On this page
Atomicorp WAF Rule 344366
Rule Summary
- Rule ID: 344366
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Remote Command Execution: Command Injection
- Observed CWEs: CWE-20 (12), CWE-22 (9), CWE-59 (1), CWE-73 (1), CWE-74 (24), CWE-77 (104), CWE-78 (252), CWE-79 (7), CWE-88 (2), CWE-89 (35), CWE-93 (1), CWE-94 (83), CWE-95 (6), CWE-119 (1), CWE-120 (1), CWE-121 (3), CWE-183 (1), CWE-184 (3), CWE-187 (1), CWE-200 (3), CWE-253 (1), CWE-269 (5), CWE-284 (4), CWE-285 (1), CWE-287 (3), CWE-288 (1), CWE-290 (1), CWE-306 (10), CWE-352 (7), CWE-434 (14), CWE-470 (4), CWE-494 (1), CWE-502 (5), CWE-639 (1), CWE-641 (1), CWE-644 (1), CWE-707 (1), CWE-732 (1), CWE-791 (1), CWE-829 (2), CWE-835 (1), CWE-862 (7), CWE-863 (3), CWE-915 (1), CWE-918 (1), CWE-942 (2), CWE-1188 (1), CWE-1336 (9), CWE-1392 (1)
- Revision: 1
- Rule severity: Critical
- Phase: 2 (request body)
- Request surfaces: Request cookies, Request argument names, Request arguments, JSON request data, SOAP request data, XML request data
- Rule action: deny
- HTTP status: 403
- Public tags: attack-rce
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Remote Command Execution: Command Injection” in the request cookies, request argument names, request arguments, JSON request data, SOAP request data, XML request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2025-34030 | sar2html <=3.2.2 Plot Parameter - Remote Code Execution | sar2html | 10.0 (v4.0) | Critical |
| CVE-2025-34037 | Linksys Routers E/WAG/WAP/WES/WET/WRT-Series | E4200 | 10.0 (v4.0) | Critical |
| CVE-2026-19188 | Haiwell IoT Cloud HMI Gateway OS Command Injection | Haiwell IoT Cloud HMI Gateway | 10.0 (v4.0) | Critical |
| CVE-2026-34234 | CtrlPanel: Unauthenticated RCE using installer script | panel | 10.0 (v3.1) | Critical |
| CVE-2026-44181 | Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution | enterprise gateway | 10.0 (v4.0) | Critical |
| CVE-2026-44182 | Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering | enterprise gateway | 10.0 (v4.0) | Critical |
| CVE-2026-47668 | DbGate - Remote Code Execution via Anonymous JWT | dbgate | 10.0 (v3.1) | Critical |
| CVE-2026-49869 | Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in AuthenticationFilter | kestra | 10.0 (v3.1) | Critical |
| CVE-2026-8054 | dotCMS Core Publish Audit API - Unauthenticated SQL Injection | dotcms | 10.0 (v4.0) | Critical |
| CVE-2026-81735 | UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command Executi | UI-TARS-desktop | 10.0 (v4.0) | Critical |
| CVE-2026-8984 | Unauthenticated RCE | maxicharger single charger firmware | 10.0 (v4.0) | Critical |
| CVE-2026-8985 | Unauthenticated Command Injection | maxicharger single charger firmware | 10.0 (v4.0) | Critical |
| CVE-2021-21345 | XStream < 1.4.16 - Remote Code Execution | xstream | 9.9 (v3.1) | Critical |
| CVE-2026-42454 | Termix: OS Command Injection in Docker Container Management Endpoints | Termix | 9.9 (v3.1) | Critical |
| CVE-2026-44450 | Lumiverse: RCE via MCP stdio argument injection | Lumiverse | 9.9 (v3.1) | Critical |
| CVE-2026-45629 | Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpoint | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-45632 | Dokploy: Schedule Authorization Bypass Enables Host/Server Command Execution | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-48030 | Pheditor 2.0.1-2.0.3 - OS Command Injection | pheditor | 9.9 (v3.1) | Critical |
| CVE-2026-55565 | Yamcs: Authenticated remote code execution via unescaped StreamSQL LIKE pattern compiled by Janino (LikeExpression) | yamcs | 9.9 (v3.1) | Critical |
| CVE-2026-55634 | Pimcore: Remote Code Execution via DataObject Class-Definition Field Name | pimcore | 9.9 (v3.1) | Critical |
| CVE-2026-63298 | LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration | LXD | 9.9 (v3.1) | Critical |
| CVE-2026-64637 | All Plesk Versions below 18.0.79.5 Reseller Privilege Escalation to Root | Plesk | 9.9 (v3.0) | Critical |
| CVE-2026-69084 | SiYuan - SQL Execution | siyuan | 9.9 (v4.0) | Critical |
| CVE-2026-72738 | Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameter | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72740 | Dokploy: OS Command Injection via SSH-form customGitUrl domain in ssh-keyscan | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72865 | Dokploy: OS Command Injection via compose composePath | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72868 | Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injection | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72869 | Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCE | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72872 | Dokploy: OS Command Injection via Bitbucket owner/repository in git clone | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72876 | Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72882 | Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed servers | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-72902 | Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryById | dokploy | 9.9 (v3.1) | Critical |
| CVE-2026-73263 | Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-path | prowler | 9.9 (v3.1) | Critical |
| CVE-2026-73294 | Semaphore U: OS Command Injection | semaphore | 9.9 (v3.1) | Critical |
| CVE-2026-8481 | Remote Code Execution via Code Validation Endpoint | langflow | 9.9 (v3.1) | Critical |
| CVE-2014-3206 | Seagate BlackArmor NAS - Command Injection | blackarmor nas 220 firmware | 9.8 (v3.0) | Critical |
| CVE-2015-3934 | Fiyo CMS 2.0_1.9.1 - SQL Injection | fiyo cms | 9.8 (v3.0) | Critical |
| CVE-2016-10108 | Western Digital MyCloud NAS - Command Injection | mycloud nas | 9.8 (v3.0) | Critical |
| CVE-2016-1555 | NETGEAR WNAP320 Access Point Firmware - Remote Command Injection | wnap320 firmware | 9.8 (v3.1) | Critical |
| CVE-2018-16167 | LogonTracer <=1.2.0 - Remote Command Injection | logontracer | 9.8 (v3.0) | Critical |
| CVE-2018-19276 | OpenMRS Platform < 2.24.0 - Insecure Object Deserialization | openmrs | 9.8 (v3.1) | Critical |
| CVE-2018-7841 | Schneider Electric U.Motion Builder 1.3.4 - 'track_import_export.php object_id' Unauthenticated Command Injection | u.motion builder | 9.8 (v3.1) | Critical |
| CVE-2019-12985 | Citrix SD-WAN Center - Remote Command Injection | netscaler sd-wan | 9.8 (v3.0) | Critical |
| CVE-2019-12986 | Citrix SD-WAN Center - Remote Command Injection | netscaler sd-wan | 9.8 (v3.0) | Critical |
