On this page

Atomicorp WAF Rule 393655

Rule Summary

Description

This rule detects behavior identified by its current alert as “Possible Remote Command Execution: Unix Shell Expression Found” in the request cookies, request argument names, request arguments, JSON request data, SOAP request data, XML request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2021-44228Apache Log4j2 Remote Code Injectionlog4j10.0 (v3.1)Critical
CVE-2022-22947Spring Cloud Gateway Code Injectionspring cloud gateway10.0 (v3.1)Critical
CVE-2025-34037Linksys Routers E/WAG/WAP/WES/WET/WRT-SeriesE420010.0 (v4.0)Critical
CVE-2025-55182React Server Components - Remote Code Executionreact10.0 (v3.1)Critical
CVE-2026-19188Haiwell IoT Cloud HMI Gateway OS Command InjectionHaiwell IoT Cloud HMI Gateway10.0 (v4.0)Critical
CVE-2026-34234CtrlPanel: Unauthenticated RCE using installer scriptpanel10.0 (v3.1)Critical
CVE-2026-44181Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Executionenterprise gateway10.0 (v4.0)Critical
CVE-2026-49869Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in AuthenticationFilterkestra10.0 (v3.1)Critical
CVE-2026-53753Crawl4AI <= 0.8.6 - Remote Code Executioncrawl4ai10.0 (v3.1)Critical
CVE-2026-81735UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command ExecutiUI-TARS-desktop10.0 (v4.0)Critical
CVE-2026-8984Unauthenticated RCEmaxicharger single charger firmware10.0 (v4.0)Critical
CVE-2026-42454Termix: OS Command Injection in Docker Container Management EndpointsTermix9.9 (v3.1)Critical
CVE-2026-44450Lumiverse: RCE via MCP stdio argument injectionLumiverse9.9 (v3.1)Critical
CVE-2026-45629Dokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket Endpointdokploy9.9 (v3.1)Critical
CVE-2026-45632Dokploy: Schedule Authorization Bypass Enables Host/Server Command Executiondokploy9.9 (v3.1)Critical
CVE-2026-48030Pheditor 2.0.1-2.0.3 - OS Command Injectionpheditor9.9 (v3.1)Critical
CVE-2026-55565Yamcs: Authenticated remote code execution via unescaped StreamSQL LIKE pattern compiled by Janino (LikeExpression)yamcs9.9 (v3.1)Critical
CVE-2026-55634Pimcore: Remote Code Execution via DataObject Class-Definition Field Namepimcore9.9 (v3.1)Critical
CVE-2026-63298LXD arbitrary lxc.conf directive injection via NVIDIA instance configurationlxd9.9 (v3.1)Critical
CVE-2026-72738Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search Parameterdokploy9.9 (v3.1)Critical
CVE-2026-72740Dokploy: OS Command Injection via SSH-form customGitUrl domain in ssh-keyscandokploy9.9 (v3.1)Critical
CVE-2026-72865Dokploy: OS Command Injection via compose composePathdokploy9.9 (v3.1)Critical
CVE-2026-72868Dokploy: Member-role RCE as host root via destination.testConnection rclone shell injectiondokploy9.9 (v3.1)Critical
CVE-2026-72869Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCEdokploy9.9 (v3.1)Critical
CVE-2026-72872Dokploy: OS Command Injection via Bitbucket owner/repository in git clonedokploy9.9 (v3.1)Critical
CVE-2026-72876Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*dokploy9.9 (v3.1)Critical
CVE-2026-72882Dokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed serversdokploy9.9 (v3.1)Critical
CVE-2026-72902Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryByIddokploy9.9 (v3.1)Critical
CVE-2026-73263Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-pathprowler9.9 (v3.1)Critical
CVE-2026-73294Semaphore U: OS Command Injectionsemaphore9.9 (v3.1)Critical
CVE-2026-8481Remote Code Execution via Code Validation Endpointlangflow9.9 (v3.1)Critical
CVE-2013-2251Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Executionstruts9.8 (v3.1)Critical
CVE-2019-12988Citrix SD-WAN Center - Remote Command Injectionnetscaler sd-wan9.8 (v3.0)Critical
CVE-2019-2729Oracle WebLogic Server Administration Console - Remote Code Executioncommunications diameter signaling router9.8 (v3.1)Critical
