2 - Multiple Vulnerabilitieswikkawiki6.8 (v2.0)Medium
CVE-2025-59709biztalk360 Path Traversal Vulnerabilitybiztalk3606.8 (v3.1)Medium
CVE-2026-10821Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCEYoast SEO Premium6.6 (v3.1)Medium
CVE-2026-34216CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in SettingsController.phppanel6.6 (v3.1)Medium
CVE-2026-72739Dokploy: Command Injection via Compose Shell Executiondokploy6.5 (v3.1)Medium
CVE-2011-4450WikkaWiki 1.3.2 - Multiple Vulnerabilitieswikkawiki6.4 (v2.0)Medium
CVE-2024-32231Stash < 0.26.0 - SQL Injectionstash6.3 (v3.1)Medium
CVE-2026-44287FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*(/ is bypassableFastGPT6.3 (v3.1)Medium
CVE-2026-45626Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameterarcane6.3 (v3.1)Medium
CVE-2015-4668Xceedium Xsuite - Multiple Vulnerabilitiesxsuite6.1 (v3.0)Medium
CVE-2018-7192osTicket < 1.10.2 - Cross-Site Scriptingosticket6.1 (v3.0)Medium
CVE-2019-7438JioFi 4G M2S 1.0.2 - 'mask' Cross-Site Scriptingjiofi 4g m2s firmware6.1 (v3.0)Medium
CVE-2022-0879Caldera Forms < 1.9.7 - Reflected Cross-Site Scriptingcaldera forms6.1 (v3.1)Medium
CVE-2024-30194Sunshine Photo Cart <= 3.1.1 - Reflected Cross-Site Scriptingsunshine photo cart6.1 (v3.1)Medium
CVE-2024-43971Sunshine Photo Cart <= 3.2.5 - Reflected Cross-Site Scriptingsunshine photo cart6.1 (v3.1)Medium
CVE-2025-13786taosir WTCMS index.php fetch code injectionwtcms5.5 (v4.0)Medium
CVE-2025-13792Qualitor getResumo.php eval code injectionthe file /html/st/stdeslocamento/request/getResumo.php5.5 (v4.0)Medium
CVE-2026-10214zhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injectionchatgpt-on-wechat5.5 (v4.0)Medium
CVE-2026-18641Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginCOperation and Maintenance Security Management System5.5 (v4.0)Medium
CVE-2026-19379EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injectionipTIME AX8004M5.5 (v4.0)Medium
CVE-2026-54611InstantCMS has Remote Code Execution in package installericms25.5 (v3.1)Medium
CVE-2026-5631assafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injectiongpt-researcher5.5 (v4.0)Medium
CVE-2026-5677Totolink A7100RU cstecgi.cgi CsteSystem os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5678Totolink A7100RU cstecgi.cgi setScheduleCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5688Totolink A7100RU cstecgi.cgi setDdnsCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5689Totolink A7100RU cstecgi.cgi setNtpCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5690Totolink A7100RU cstecgi.cgi setRemoteCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5691Totolink A7100RU cstecgi.cgi setFirewallType os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5692Totolink A7100RU cstecgi.cgi setGameSpeedCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5736PowerJob detailPlus Endpoint InstanceController.java sql injectionPowerJob5.5 (v4.0)Medium
CVE-2026-5741suvarchal docker-mcp-server HTTP index.ts pull_image os command injectiondocker-mcp-server5.5 (v4.0)Medium
CVE-2026-5802idachev mcp-javadc HTTP os command injectionmcp-javadc5.5 (v4.0)Medium
CVE-2026-7220jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injectionFastlyMCP5.5 (v4.0)Medium