| CVE-2019-16920 | D-Link Routers - Remote Code Execution | dir-655 firmware | 9.8 (v3.1) | Critical |
| CVE-2019-5893 | OpenSource ERP 6.3.1. - SQL Injection | open source erp | 9.8 (v3.0) | Critical |
| CVE-2020-10987 | Tenda AC15 AC1900 version 15.03.05.19 - Command Injection | ac15 firmware | 9.8 (v3.1) | Critical |
| CVE-2020-13117 | Wavlink Multiple AP - Remote Command Injection | wn575a4 | 9.8 (v3.1) | Critical |
| CVE-2020-18662 | Gnuboard5 5.3.2.8 - SQL Injection | gnuboard | 9.8 (v3.1) | Critical |
| CVE-2020-25223 | Sophos UTM Preauth - Remote Code Execution | unified threat management | 9.8 (v3.1) | Critical |
| CVE-2020-25494 | SCO Openserver 5.0.7 - 'outputform' Command Injection | openserver | 9.8 (v3.1) | Critical |
| CVE-2020-5722 | Grandstream UCM6200 - SQL Injection | ucm6200 firmware | 9.8 (v3.1) | Critical |
| CVE-2021-1472 | Cisco Small Business RV Series - OS Command Injection | rv160 firmware | 9.8 (v3.1) | Critical |
| CVE-2021-1498 | Cisco HyperFlex HX Data Platform - Remote Command Execution | hyperflex hx data platform | 9.8 (v3.1) | Critical |
| CVE-2021-21307 | Lucee Admin - Remote Code Execution | lucee server | 9.8 (v3.1) | Critical |
| CVE-2021-22502 | Micro Focus Operations Bridge Reporter - Remote Code Execution | operation bridge reporter | 9.8 (v3.1) | Critical |
| CVE-2021-31856 | Layer5 Meshery 0.5.2 - SQL Injection | meshery | 9.8 (v3.1) | Critical |
| CVE-2021-32305 | Websvn <2.6.1 - Remote Code Execution | websvn | 9.8 (v3.1) | Critical |
| CVE-2021-33357 | RaspAP <=2.6.5 - Remote Command Injection | raspap | 9.8 (v3.1) | Critical |
| CVE-2021-4039 | Zyxel NWA-1100-NH - Command Injection | nwa1100-nh firmware | 9.8 (v3.1) | Critical |
| CVE-2021-42237 | Sitecore Experience Platform Pre-Auth RCE | experience platform | 9.8 (v3.1) | Critical |
| CVE-2022-24112 | Apache APISIX - Remote Code Execution | apisix | 9.8 (v3.1) | Critical |
| CVE-2022-2486 | Wavlink WN535K2/WN535K3 - OS Command Injection | wl-wn535k2 | 9.8 (v3.1) | Critical |
| CVE-2022-2488 | Wavlink WN535K2/WN535K3 - OS Command Injection | wl-wn535k2 firmware | 9.8 (v3.1) | Critical |
| CVE-2022-29303 | SolarView Compact 6.0 - OS Command Injection | sv-cpt-mc310 firmware | 9.8 (v3.1) | Critical |
| CVE-2022-31499 | Nortek Linear eMerge E3-Series <0.32-08f - Remote Command Injection | emerge e3 firmware | 9.8 (v3.1) | Critical |
| CVE-2022-44877 | Centos Web Panel 7 v0.9.8.1147 - Unauthenticated Remote Code Execution (RCE) | webpanel | 9.8 (v3.1) | Critical |
| CVE-2022-45699 | APsystems ECU-R Firmware - Command Injection | ecu-r firmware | 9.8 (v3.1) | Critical |
| CVE-2023-22527 | Atlassian Confluence - Remote Code Execution | confluence data center | 9.8 (v3.1) | Critical |
| CVE-2023-25280 | D-Link DIR820LA1_FW105B03 'ping_addr' - OS Command Injection | dir820la1 firmware | 9.8 (v3.1) | Critical |
| CVE-2023-26035 | ZoneMinder Snapshots - Command Injection | zoneminder | 9.8 (v3.1) | Critical |
| CVE-2023-27637 | PrestaShop tshirtecommerce Module - SQL Injection | custom product designer | 9.8 (v3.1) | Critical |
| CVE-2023-30194 | Prestashop posstaticfooter <= 1.0.0 - SQL Injection | poststaticfooter | 9.8 (v3.1) | Critical |
| CVE-2023-30258 | MagnusBilling - Remote Code Execution | magnusbilling | 9.8 (v3.1) | Critical |
| CVE-2023-39361 | Cacti 1.2.24 - SQL Injection | cacti | 9.8 (v3.1) | Critical |
| CVE-2023-46347 | PrestaShop Step by Step products Pack - SQL Injection | ndk steppingpack | 9.8 (v3.1) | Critical |
| CVE-2023-6655 | Hongjing e-HR 2020 - SQL Injection | e-hr | 9.8 (v3.1) | Critical |
| CVE-2023-7116 | WeiYe-Jing datax-web <= 2.1.2 - OS Command Injection | datax-web | 9.8 (v3.1) | Critical |
| CVE-2024-23692 | Rejetto HTTP File Server - Template injection | http file server | 9.8 (v3.1) | Critical |
| CVE-2024-24495 | Daily Habit Tracker 1.0 - SQL Injection | daily habit tracker | 9.8 (v3.1) | Critical |
| CVE-2024-6671 | WhatsUp Gold GetStatisticalMonitorList SQL Injection - Authentication Bypass | whatsup gold | 9.8 (v3.1) | Critical |
| CVE-2026-12940 | Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoint | langflow | 9.8 (v3.1) | Critical |
| CVE-2026-18482 | neo-mjs Command Injection Vulnerability | neo-mjs | 9.8 (v3.1) | Critical |
| CVE-2026-31040 | stata-mcp Code Injection Vulnerability | stata-mcp | 9.8 (v3.1) | Critical |
| CVE-2026-3296 | Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | 9.8 (v3.1) | Critical |
| CVE-2026-34243 | wenxian: Command Injection in GitHub Actions Workflow via issue_comment.body | wenxian | 9.8 (v3.1) | Critical |
| CVE-2026-35048 | Piwigo RCE via PHP Code Injection into Config File in Installer | Piwigo | 9.8 (v3.1) | Critical |
| CVE-2026-35847 | dnsmgr 2.15 and Earlier Arbitrary Code Execution Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-37281 | the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 Command Injection Vulnerability | the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 | 9.8 (v3.1) | Critical |
| CVE-2026-38428 | kestra SQL Injection Vulnerability | kestra | 9.8 (v3.1) | Critical |
| CVE-2026-38431 | erpnext Code Injection Vulnerability | erpnext | 9.8 (v3.1) | Critical |
| CVE-2026-45018 | Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution | chainlit | 9.8 (v3.1) | Critical |
| CVE-2026-46562 | Yamcs: Remote Code Execution via Mission Database algorithm override | yamcs | 9.8 (v3.1) | Critical |
| CVE-2026-47391 | PraisonAI's unauthenticated A2A official example can reach real LLM-driven eval() tool execution | PraisonAI | 9.8 (v3.1) | Critical |
| CVE-2026-48687 | fastnetmon Command Injection Vulnerability | fastnetmon | 9.8 (v3.1) | Critical |
| CVE-2026-49819 | UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmd | UpSnap | 9.8 (v3.1) | Critical |
| CVE-2026-53545 | Termix: Remote Code Execution via Tunnel Disconnect pkill Command Injection | Termix | 9.8 (v3.1) | Critical |
| CVE-2026-55559 | Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance) | yamcs | 9.8 (v3.1) | Critical |
| CVE-2026-67919 | Halo 2.25.4 Arbitrary Code Execution Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-72592 | dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload | phpfm | 9.8 (v3.1) | Critical |
| CVE-2026-75411 | JeecgBoot v3.9.2 Code Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-75414 | In AntFlow V2.0.0, ActivitiTest.java Code Injection Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-79408 | MetaGPT 0.8.1 Command Injection Vulnerability | MetaGPT 0.8.1 | 9.8 (v3.1) | Critical |