CVE-2020-11546SuperWebmailer 7.21.0.01526 - Remote Code Executionsuperwebmailer9.8 (v3.1)Critical
CVE-2020-5722Grandstream UCM6200 - SQL Injectionucm6200 firmware9.8 (v3.1)Critical
CVE-2021-36260Hikvision IP camera/NVR - Remote Command Executionds-2cd2026g2-iu/sl firmware9.8 (v3.1)Critical
CVE-2022-22954VMware Workspace ONE Access - Server-Side Template Injectionidentity manager9.8 (v3.1)Critical
CVE-2022-27927Microfinance Management System 1.0 - 'customer_number' SQLimicrofinance management system9.8 (v3.1)Critical
CVE-2022-29303SolarView Compact 6.0 - OS Command Injectionsv-cpt-mc310 firmware9.8 (v3.1)Critical
CVE-2022-40032Simple Task Managing System v1.0 - SQL Injection (Unauthenticated)simple task managing system9.8 (v3.1)Critical
CVE-2022-40347Intern Record System v1.0 - SQL Injection (Unauthenticated)intern record system9.8 (v3.1)Critical
CVE-2022-40881SolarView 6.00 - Remote Command Executionsolarview compact9.8 (v3.1)Critical
CVE-2022-44877Centos Web Panel 7 v0.9.8.1147 - Unauthenticated Remote Code Execution (RCE)webpanel9.8 (v3.1)Critical
CVE-2023-25717Ruckus Wireless Admin - Remote Code Executionruckus wireless admin9.8 (v3.1)Critical
CVE-2023-31465TimeKeeper by FSMLabs - Remote Code Executiontimekeeper9.8 (v3.1)Critical
CVE-2023-3368Chamilo LMS <= v1.11.20 Unauthenticated Command Injectionchamilo9.8 (v3.1)Critical
CVE-2023-4450JeecgBoot JimuReport - Template injectionjeecg9.8 (v3.1)Critical
CVE-2023-46359cPH2 Charging Station v1.87.0 - OS Command Injectioncph2 echarge9.8 (v3.1)Critical
CVE-2024-50603Aviatrix Controller - Remote Code Executioncontroller9.8 (v3.1)Critical
CVE-2025-29306FoxCMS v.1.2.5 - Remote Code Executionfoxcms9.8 (v3.1)Critical
CVE-2026-12940Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpointlangflow9.8 (v3.1)Critical
CVE-2026-15733WGDashboard <= 4.3.2 - Authenticated OS Command Injection /etc/passwd ReadWGDashboard9.8 (v3.1)Critical
CVE-2026-18482neo-mjs Command Injection Vulnerabilityneo-mjs9.8 (v3.1)Critical
CVE-2026-31040stata-mcp Code Injection Vulnerabilitystata-mcp9.8 (v3.1)Critical
CVE-2026-35847the CheckUils.php file Arbitrary Code Execution Vulnerabilitythe CheckUils.php file9.8 (v3.1)Critical
CVE-2026-37281the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 Command Injection Vulnerabilitythe /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.09.8 (v3.1)Critical
CVE-2026-38428kestra SQL Injection Vulnerabilitykestra9.8 (v3.1)Critical
CVE-2026-38431erpnext Code Injection Vulnerabilityerpnext9.8 (v3.1)Critical
CVE-2026-45018Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code executionchainlit9.8 (v3.1)Critical
CVE-2026-45695Kopia Server 0.23.0 - Remote Code Executionkopia9.8 (v3.1)Critical
CVE-2026-46562Yamcs: Remote Code Execution via Mission Database algorithm overrideyamcs9.8 (v3.1)Critical
CVE-2026-47391PraisonAI's unauthenticated A2A official example can reach real LLM-driven eval() tool executionPraisonAI9.8 (v3.1)Critical
CVE-2026-48687fastnetmon Command Injection Vulnerabilityfastnetmon9.8 (v3.1)Critical
CVE-2026-49819UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmdUpSnap9.8 (v3.1)Critical
CVE-2026-53545Termix: Remote Code Execution via Tunnel Disconnect pkill Command InjectionTermix9.8 (v3.1)Critical
CVE-2026-55559Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance)yamcs9.8 (v3.1)Critical
CVE-2026-67919Halo 2.25.4 Arbitrary Code Execution Vulnerability-9.8 (v3.1)Critical
CVE-2026-72592dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Uploadphpfm9.8 (v3.1)Critical
CVE-2026-75411JeecgBoot v3.9.2 Code Injection Vulnerability-9.8 (v3.1)Critical
CVE-2026-75414In AntFlow V2.0.0, ActivitiTest.java Code Injection Vulnerability-9.8 (v3.1)Critical
CVE-2026-79408MetaGPT 0.8.1 Command Injection VulnerabilityMetaGPT 0.8.19.8 (v3.1)Critical