CVE-2026-76760chenhg5 cc-connect webhook.go authenticate code injectioncc-connect5.5 (v4.0)Medium
CVE-2026-76761chenhg5 cc-connect Management API engine.go shellExecCommand os command injectioncc-connect5.5 (v4.0)Medium
CVE-2026-82598SeaCMS Template search.php parseIf code injectionSeaCMS5.5 (v4.0)Medium
CVE-2026-85137SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injectionSeaCMS5.5 (v4.0)Medium
CVE-2026-9474yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injectionStudentManagementSystem5.5 (v4.0)Medium
CVE-2026-54543Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fieldsfroxlor5.4 (v3.1)Medium
CVE-2021-4191GitLab GraphQL API User Enumerationgitlab5.3 (v3.1)Medium
CVE-2023-7299DataGear resolveSql sql injectiondatagear5.3 (v4.0)Medium
CVE-2026-19785francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injectionRosarioSIS5.3 (v4.0)Medium
CVE-2026-5547Tenda AC10 httpd formAddMacfilterRule os command injectionac10 firmware5.3 (v4.0)Medium
CVE-2013-6043Webuzo 2.1.3 - Multiple Vulnerabilitieswebuzo5.0 (v2.0)Medium
CVE-2015-4666Xceedium Xsuite - Multiple Vulnerabilitiesxsuite5.0 (v2.0)Medium
CVE-2011-4451WikkaWiki 1.3.2 - Multiple Vulnerabilitieswikkawiki4.3 (v2.0)Medium
CVE-2013-6042Webuzo 2.1.3 - Multiple Vulnerabilitieswebuzo4.3 (v2.0)Medium
CVE-2015-4665Xceedium Xsuite - Multiple Vulnerabilitiesxsuite4.3 (v2.0)Medium
CVE-2026-36239PbootCMS v.3.2.11 Cross-site Scripting VulnerabilityPbootCMS v.3.2.114.3 (v3.1)Medium
CVE-2026-10172Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted uploadMulti-Store Inventory Management System2.1 (v4.0)Low
CVE-2026-10279hiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injectionwezterm-mcp2.1 (v4.0)Low
CVE-2026-11408vertex-app vertex Log Viewer Endpoint LogMod.js os command injectionvertex2.1 (v4.0)Low
CVE-2026-19932DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.evaluate code injectionNotice-System-Managent2.1 (v4.0)Low
CVE-2026-19958iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injectionpptr-mcp2.1 (v4.0)Low
CVE-2026-5351Trendnet TEW-657BRM setup.cgi add_wps_client os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5352Trendnet TEW-657BRM setup.cgi edit os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5353Trendnet TEW-657BRM setup.cgi ping_test os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5354Trendnet TEW-657BRM setup.cgi vpn_connect os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5355Trendnet TEW-657BRM setup.cgi vpn_drop os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-78166provectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest code injectionkafka-ui2.1 (v4.0)Low
CVE-2026-8188Wavlink NU516U1 adm.cgi change_wifi_password os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8189Wavlink NU516U1 adm.cgi wzdrepeater os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8190Wavlink NU516U1 adm.cgi wan os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8191Wavlink NU516U1 adm.cgi wifi_region os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8192Wavlink NU516U1 adm.cgi wzdap os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8227Wavlink NU516U1 adm.cgi wzdapMesh os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8228Wavlink NU516U1 wireless.cgi advance os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8229Wavlink NU516U1 wireless.cgi WifiBasic os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8230Wavlink NU516U1 login.cgi sys_login1 os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8264Tenda AC6 httpd WifiApScan formWifiApScan os command injectionac6 firmware2.1 (v4.0)Low