| CVE-2026-8037 | Progress ADC LoadMaster - Command Injection | connection manager for objectscale | 9.8 (v3.1) | Critical |
| CVE-2026-84372 | Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections | predis | 9.8 (v3.1) | Critical |
| CVE-2026-34449 | SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection | siyuan | 9.6 (v3.1) | Critical |
| CVE-2026-35906 | An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 OS Command Injection Vulnerability | - | 9.6 (v3.1) | Critical |
| CVE-2026-53649 | Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE | joro | 9.6 (v3.1) | Critical |
| CVE-2026-72878 | Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell arguments | dokploy | 9.6 (v3.1) | Critical |
| CVE-2026-70477 | Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability | Flowise | 9.5 (v4.0) | Critical |
| CVE-2026-8986 | Command Injection via Malicious OCPP Server | maxicharger single charger firmware | 9.5 (v4.0) | Critical |
| CVE-2019-16383 | MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection | moveit transfer | 9.4 (v3.1) | Critical |
| CVE-2025-62593 | Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack | ray | 9.4 (v4.0) | Critical |
| CVE-2026-33324 | SQLBot prompt injection allows arbitrary SQL execution and remote code execution | sqlbot | 9.4 (v4.0) | Critical |
| CVE-2026-39932 | OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection | openemr | 9.4 (v4.0) | Critical |
| CVE-2026-45272 | MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File | talebook | 9.4 (v4.0) | Critical |
| CVE-2026-47670 | DbGate - Remote Code Execution via Dynamic Import Bypass | dbgate | 9.4 (v4.0) | Critical |
| CVE-2026-63732 | 9router before 0.4.60 Remote Code Execution via default password | 9router | 9.4 (v4.0) | Critical |
| CVE-2026-66398 | phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API | phpMyFAQ | 9.4 (v4.0) | Critical |
| CVE-2026-69256 | Flowise: Remote Code Execution Vulnerability in CSVAgent | Flowise | 9.4 (v4.0) | Critical |
| CVE-2026-72879 | Dokploy: Command Injection via Registry Credentials in Swarm Upload | dokploy | 9.4 (v4.0) | Critical |
| CVE-2026-73041 | SiYuan before v3.7.4 Remote Code Execution via PDF Annotations | siyuan | 9.4 (v4.0) | Critical |
| CVE-2026-73042 | SiYuan before v3.7.4 Remote Code Execution via Menu Metadata | siyuan | 9.4 (v4.0) | Critical |
| CVE-2026-73483 | Flowise before 3.1.3 Sandbox Escape via Puppeteer | flowise | 9.4 (v4.0) | Critical |
| CVE-2026-82244 | Budibase before 3.41.3 Remote Code Execution via Plugin eval() | server | 9.4 (v4.0) | Critical |
| CVE-2013-2642 | Sophos Web Protection Appliance 3.7.8.1 - Multiple Vulnerabilities | web appliance firmware | 9.3 (v2.0) | High |
| CVE-2017-20251 | WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API | Woody Code Snippets | 9.3 (v4.0) | Critical |
| CVE-2018-25357 | Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php | dolibarr erp/crm | 9.3 (v4.0) | Critical |
| CVE-2019-25687 | Pegasus CMS 1.0 Remote Code Execution via extra_fields.php | pegasus cms | 9.3 (v4.0) | Critical |
| CVE-2024-33559 | Wordpress Theme XStore 9.3.8 - SQLi | XStore | 9.3 (v3.1) | Critical |
| CVE-2024-58348 | WordPress Background Image Cropper 1.2 Remote Code Execution | Background Image Cropper | 9.3 (v4.0) | Critical |
| CVE-2025-31114 | Fooocus webui vulnerable to Remote Code Execution | Fooocus | 9.3 (v4.0) | Critical |
| CVE-2026-19586 | Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways | er7212pc firmware | 9.3 (v4.0) | Critical |
| CVE-2026-41939 | Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly | Care Everywhere Gateway | 9.3 (v4.0) | Critical |
| CVE-2026-42647 | JoomSport <= 5.7.7 - SQL Injection | joomsport-sports-league-results-management | 9.3 (v3.1) | Critical |
| CVE-2026-44402 | Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi | SNMP Web Pro | 9.3 (v4.0) | Critical |
| CVE-2026-53975 | OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec | OpenChamber | 9.3 (v4.0) | Critical |
| CVE-2026-58138 | Orkes Conductor 3.21.21-3.30.1 - Remote Code Execution | conductor | 9.3 (v4.0) | Critical |
| CVE-2026-60121 | Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php | flamingo | 9.3 (v4.0) | Critical |
| CVE-2026-61498 | Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php | flamingo | 9.3 (v4.0) | Critical |
| CVE-2026-61511 | vBulletin 6.x - Remote Code Execution | vBulletin | 9.3 (v4.0) | Critical |
| CVE-2026-63766 | GPT-SoVITS 20250606v2pro OS Command Injection via webui.py | GPT-SoVITS | 9.3 (v4.0) | Critical |
| CVE-2026-64625 | AVideo before 29.0 OS Command Injection via execAsync | AVideo | 9.3 (v4.0) | Critical |
| CVE-2026-64824 | Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore | Home Assistant Core | 9.3 (v4.0) | Critical |
| CVE-2026-65008 | Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData | grav | 9.3 (v4.0) | Critical |
| CVE-2026-67308 | Wazuh GitHub Actions Shell Injection via Fork Pull Request | wazuh | 9.3 (v4.0) | Critical |
| CVE-2026-70553 | MaxSite CMS Unauthenticated RCE via Install Endpoint | MaxSite CMS | 9.3 (v4.0) | Critical |
| CVE-2026-71921 | DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi | VigorSwitch G2540xs | 9.3 (v4.0) | Critical |
| CVE-2026-71944 | D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71945 | D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71946 | D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71947 | D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71948 | D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71949 | D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71950 | D-Link DWR-M961 Command Injection via /boafrm/formSmsManage | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71951 | D-Link DWR-M961 Command Injection via /boafrm/formIMEISetup | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71952 | D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetup | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71953 | D-Link DWR-M961 Command Injection via /boafrm/formNtp | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71954 | D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71955 | D-Link DWR-M961 Command Injection via /boafrm/formWsc | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71956 | D-Link DWR-M961 Command Injection via app.cgi | DWR-M961 | 9.3 (v4.0) | Critical |
| CVE-2026-71984 | MSI Radix AXE6600 v781521 Command Injection via urlfilter | Radix AXE6600 | 9.3 (v4.0) | Critical |
| CVE-2026-71992 | MSI Radix AXE6600 v781521 Command Injection via macfilter | Radix AXE6600 | 9.3 (v4.0) | Critical |
| CVE-2026-76070 | Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter | NC63 | 9.3 (v4.0) | Critical |
| CVE-2026-76071 | Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter | NC63 | 9.3 (v4.0) | Critical |
| CVE-2023-7305 | SmartBI RMIServlet Unrestricted File Upload RCE | SmartBI | 9.2 (v4.0) | Critical |
| CVE-2026-63304 | AVideo through 29.0 OS Command Injection via listFFmpegProcesses | AVideo | 9.2 (v4.0) | Critical |
| CVE-2026-63305 | AVideo through 29.0 OS Command Injection via ffmpeg.json.php | AVideo | 9.2 (v4.0) | Critical |
| CVE-2026-80138 | ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameter | clipbucket-v5 | 9.2 (v4.0) | Critical |
| CVE-2026-46621 | Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection | yamcs | 9.1 (v3.1) | Critical |
| CVE-2026-55511 | Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs executeSql | yamcs | 9.1 (v3.1) | Critical |
| CVE-2026-57499 | Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE) | core | 9.1 (v3.1) | Critical |
| CVE-2026-58400 | GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter | core-geonetwork | 9.1 (v3.1) | Critical |
| CVE-2026-34612 | Kestra: Remote Code Execution via SQL Injection | kestra | 9.0 (v3.1) | Critical |
| CVE-2026-45630 | Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo Statement | dokploy | 9.0 (v3.1) | Critical |
| CVE-2026-62674 | Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE | omnigent | 9.0 (v3.1) | Critical |
| CVE-2026-69251 | Flowise RCE via TypeORM DataSource | Flowise | 9.0 (v4.0) | Critical |
| CVE-2026-73485 | Flowise before 3.1.3 Remote Code Execution via Airtable Agent | flowise | 9.0 (v4.0) | Critical |
| CVE-2026-73486 | Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV | flowise | 9.0 (v4.0) | Critical |
| CVE-2026-73487 | Flowise before 3.1.3 Prompt Injection RCE via CSV Agent | flowise | 9.0 (v4.0) | Critical |
| CVE-2026-43945 | FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection | FUXA | 8.9 (v4.0) | High |
| CVE-2026-7202 | Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-7203 | Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-7204 | Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-73570 | zimbra collaboration suite Arbitrary Code Execution Vulnerability | zimbra collaboration suite | 8.9 (v3.1) | High |
| CVE-2026-77956 | EEx template evaluation of prompt content in AshAi enables remote code execution | ash ai | 8.9 (v4.0) | High |
| CVE-2026-9384 | Totolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9385 | Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9386 | Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9387 | Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9388 | Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9404 | Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9405 | Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9406 | Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9407 | Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9408 | Totolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9432 | Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9433 | Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9434 | Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9435 | Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9436 | Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9454 | Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9455 | Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9456 | Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9457 | Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9458 | Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9475 | Totolink A8000RU Web Management cstecgi.cgi setIpQosRules os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9476 | Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9477 | Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2026-9478 | Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection | A8000RU | 8.9 (v4.0) | High |
| CVE-2016-4808 | Web2py 2.14.5 - Multiple Vulnerabilities | web2py | 8.8 (v3.0) | High |
| CVE-2017-6884 | Zyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command Injection | emg2926 firmware | 8.8 (v3.1) | High |
| CVE-2018-7765 | Schneider Electric U.Motion Builder 1.3.4 - 'track_import_export.php object_id' Unauthenticated Command Injection | u.motion builder | 8.8 (v3.0) | High |
| CVE-2019-15642 | Webmin < 1.920 - Authenticated Remote Code Execution | webmin | 8.8 (v3.0) | High |
| CVE-2019-9189 | Prima Access Control 2.3.35 - Arbitrary File Upload | flexair | 8.8 (v3.0) | High |
| CVE-2020-10221 | rConfig <= 3.9.4 - Authenticated OS Command Injection | rconfig | 8.8 (v3.1) | High |
| CVE-2020-15874 | Command Injection | - | 8.8 (v3.1) | High |
| CVE-2020-17505 | Artica Web Proxy 4.30 - OS Command Injection | web proxy | 8.8 (v3.1) | High |
| CVE-2020-26217 | XStream <1.4.14 - Remote Code Execution | xstream | 8.8 (v3.1) | High |
| CVE-2020-5776 | MAGMI - Cross-Site Request Forgery | magmi | 8.8 (v3.1) | High |
| CVE-2022-3800 | IBAX - SQL Injection | go-ibax | 8.8 (v3.1) | High |
| CVE-2023-45375 | PrestaShop PireosPay - SQL Injection | pireospay | 8.8 (v3.1) | High |
| CVE-2023-7137 | Client Details System 1.0 - SQL Injection | client details system | 8.8 (v3.1) | High |
| CVE-2024-39024 | In Packetfence 13.2.0, the WebGui interface setting Arbitrary Code Execution Vulnerability | - | 8.8 (v3.1) | High |
| CVE-2025-59710 | biztalk360 Arbitrary Code Execution Vulnerability | biztalk360 | 8.8 (v3.1) | High |
| CVE-2026-24893 | openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansion | openitcockpit | 8.8 (v3.1) | High |
| CVE-2026-26899 | OS Command Injection | - | 8.8 (v3.1) | High |
| CVE-2026-34197 | Apache ActiveMQ - Remote Code Execution | activemq | 8.8 (v3.1) | High |
| CVE-2026-35031 | Jellyfin: Potential RCE via subtitle upload path traversal + .strm chain | jellyfin | 8.8 (v3.1) | High |
| CVE-2026-35196 | Chamilo LMS has OS Command Injection via export_all_certificates action | chamilo lms | 8.8 (v3.1) | High |
| CVE-2026-45505 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia addNetworkConnector Discovery Wrapper Bypass | activemq | 8.8 (v3.1) | High |