CVE-2026-9302546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injectionvps-inventory-monitoring2.1 (v4.0)Low
CVE-2026-9343Edimax EW-7438RPn webs formWpsStart os command injectionEW-7438RPn2.1 (v4.0)Low
CVE-2026-9347Edimax EW-7438RPn webs formWizSurvey os command injectionEW-7438RPn2.1 (v4.0)Low
CVE-2026-9424Edimax EW-7438RPn Content-Type formWlanMP os command injectionEW-7438RPn2.1 (v4.0)Low
CVE-2026-9511Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9512Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9514Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9515Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9531Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9532Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9533Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9534Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-19964Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injectionJij-MCP-Server2.0 (v4.0)Low
CVE-2026-78140Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engineUJCMS2.0 (v4.0)Low
CVE-2026-8259Tenda AC6 httpd telnet os command injectionac6 firmware2.0 (v4.0)Low
CVE-2026-8265Tenda AC6 httpd getLogFile get_log_file os command injectionac6 firmware2.0 (v4.0)Low
CVE-2026-82678diem-project diem Administrative Console actions.class.php executeCommand os command injectiondiem2.0 (v4.0)Low
CVE-2026-82702Edimax BR-6214K asp_WlanMP Endpoint wlanMP.asp system os command injectionBR-6214K2.0 (v4.0)Low
CVE-2026-82703Edimax BR-6214K asp_setPing Endpoint ping.asp system os command injectionBR-6214K2.0 (v4.0)Low
CVE-2026-85040ZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injectionCRMEB2.0 (v4.0)Low
CVE-2026-16129princezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklistSafestClaw1.9 (v4.0)Low
CVE-2026-5621ChrisChinchilla Vale-MCP HTTP index.ts os command injectionVale-MCP1.9 (v4.0)Low
CVE-2026-19353DedeCMS Installation Wizard index.php _4_Setup file inclusionDedeCMS1.3 (v4.0)Low

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-20CVE-2026-47668 , CVE-2015-4664 , CVE-2018-11686 , CVE-2023-3710 , CVE-2026-35048 , CVE-2026-57499 , CVE-2026-24893 , CVE-2026-34197 , CVE-2026-35031 , CVE-2026-45505 , CVE-2025-34115 , CVE-2026-28797 , CVE-2026-42588 , CVE-2026-27891
CWE-22CVE-2023-26802 , CVE-2019-25687 , CVE-2026-64824 , CVE-2026-35031 , CVE-2026-82217 , CVE-2019-25671 , CVE-2025-59711 , CVE-2026-46581 , CVE-2025-59709 , CVE-2011-4450 , CVE-2015-4666
CWE-59CVE-2026-71964
CWE-73CVE-2026-19353
CWE-74CVE-2013-2251 , CVE-2026-45344 , CVE-2026-71320 , CVE-2026-11450 , CVE-2026-5739 , CVE-2026-10821 , CVE-2025-13786 , CVE-2025-13792 , CVE-2026-5631 , CVE-2026-5736 , CVE-2026-76760 , CVE-2026-82598 , CVE-2026-85137 , CVE-2026-9474 , CVE-2026-54543 , CVE-2023-7299 , CVE-2026-19785 , CVE-2026-19932 , CVE-2026-19958 , CVE-2026-78166 , CVE-2026-9302 , CVE-2026-19964