| CVE-2026-45578 | WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URL | avideo | 8.8 (v3.1) | High |
| CVE-2026-45662 | Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion) | dokploy | 8.8 (v3.1) | High |
| CVE-2026-48017 | DbGate: Remote Code Execution via functionName injection in loadReader endpoint | dbgate | 8.8 (v3.1) | High |
| CVE-2026-55585 | QWED: Authenticated Remote Code Execution via Unsafe SymPy parse_expr() | qwed-verification | 8.8 (v3.1) | High |
| CVE-2026-58195 | Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into ex | agentic-flow | 8.8 (v3.1) | High |
| CVE-2026-62675 | Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools | omnigent | 8.8 (v3.1) | High |
| CVE-2026-72875 | Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFile | dokploy | 8.8 (v3.1) | High |
| CVE-2026-73222 | Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (–studio) | claude-code-templates | 8.8 (v3.1) | High |
| CVE-2026-78834 | Security Vulnerability | - | 8.8 (v3.1) | High |
| CVE-2026-79423 | the admin_config.php component of seacms v13.6 Arbitrary Code Execution Vulnerability | the admin config.php component of seacms v13.6 | 8.8 (v3.1) | High |
| CVE-2026-82217 | Eclipse Theia Path Traversal Vulnerability | Eclipse Theia | 8.8 (v3.1) | High |
| CVE-2019-25671 | VA MAX 8.3.4 Remote Code Execution via changeip.php | VA MAX | 8.7 (v4.0) | High |
| CVE-2021-47938 | ImpressCMS 1.4.2 Remote Code Execution via Autotasks | ImpressCMS | 8.7 (v4.0) | High |
| CVE-2021-47939 | Evolution CMS 3.1.6 Authenticated Remote Code Execution via Module Creation | Evolution CMS | 8.7 (v4.0) | High |
| CVE-2021-47943 | TextPattern CMS 4.8.7 Remote Code Execution via File Upload | TextPattern CMS | 8.7 (v4.0) | High |
| CVE-2022-50944 | Aero CMS 0.0.1 PHP Code Injection via posts.php | Aero CMS | 8.7 (v4.0) | High |
| CVE-2023-54350 | WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated | Augmented Reality | 8.7 (v4.0) | High |
| CVE-2025-30007 | HestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record Management | control panel | 8.7 (v4.0) | High |
| CVE-2025-34115 | OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.php | OP5 Monitor | 8.7 (v4.0) | High |
| CVE-2026-28797 | RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Compone | ragflow | 8.7 (v4.0) | High |
| CVE-2026-34228 | Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write | emlog | 8.7 (v4.0) | High |
| CVE-2026-34735 | Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileController | wiki | 8.7 (v4.0) | High |
| CVE-2026-34792 | Endian Firewall /cgi-bin/logs_clamav.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34793 | Endian Firewall /cgi-bin/logs_firewall.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34794 | Endian Firewall /cgi-bin/logs_ids.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34795 | Endian Firewall /cgi-bin/logs_log.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34796 | Endian Firewall /cgi-bin/logs_openvpn.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-34797 | Endian Firewall /cgi-bin/logs_smtp.cgi DATE Perl Command Injection | firewall community | 8.7 (v4.0) | High |
| CVE-2026-46746 | sinec ins OS Command Injection Vulnerability | sinec ins | 8.7 (v4.0) | High |
| CVE-2026-49143 | BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handler | browserstack-runner | 8.7 (v4.0) | High |
| CVE-2026-63722 | ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.php | ICEcoder | 8.7 (v4.0) | High |
| CVE-2026-64850 | Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() | grav | 8.7 (v4.0) | High |
| CVE-2026-67206 | Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload | wolfcms | 8.7 (v4.0) | High |
| CVE-2026-69096 | OpenWrt luci-app-dockerman Read ACL Remote Code Execution | luci | 8.7 (v4.0) | High |
| CVE-2026-69100 | LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution | lamp-cloud | 8.7 (v4.0) | High |
| CVE-2026-71966 | CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer | cyberpanel | 8.7 (v4.0) | High |
| CVE-2026-72819 | Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload | grav | 8.7 (v4.0) | High |
| CVE-2026-72827 | Grav CMS before 2.0.13 Remote Code Execution via Twig | grav | 8.7 (v4.0) | High |
| CVE-2026-72830 | Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass | grav | 8.7 (v4.0) | High |
| CVE-2026-72870 | Dokploy: Command Injection via Docker Credentials in buildRemoteDocker | dokploy | 8.7 (v4.0) | High |
| CVE-2026-72874 | Dokploy: Command Injection via Unescaped Git URL in Clone Commands | dokploy | 8.7 (v4.0) | High |
| CVE-2026-73680 | Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename | Cockpit CMS | 8.7 (v4.0) | High |
| CVE-2026-75574 | Grav before 4.2.2 Remote Code Execution via Email Twig | grav | 8.7 (v4.0) | High |
| CVE-2026-76060 | OS Command Injection in PayRange API | Zoneminder | 8.7 (v4.0) | High |
| CVE-2026-76836 | AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group Bypass | AzuraCast | 8.7 (v4.0) | High |
| CVE-2026-78416 | Authenticated RCE via condition.config JSON cleanse bypass | cms | 8.7 (v4.0) | High |
| CVE-2026-79756 | Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platform | nuclio | 8.7 (v4.0) | High |
| CVE-2026-82278 | BISHENG Authenticated Arbitrary Python Code Execution via Workflow run_once | bisheng | 8.7 (v4.0) | High |
| CVE-2026-85604 | Grav before 2.0.19 Remote Code Execution via sort filter | grav | 8.7 (v4.0) | High |
| CVE-2026-85610 | OpenPanel before 2.3.0 Remote Code Execution via chart formulas | openpanel | 8.7 (v4.0) | High |
| CVE-2026-86732 | Craft CMS before 5.10.12 Remote Code Execution via element-index | cms | 8.7 (v4.0) | High |
| CVE-2024-20353 | adaptive security appliance software Denial of Service Vulnerability | adaptive security appliance software | 8.6 (v3.1) | High |
| CVE-2026-40187 | Authenticated RCE via Malicious eTemplate Upload in EGroupware | egroupware | 8.6 (v4.0) | High |
| CVE-2026-42785 | OpenKM 6.3.12 Remote Code Execution via Administrative Scripting | OpenKM Community Edition | 8.6 (v4.0) | High |
| CVE-2026-53804 | OTRS Community Edition OS Command Injection via PGP Configuration | OTRS Community Edition | 8.6 (v4.0) | High |
| CVE-2026-55182 | LibreNMS: Remote Code Execution by Signal Alert Transportation Module | librenms | 8.6 (v4.0) | High |
| CVE-2026-56703 | Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTO | adminer | 8.6 (v4.0) | High |
| CVE-2026-61517 | Netis NX10 OS Command Injection via Ping Diagnostic Handler | NX10 | 8.6 (v4.0) | High |
| CVE-2026-61523 | WebsiteBaker CMS < 2.13.10 Code Injection via Droplets Editor | WebsiteBaker CMS | 8.6 (v4.0) | High |
| CVE-2026-63725 | sysPass FileBackupService Authenticated OS Command Injection via Backup Path | sysPass | 8.6 (v4.0) | High |
| CVE-2026-65693 | Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates | microweber | 8.6 (v4.0) | High |
| CVE-2026-65711 | sysPass 3.2.11 Authenticated OS Command Injection via Backup Path | sysPass | 8.6 (v4.0) | High |
| CVE-2026-67599 | ClearOS 7.9 OS Command Injection via Log Viewer filter parameter | ClearOS | 8.6 (v4.0) | High |
| CVE-2026-67608 | Telenia TVox 26.5.3 OS Command Injection via action_audio.php | TVox | 8.6 (v4.0) | High |
| CVE-2026-69088 | Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint | grav | 8.6 (v4.0) | High |
| CVE-2026-71906 | DrayTek VigorAP Multiple Models OS Command Injection via setLan | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71907 | DrayTek VigorAP Multiple Models OS Command Injection via setcamset | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71908 | DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_test | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71913 | DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgi | VigorAP 918R | 8.6 (v4.0) | High |
| CVE-2026-71915 | DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatus | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71918 | DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupAction | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71919 | DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71923 | DrayTek VigorSwitch Multiple Models OS Command Injection via auth_set | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71924 | DrayTek VigorSwitch Multiple Models OS Command Injection via getVid | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71925 | DrayTek VigorSwitch Multiple Models OS Command Injection via getDetail | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71926 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevice | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71927 | DrayTek VigorSwitch Multiple Models OS Command Injection via rebDevice | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71928 | DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDevice | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71929 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProto | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71930 | DrayTek VigorSwitch Multiple Models OS Command Injection via setTime | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71931 | DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-71943 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNet | VigorSwitch G2540xs | 8.6 (v4.0) | High |
| CVE-2026-73664 | FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module | backup | 8.6 (v4.0) | High |
| CVE-2026-75121 | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_post | PLANET GS-4210-16P2S V3 | 8.6 (v4.0) | High |
| CVE-2026-75122 | PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgi | PLANET GS-4210-16P2S V3 | 8.6 (v4.0) | High |
| CVE-2026-75123 | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_post | PLANET GS-4210-16P2S V3 | 8.6 (v4.0) | High |
| CVE-2026-80214 | LibreNMS Virtualisation Discovery Module RCE | librenms | 8.6 (v4.0) | High |
| CVE-2026-82692 | D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection | DNS-340L | 8.6 (v4.0) | High |
| CVE-2026-84194 | LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostname | librenms | 8.6 (v4.0) | High |
| CVE-2026-85223 | D-Link DNS-340L CGI dropbox.cgi os command injection | DNS-340L | 8.6 (v4.0) | High |
| CVE-2026-86299 | Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection | RE7000 | 8.6 (v4.0) | High |
| CVE-2026-86437 | Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload | laradashboard | 8.6 (v4.0) | High |
| CVE-2026-86438 | Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action | laradashboard | 8.6 (v4.0) | High |
| CVE-2026-86733 | Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore | snipe-it | 8.6 (v4.0) | High |
| CVE-2026-22244 | OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCE | openmetadata | 8.5 (v4.0) | High |
| CVE-2026-82690 | D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection | DNS-327L | 8.5 (v4.0) | High |
| CVE-2026-82691 | D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection | DNS-320L | 8.5 (v4.0) | High |
| CVE-2026-85222 | D-Link DNS-340L Add-On Center addon_center.cgi os command injection | DNS-340L | 8.5 (v4.0) | High |
| CVE-2026-85224 | D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection | DNS-320 ShareCenter | 8.5 (v4.0) | High |
| CVE-2025-59711 | biztalk360 Path Traversal Vulnerability | biztalk360 | 8.3 (v3.1) | High |
| CVE-2026-49471 | Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE | serena | 8.3 (v3.1) | High |
| CVE-2025-69755 | Neterbit NW-431F Router vNW-431F-20241014-IR03 Arbitrary Code Execution Vulnerability | - | 8.2 (v3.1) | High |
| CVE-2017-9805 | Apache Struts2 S2-052 - Remote Code Execution | struts | 8.1 (v3.1) | High |
| CVE-2026-42588 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector | activemq | 8.1 (v3.1) | High |
| CVE-2026-45344 | LinkAce: Setup database password newline injection enables pre-auth RCE on uninitialized instances | LinkAce | 8.1 (v3.1) | High |
| CVE-2026-47398 | PraisonAI: Arbitrary code execution via unguarded spec.loader.exec_module in agents_generator.py - sibling of CVE-20 | PraisonAI | 8.1 (v3.1) | High |
| CVE-2026-48695 | fastnetmon Command Injection Vulnerability | fastnetmon | 8.1 (v3.1) | High |
| CVE-2026-71320 | Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props | nuxt | 8.1 (v3.1) | High |
| CVE-2025-6204 | DELMIA Apriso - Command Injection | delmia apriso | 8.0 (v3.1) | High |
| CVE-2026-52831 | Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE | nuclio | 8.0 (v3.1) | High |
| CVE-2026-79755 | Nuclio: Unauthenticated OS command injection via function namespace in docker ps –filter label (local Docker platform) | nuclio | 8.0 (v3.1) | High |
| CVE-2019-20499 | D-Link DWL-2600AP - Multiple OS Command Injection | dwl-2600ap firmware | 7.8 (v3.1) | High |