CWE-77CVE-2026-72869 , CVE-2014-1203 , CVE-2023-23333 , CVE-2023-34960 , CVE-2023-3710 , CVE-2023-45852 , CVE-2026-34243 , CVE-2026-35847 , CVE-2026-8037 , CVE-2026-47670 , CVE-2026-7202 , CVE-2026-7203 , CVE-2026-7204 , CVE-2026-9384 , CVE-2026-9385 , CVE-2026-9386 , CVE-2026-9387 , CVE-2026-9388 , CVE-2026-9404 , CVE-2026-9405 , CVE-2026-9406 , CVE-2026-9407 , CVE-2026-9408 , CVE-2026-9432 , CVE-2026-9433 , CVE-2026-9434 , CVE-2026-9435 , CVE-2026-9436 , CVE-2026-9454 , CVE-2026-9455 , CVE-2026-9456 , CVE-2026-9457 , CVE-2026-9458 , CVE-2026-9475 , CVE-2026-9476 , CVE-2026-9477 , CVE-2026-9478 , CVE-2020-15874 , CVE-2026-55182 , CVE-2026-82692 , CVE-2026-85223 , CVE-2026-86299 , CVE-2026-82690 , CVE-2026-82691 , CVE-2026-85222 , CVE-2026-85224 , CVE-2026-10870 , CVE-2026-10871 , CVE-2026-10873 , CVE-2026-18900 , CVE-2026-19771 , CVE-2026-11450 , CVE-2026-19983 , CVE-2026-10214 , CVE-2026-18641 , CVE-2026-19379 , CVE-2026-5677 , CVE-2026-5678 , CVE-2026-5688 , CVE-2026-5689 , CVE-2026-5690 , CVE-2026-5691 , CVE-2026-5692 , CVE-2026-5741 , CVE-2026-5802 , CVE-2026-7220 , CVE-2026-76761 , CVE-2026-5547 , CVE-2026-10279 , CVE-2026-11408 , CVE-2026-5351 , CVE-2026-5352 , CVE-2026-5353 , CVE-2026-5354 , CVE-2026-5355 , CVE-2026-8188 , CVE-2026-8189 , CVE-2026-8190 , CVE-2026-8191 , CVE-2026-8192 , CVE-2026-8227 , CVE-2026-8228 , CVE-2026-8229 , CVE-2026-8230 , CVE-2026-8264 , CVE-2026-9343 , CVE-2026-9347 , CVE-2026-9424 , CVE-2026-9511 , CVE-2026-9512 , CVE-2026-9514 , CVE-2026-9515 , CVE-2026-9531 , CVE-2026-9532 , CVE-2026-9533 , CVE-2026-9534 , CVE-2026-8259 , CVE-2026-8265 , CVE-2026-82678 , CVE-2026-82702 , CVE-2026-82703 , CVE-2026-85040 , CVE-2026-5621
CWE-78CVE-2025-34037 , CVE-2026-19188 , CVE-2026-34234 , CVE-2026-49869 , CVE-2026-8985 , CVE-2026-42454 , CVE-2026-45629 , CVE-2026-45632 , CVE-2026-48030 , CVE-2026-63298 , CVE-2026-72738 , CVE-2026-72740 , CVE-2026-72865 , CVE-2026-72868 , CVE-2026-72869 , CVE-2026-72872 , CVE-2026-72876 , CVE-2026-72882 , CVE-2026-72902 , CVE-2026-73263 , CVE-2026-73294 , CVE-2019-12725 , CVE-2019-15107 , CVE-2019-16662 , CVE-2019-16920 , CVE-2019-7256 , CVE-2020-15920 , CVE-2020-28429 , CVE-2020-29390 , CVE-2020-9054 , CVE-2022-25082 , CVE-2022-29303 , CVE-2022-31137 , CVE-2024-53584 , CVE-2026-12940 , CVE-2026-18482 , CVE-2026-34243 , CVE-2026-37281 , CVE-2026-45018 , CVE-2026-48687 , CVE-2026-49819 , CVE-2026-53545 , CVE-2026-79408 , CVE-2026-35906 , CVE-2026-72878 , CVE-2026-8986 , CVE-2026-47670 , CVE-2026-63732 , CVE-2026-72879 , CVE-2026-73483 , CVE-2025-2611 , CVE-2026-19586 , CVE-2026-53975 , CVE-2026-60121 , CVE-2026-61498 , CVE-2026-63766 , CVE-2026-64625 , CVE-2026-67308 , CVE-2026-71921 , CVE-2026-71944 , CVE-2026-71945 , CVE-2026-71946 , CVE-2026-71947 , CVE-2026-71948 , CVE-2026-71949 , CVE-2026-71950 , CVE-2026-71951 , CVE-2026-71952 , CVE-2026-71953 , CVE-2026-71954 , CVE-2026-71955 , CVE-2026-71956 , CVE-2026-71984 , CVE-2026-71992 , CVE-2026-58455 , CVE-2026-63304 , CVE-2026-63305 , CVE-2026-80138 , CVE-2026-57499 , CVE-2026-45630 , CVE-2026-7202 , CVE-2026-7203 , CVE-2026-7204 , CVE-2026-73570 , CVE-2026-9384 , CVE-2026-9385 , CVE-2026-9386 , CVE-2026-9387 , CVE-2026-9388 , CVE-2026-9404 , CVE-2026-9405 , CVE-2026-9406 , CVE-2026-9407 , CVE-2026-9408 , CVE-2026-9432 , CVE-2026-9433 , CVE-2026-9434 , CVE-2026-9435 , CVE-2026-9436 , CVE-2026-9454 , CVE-2026-9455 , CVE-2026-9456 , CVE-2026-9457 , CVE-2026-9458 , CVE-2026-9475 , CVE-2026-9476 , CVE-2026-9477 , CVE-2026-9478 , CVE-2017-14535 , CVE-2017-6884 , CVE-2020-10173 , CVE-2022-33891 , CVE-2026-24893 , CVE-2026-26899 , CVE-2026-34197 , CVE-2026-35196 , CVE-2026-45578 , CVE-2026-45662 , CVE-2026-58195 , CVE-2026-72875 , CVE-2026-73222 , CVE-2026-79423 , CVE-2025-30007 , CVE-2025-34115 , CVE-2026-28797 , CVE-2026-34792 , CVE-2026-34793 , CVE-2026-34794 , CVE-2026-34795 , CVE-2026-34796 , CVE-2026-34797 , CVE-2026-46746 , CVE-2026-64837 , CVE-2026-69096 , CVE-2026-71966 , CVE-2026-72870 , CVE-2026-72874 , CVE-2026-73680 , CVE-2026-76060 , CVE-2026-79756 , CVE-2026-40187 , CVE-2026-53804 , CVE-2026-61517 , CVE-2026-63725 , CVE-2026-65711 , CVE-2026-67599 , CVE-2026-67608 , CVE-2026-71906 , CVE-2026-71907 , CVE-2026-71908 , CVE-2026-71913 , CVE-2026-71915 , CVE-2026-71918 , CVE-2026-71919 , CVE-2026-71923 , CVE-2026-71924 , CVE-2026-71925 , CVE-2026-71926 , CVE-2026-71927 , CVE-2026-71928 , CVE-2026-71929 , CVE-2026-71930 , CVE-2026-71931 , CVE-2026-71943 , CVE-2026-75121 , CVE-2026-75122 , CVE-2026-75123 , CVE-2026-80214 , CVE-2026-82692 , CVE-2026-84194 , CVE-2026-85223 , CVE-2026-86299 , CVE-2026-86733 , CVE-2026-82690 , CVE-2026-82691 , CVE-2026-85222 , CVE-2026-85224 , CVE-2025-69755 , CVE-2026-48695 , CVE-2026-52831 , CVE-2026-79755 , CVE-2019-20499 , CVE-2019-20500 , CVE-2019-20501 , CVE-2026-40519 , CVE-2013-6041 , CVE-2026-10870 , CVE-2026-10871 , CVE-2026-10873 , CVE-2026-18900 , CVE-2026-19771 , CVE-2019-18396 , CVE-2026-71284 , CVE-2026-19983 , CVE-2026-72739 , CVE-2026-45626 , CVE-2026-10214 , CVE-2026-18641 , CVE-2026-19379 , CVE-2026-5677 , CVE-2026-5678 , CVE-2026-5688 , CVE-2026-5689 , CVE-2026-5690 , CVE-2026-5691 , CVE-2026-5692 , CVE-2026-5741 , CVE-2026-5802 , CVE-2026-7220 , CVE-2026-76761 , CVE-2026-5547 , CVE-2026-10279 , CVE-2026-11408 , CVE-2026-5351 , CVE-2026-5352 , CVE-2026-5353 , CVE-2026-5354 , CVE-2026-5355 , CVE-2026-8188 , CVE-2026-8189 , CVE-2026-8190 , CVE-2026-8191 , CVE-2026-8192 , CVE-2026-8227 , CVE-2026-8228 , CVE-2026-8229 , CVE-2026-8230 , CVE-2026-8264 , CVE-2026-9343 , CVE-2026-9347 , CVE-2026-9424 , CVE-2026-9511 , CVE-2026-9512 , CVE-2026-9514 , CVE-2026-9515 , CVE-2026-9531 , CVE-2026-9532 , CVE-2026-9533 , CVE-2026-9534 , CVE-2026-8259 , CVE-2026-8265 , CVE-2026-82678 , CVE-2026-82702 , CVE-2026-82703 , CVE-2026-85040 , CVE-2026-5621
CWE-79CVE-2026-73041 , CVE-2026-73042 , CVE-2024-39024 , CVE-2018-7192 , CVE-2019-7438 , CVE-2022-0879 , CVE-2024-30194 , CVE-2024-43971 , CVE-2013-6042 , CVE-2015-4665 , CVE-2026-36239
CWE-88CVE-2026-44450 , CVE-2026-73294 , CVE-2020-21224
CWE-89CVE-2026-55634 , CVE-2018-18755 , CVE-2021-24915 , CVE-2022-0332 , CVE-2026-38428 , CVE-2026-33324 , CVE-2019-13462 , CVE-2026-40887 , CVE-2026-34612 , CVE-2015-4669 , CVE-2011-4448 , CVE-2015-2824 , CVE-2024-32231 , CVE-2026-5736 , CVE-2026-9474 , CVE-2023-7299 , CVE-2026-19785
CWE-93CVE-2026-84372