| CVE-2019-20500 | D-Link DWL-2600AP - Multiple OS Command Injection | dwl-2600ap firmware | 7.8 (v3.1) | High |
| CVE-2019-20501 | D-Link DWL-2600AP - Multiple OS Command Injection | dwl-2600ap firmware | 7.8 (v3.1) | High |
| CVE-2026-67179 | Genkit improper host header validation | genkit | 7.8 (v3.1) | High |
| CVE-2025-27621 | UpTrain has a Constant Default API Key | uptrain | 7.7 (v4.0) | High |
| CVE-2026-40519 | Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins() | nginx-proxy-manager | 7.7 (v4.0) | High |
| CVE-2026-66738 | SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLite | SPIP | 7.7 (v4.0) | High |
| CVE-2015-2824 | WordPress Plugin Simple Ads Manager - Multiple SQL Injections | simple ads manager | 7.5 (v2.0) | High |
| CVE-2016-4806 | Web2py 2.14.5 - Multiple Vulnerabilities | web2py | 7.5 (v3.0) | High |
| CVE-2017-10271 | Oracle WebLogic Server - Remote Command Execution | weblogic server | 7.5 (v3.1) | High |
| CVE-2026-34239 | Chamilo Authenticated Remote Code Execution | chamilo-lms | 7.5 (v4.0) | High |
| CVE-2026-36783 | Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to Denial of Service Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-36796 | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to Denial of Service Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-46581 | mojarra Path Traversal Vulnerability | mojarra | 7.5 (v3.1) | High |
| CVE-2026-51078 | Dede CMS v.5.7.118 Information Disclosure Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-53599 | Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mo | core | 7.5 (v3.1) | High |
| CVE-2026-10870 | Shibby Tomato Web UI rc start_dhcpc os command injection | Tomato | 7.3 (v4.0) | High |
| CVE-2026-10871 | Shibby Tomato Web UI rc start_6rd_tunnel os command injection | Tomato | 7.3 (v4.0) | High |
| CVE-2026-10873 | Shibby Tomato Web UI rstats rstats_path os command injection | Tomato | 7.3 (v4.0) | High |
| CVE-2026-18900 | H3C NX15 Backend RPC esps file.exec os command injection | NX15 | 7.3 (v4.0) | High |
| CVE-2026-19771 | Baicells EG3661M LuCI Web luci os command injection | EG3661M | 7.3 (v4.0) | High |
| CVE-2023-1211 | phpIPAM 1.5.1 - SQL Injection | phpipam | 7.2 (v3.1) | High |
| CVE-2025-29635 | D-Link DIR-823X set_prohibiting - Command Injection | dir-823x firmware | 7.2 (v3.1) | High |
| CVE-2026-13392 | ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite) | ElementsKit Elementor Addons | 7.2 (v3.1) | High |
| CVE-2026-15686 | Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability | Adminer | 7.2 (v3.0) | High |
| CVE-2026-27891 | Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism | facturascripts | 7.2 (v3.1) | High |
| CVE-2026-71284 | Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filename | fledge | 7.2 (v3.1) | High |
| CVE-2026-71964 | CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload | cyberpanel | 7.1 (v4.0) | High |
| CVE-2026-77939 | Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint | flextype | 7.1 (v4.0) | High |
| CVE-2026-11450 | GL.iNet GL-MT3000 Path Normalization dlopen command injection | GL-MT3000 | 6.9 (v4.0) | Medium |
| CVE-2026-19983 | GL.iNet XE3000 NAS Command Service gl_nas_sys os command injection | A1300 | 6.9 (v4.0) | Medium |
| CVE-2026-5739 | PowerJob OpenAPI Endpoint addWorkflowNode GroovyEvaluator.evaluate code injection | PowerJob | 6.9 (v4.0) | Medium |
| CVE-2025-59709 | biztalk360 Path Traversal Vulnerability | biztalk360 | 6.8 (v3.1) | Medium |
| CVE-2026-10821 | Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE | Yoast SEO Premium | 6.6 (v3.1) | Medium |
| CVE-2026-34216 | CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in SettingsController.php | panel | 6.6 (v3.1) | Medium |
| CVE-2018-6671 | McAfee ePO 5.9.1 - Registered Executable Local Access Bypass | epolicy orchestrator | 6.5 (v3.0) | Medium |
| CVE-2024-4257 | BlueNet Technology Clinical Browsing System 1.2.1 - Sql Injection | clinical browsing system | 6.5 (v3.1) | Medium |
| CVE-2026-72739 | Dokploy: Command Injection via Compose Shell Execution | dokploy | 6.5 (v3.1) | Medium |
| CVE-2024-32231 | Stash < 0.26.0 - SQL Injection | stash | 6.3 (v3.1) | Medium |
| CVE-2026-44287 | FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*(/ is bypassable | FastGPT | 6.3 (v3.1) | Medium |
| CVE-2026-45626 | Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameter | arcane | 6.3 (v3.1) | Medium |
| CVE-2025-10090 | Jinher OA - SQL Injection | jinher oa | 5.5 (v4.0) | Medium |
| CVE-2025-13786 | taosir WTCMS index.php fetch code injection | wtcms | 5.5 (v4.0) | Medium |
| CVE-2025-13792 | Qualitor getResumo.php eval code injection | Qualitor | 5.5 (v4.0) | Medium |
| CVE-2026-10214 | zhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injection | chatgpt-on-wechat | 5.5 (v4.0) | Medium |
| CVE-2026-18641 | Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginC | Operation and Maintenance Security Management System | 5.5 (v4.0) | Medium |
| CVE-2026-19379 | EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection | ipTIME AX8004M | 5.5 (v4.0) | Medium |
| CVE-2026-54611 | InstantCMS has Remote Code Execution in package installer | icms2 | 5.5 (v3.1) | Medium |
| CVE-2026-5631 | assafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injection | gpt-researcher | 5.5 (v4.0) | Medium |
| CVE-2026-5677 | Totolink A7100RU cstecgi.cgi CsteSystem os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5678 | Totolink A7100RU cstecgi.cgi setScheduleCfg os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5688 | Totolink A7100RU cstecgi.cgi setDdnsCfg os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5689 | Totolink A7100RU cstecgi.cgi setNtpCfg os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5690 | Totolink A7100RU cstecgi.cgi setRemoteCfg os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5691 | Totolink A7100RU cstecgi.cgi setFirewallType os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5692 | Totolink A7100RU cstecgi.cgi setGameSpeedCfg os command injection | A7100RU | 5.5 (v4.0) | Medium |
| CVE-2026-5736 | PowerJob detailPlus Endpoint InstanceController.java sql injection | PowerJob | 5.5 (v4.0) | Medium |
| CVE-2026-5741 | suvarchal docker-mcp-server HTTP index.ts pull_image os command injection | docker-mcp-server | 5.5 (v4.0) | Medium |
| CVE-2026-5802 | idachev mcp-javadc HTTP os command injection | mcp-javadc | 5.5 (v4.0) | Medium |
| CVE-2026-7220 | jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injection | FastlyMCP | 5.5 (v4.0) | Medium |
| CVE-2026-76760 | chenhg5 cc-connect webhook.go authenticate code injection | cc-connect | 5.5 (v4.0) | Medium |
| CVE-2026-76761 | chenhg5 cc-connect Management API engine.go shellExecCommand os command injection | cc-connect | 5.5 (v4.0) | Medium |
| CVE-2026-82598 | SeaCMS Template search.php parseIf code injection | SeaCMS | 5.5 (v4.0) | Medium |
| CVE-2026-85137 | SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injection | SeaCMS | 5.5 (v4.0) | Medium |
| CVE-2026-9474 | yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injection | StudentManagementSystem | 5.5 (v4.0) | Medium |
| CVE-2017-12544 | HPE System Management - Cross-Site Scripting | system management homepage | 5.4 (v3.0) | Medium |
| CVE-2026-54543 | Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields | froxlor | 5.4 (v3.1) | Medium |
| CVE-2023-7299 | DataGear resolveSql sql injection | datagear | 5.3 (v4.0) | Medium |
| CVE-2026-19785 | francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection | RosarioSIS | 5.3 (v4.0) | Medium |
| CVE-2026-5547 | Tenda AC10 httpd formAddMacfilterRule os command injection | ac10 firmware | 5.3 (v4.0) | Medium |
| CVE-2013-2641 | Sophos Web Protection Appliance 3.7.8.1 - Multiple Vulnerabilities | web appliance firmware | 5.0 (v2.0) | Medium |
| CVE-2016-4807 | Web2py 2.14.5 - Multiple Vulnerabilities | web2py | 4.8 (v3.0) | Medium |
| CVE-2013-2643 | Sophos Web Protection Appliance 3.7.8.1 - Multiple Vulnerabilities | web appliance firmware | 4.3 (v2.0) | Medium |
| CVE-2026-36239 | PbootCMS v.3.2.11 Cross-site Scripting Vulnerability | PbootCMS v.3.2.11 | 4.3 (v3.1) | Medium |
| CVE-2026-10172 | Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted upload | Multi-Store Inventory Management System | 2.1 (v4.0) | Low |
| CVE-2026-10279 | hiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injection | wezterm-mcp | 2.1 (v4.0) | Low |
| CVE-2026-11408 | vertex-app vertex Log Viewer Endpoint LogMod.js os command injection | vertex | 2.1 (v4.0) | Low |
| CVE-2026-19932 | DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.evaluate code injection | Notice-System-Managent | 2.1 (v4.0) | Low |
| CVE-2026-19958 | iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injection | pptr-mcp | 2.1 (v4.0) | Low |
| CVE-2026-5351 | Trendnet TEW-657BRM setup.cgi add_wps_client os command injection | tew-657brm firmware | 2.1 (v4.0) | Low |
| CVE-2026-5352 | Trendnet TEW-657BRM setup.cgi edit os command injection | tew-657brm firmware | 2.1 (v4.0) | Low |
| CVE-2026-5353 | Trendnet TEW-657BRM setup.cgi ping_test os command injection | tew-657brm firmware | 2.1 (v4.0) | Low |
| CVE-2026-5354 | Trendnet TEW-657BRM setup.cgi vpn_connect os command injection | tew-657brm firmware | 2.1 (v4.0) | Low |
| CVE-2026-5355 | Trendnet TEW-657BRM setup.cgi vpn_drop os command injection | tew-657brm firmware | 2.1 (v4.0) | Low |
| CVE-2026-78166 | provectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest code injection | kafka-ui | 2.1 (v4.0) | Low |
| CVE-2026-8188 | Wavlink NU516U1 adm.cgi change_wifi_password os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8189 | Wavlink NU516U1 adm.cgi wzdrepeater os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8190 | Wavlink NU516U1 adm.cgi wan os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8191 | Wavlink NU516U1 adm.cgi wifi_region os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8192 | Wavlink NU516U1 adm.cgi wzdap os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8227 | Wavlink NU516U1 adm.cgi wzdapMesh os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8228 | Wavlink NU516U1 wireless.cgi advance os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8229 | Wavlink NU516U1 wireless.cgi WifiBasic os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8230 | Wavlink NU516U1 login.cgi sys_login1 os command injection | wl-nu516u1 firmware | 2.1 (v4.0) | Low |
| CVE-2026-8264 | Tenda AC6 httpd WifiApScan formWifiApScan os command injection | ac6 firmware | 2.1 (v4.0) | Low |
| CVE-2026-9302 | 546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injection | vps-inventory-monitoring | 2.1 (v4.0) | Low |
| CVE-2026-9343 | Edimax EW-7438RPn webs formWpsStart os command injection | EW-7438RPn | 2.1 (v4.0) | Low |
| CVE-2026-9347 | Edimax EW-7438RPn webs formWizSurvey os command injection | EW-7438RPn | 2.1 (v4.0) | Low |
| CVE-2026-9424 | Edimax EW-7438RPn Content-Type formWlanMP os command injection | EW-7438RPn | 2.1 (v4.0) | Low |
| CVE-2026-9511 | Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9512 | Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9514 | Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9515 | Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9531 | Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9532 | Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9533 | Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-9534 | Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection | CA750-PoE | 2.1 (v4.0) | Low |
| CVE-2026-19964 | Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injection | Jij-MCP-Server | 2.0 (v4.0) | Low |
| CVE-2026-78140 | Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine | UJCMS | 2.0 (v4.0) | Low |
| CVE-2026-8259 | Tenda AC6 httpd telnet os command injection | ac6 firmware | 2.0 (v4.0) | Low |
| CVE-2026-8265 | Tenda AC6 httpd getLogFile get_log_file os command injection | ac6 firmware | 2.0 (v4.0) | Low |
| CVE-2026-82678 | diem-project diem Administrative Console actions.class.php executeCommand os command injection | diem | 2.0 (v4.0) | Low |
| CVE-2026-82702 | Edimax BR-6214K asp_WlanMP Endpoint wlanMP.asp system os command injection | BR-6214K | 2.0 (v4.0) | Low |
| CVE-2026-82703 | Edimax BR-6214K asp_setPing Endpoint ping.asp system os command injection | BR-6214K | 2.0 (v4.0) | Low |
| CVE-2026-85040 | ZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injection | CRMEB | 2.0 (v4.0) | Low |
| CVE-2026-16129 | princezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklist | SafestClaw | 1.9 (v4.0) | Low |
| CVE-2026-5621 | ChrisChinchilla Vale-MCP HTTP index.ts os command injection | Vale-MCP | 1.9 (v4.0) | Low |
| CVE-2026-19353 | DedeCMS Installation Wizard index.php _4_Setup file inclusion | DedeCMS | 1.3 (v4.0) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.