CWE-94CVE-2026-47668 , CVE-2026-8984 , CVE-2026-55565 , CVE-2026-55634 , CVE-2026-8481 , CVE-2018-17173 , CVE-2022-1609 , CVE-2022-22954 , CVE-2022-3236 , CVE-2026-31040 , CVE-2026-38431 , CVE-2026-46562 , CVE-2026-55559 , CVE-2026-67919 , CVE-2026-75411 , CVE-2026-75414 , CVE-2026-70477 , CVE-2026-88062 , CVE-2025-62593 , CVE-2026-45272 , CVE-2026-69256 , CVE-2026-82244 , CVE-2017-20251 , CVE-2018-25357 , CVE-2026-65008 , CVE-2026-70553 , CVE-2026-46621 , CVE-2026-55511 , CVE-2026-58400 , CVE-2026-62674 , CVE-2026-69251 , CVE-2026-73485 , CVE-2026-73486 , CVE-2026-73487 , CVE-2026-43945 , CVE-2026-77956 , CVE-2019-9082 , CVE-2026-34197 , CVE-2026-45505 , CVE-2026-48017 , CVE-2026-55585 , CVE-2026-62675 , CVE-2026-78834 , CVE-2021-47938 , CVE-2021-47939 , CVE-2022-50944 , CVE-2026-28797 , CVE-2026-49143 , CVE-2026-64850 , CVE-2026-69100 , CVE-2026-72819 , CVE-2026-76836 , CVE-2026-82278 , CVE-2026-85604 , CVE-2026-85610 , CVE-2026-86732 , CVE-2026-42785 , CVE-2026-56703 , CVE-2026-61523 , CVE-2026-65693 , CVE-2026-69088 , CVE-2026-22244 , CVE-2026-42588 , CVE-2026-47398 , CVE-2026-71320 , CVE-2025-6204 , CVE-2026-66738 , CVE-2026-46581 , CVE-2026-13392 , CVE-2026-77939 , CVE-2026-5739 , CVE-2026-44287 , CVE-2025-13786 , CVE-2025-13792 , CVE-2026-54611 , CVE-2026-5631 , CVE-2026-76760 , CVE-2026-82598 , CVE-2026-85137 , CVE-2026-19932 , CVE-2026-19958 , CVE-2026-78166 , CVE-2026-9302 , CVE-2026-19964
CWE-95CVE-2026-46562 , CVE-2026-47391 , CVE-2026-39932 , CVE-2025-31114 , CVE-2026-61511 , CVE-2026-40187
CWE-120CVE-2026-36796
CWE-121CVE-2026-76070 , CVE-2026-76071 , CVE-2026-36783
CWE-183CVE-2026-16129
CWE-184CVE-2026-49869 , CVE-2026-44287 , CVE-2026-16129
CWE-187CVE-2026-35031
CWE-200CVE-2025-69755 , CVE-2015-2080 , CVE-2026-51078 , CVE-2013-6043
CWE-253CVE-2026-15686
CWE-269CVE-2026-45632 , CVE-2026-49819 , CVE-2026-72830 , CVE-2026-73664
CWE-284CVE-2026-34234 , CVE-2019-2729 , CVE-2026-43945 , CVE-2026-73664 , CVE-2026-10172
CWE-285CVE-2026-34239
CWE-287CVE-2026-49869 , CVE-2018-17431 , CVE-2025-27621
CWE-288CVE-2026-43945
CWE-306CVE-2026-81735 , CVE-2022-1388 , CVE-2026-47391 , CVE-2026-49819 , CVE-2026-53649 , CVE-2026-88062 , CVE-2019-9880 , CVE-2019-9082 , CVE-2026-73222 , CVE-2023-54350 , CVE-2025-34115 , CVE-2026-63722 , CVE-2026-49471
CWE-352CVE-2026-53649 , CVE-2025-62593 , CVE-2018-11442 , CVE-2018-11445 , CVE-2026-73222 , CVE-2026-34228 , CVE-2026-49471 , CVE-2011-4452
CWE-434CVE-2026-72592 , CVE-2026-53649 , CVE-2024-58348 , CVE-2026-44402 , CVE-2023-7305 , CVE-2025-59710 , CVE-2021-47943 , CVE-2026-34735 , CVE-2026-67206 , CVE-2026-53599 , CVE-2026-27891 , CVE-2026-54611 , CVE-2026-10172
CWE-470CVE-2026-46562 , CVE-2026-55559 , CVE-2026-58400 , CVE-2026-79987 , CVE-2026-34216
CWE-494CVE-2026-66398
CWE-502CVE-2018-19276 , CVE-2026-3296
CWE-601CVE-2015-4668
CWE-639CVE-2026-72876
CWE-641CVE-2026-46581
CWE-644CVE-2026-67179
CWE-698CVE-2026-58455
CWE-732CVE-2026-73664
CWE-791CVE-2026-78140
CWE-798CVE-2015-4667
CWE-829CVE-2026-45272 , CVE-2026-47398
CWE-835CVE-2024-20353
CWE-862CVE-2026-45632 , CVE-2026-72868 , CVE-2026-72876 , CVE-2026-49819 , CVE-2026-86438
CWE-863CVE-2026-43945 , CVE-2026-76836 , CVE-2026-86437
CWE-913CVE-2025-68613
CWE-915CVE-2026-72710 , CVE-2026-78416
CWE-918CVE-2026-49869
CWE-942CVE-2026-34449 , CVE-2026-53649
CWE-1188CVE-2026-47668
CWE-1336CVE-2026-44181 , CVE-2026-55559 , CVE-2026-28797 , CVE-2026-72827 , CVE-2026-75574 , CVE-2026-22244 , CVE-2026-77939 , CVE-2026-78140
CWE-1392CVE-2026-41939