CVE-2026-8037Progress ADC LoadMaster - Command Injectionconnection manager for objectscale9.8 (v3.1)Critical
CVE-2026-84372Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connectionspredis9.8 (v3.1)Critical
CVE-2026-34449SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injectionsiyuan9.6 (v3.1)Critical
CVE-2026-35906An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 OS Command Injection Vulnerability-9.6 (v3.1)Critical
CVE-2026-53649Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCEjoro9.6 (v3.1)Critical
CVE-2026-72878Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell argumentsdokploy9.6 (v3.1)Critical
CVE-2026-70477Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerabilityflowise9.5 (v4.0)Critical
CVE-2026-88062OmniRoute ACP Custom-Agent Remote Code Execution (RCE)OmniRoute9.5 (v4.0)Critical
CVE-2025-34152Shenzhen Aitemi M300 Wi-Fi Repeater – Unauthenticated Remote Command Execution via time ParameterM300 Wi-Fi Repeater9.4 (v4.0)Critical
CVE-2025-62593Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attackray9.4 (v4.0)Critical
CVE-2026-33324SQLBot prompt injection allows arbitrary SQL execution and remote code executionsqlbot9.4 (v4.0)Critical
CVE-2026-39932OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injectionopenemr9.4 (v4.0)Critical
CVE-2026-45272MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config Filetalebook9.4 (v4.0)Critical
CVE-2026-47670DbGate - Remote Code Execution via Dynamic Import Bypassdbgate9.4 (v4.0)Critical
CVE-2026-637329router before 0.4.60 Remote Code Execution via default password9router9.4 (v4.0)Critical
CVE-2026-66398phpMyFAQ before 4.1.6 Remote Code Execution via Configuration APIphpMyFAQ9.4 (v4.0)Critical
CVE-2026-69256Flowise: Remote Code Execution Vulnerability in CSVAgentFlowise9.4 (v4.0)Critical
CVE-2026-72879Dokploy: Command Injection via Registry Credentials in Swarm Uploaddokploy9.4 (v4.0)Critical
CVE-2026-73041SiYuan before v3.7.4 Remote Code Execution via PDF Annotationssiyuan9.4 (v4.0)Critical
CVE-2026-73042SiYuan before v3.7.4 Remote Code Execution via Menu Metadatasiyuan9.4 (v4.0)Critical
CVE-2026-73483Flowise before 3.1.3 Sandbox Escape via Puppeteerflowise9.4 (v4.0)Critical
CVE-2026-82244Budibase before 3.41.3 Remote Code Execution via Plugin eval()server9.4 (v4.0)Critical
CVE-2019-25687Pegasus CMS 1.0 Remote Code Execution via extra_fields.phppegasus cms9.3 (v4.0)Critical
CVE-2024-58348WordPress Background Image Cropper 1.2 Remote Code ExecutionBackground Image Cropper9.3 (v4.0)Critical
CVE-2025-2611ICTBroadcast - Command InjectionICTBroadcast9.3 (v4.0)Critical
CVE-2025-31114Fooocus webui vulnerable to Remote Code ExecutionFooocus9.3 (v4.0)Critical
CVE-2025-32778Web-Check < 2.0.1 Screenshot API - OS Command Injectionweb-check9.3 (v4.0)Critical
CVE-2026-19586Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gatewayser7212pc firmware9.3 (v4.0)Critical
CVE-2026-29014MetInfo CMS <= 8.1 - Remote Code Executionmetinfo9.3 (v4.0)Critical
CVE-2026-41939Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFlyCare Everywhere Gateway9.3 (v4.0)Critical
CVE-2026-44402Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgiSNMP Web Pro9.3 (v4.0)Critical
CVE-2026-53975OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/execOpenChamber9.3 (v4.0)Critical
CVE-2026-58138Orkes Conductor 3.21.21-3.30.1 - Remote Code Executionconductor9.3 (v4.0)Critical
CVE-2026-59111Command Injection vulnerability in eObčanka-IdentifikaceeObčanka-Identifikace9.3 (v3.1)Critical
CVE-2026-60121Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.phpflamingo9.3 (v4.0)Critical
CVE-2026-61498Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.phpflamingo9.3 (v4.0)Critical
CVE-2026-61511vBulletin 6.x - Remote Code ExecutionvBulletin9.3 (v4.0)Critical
CVE-2026-63766GPT-SoVITS 20250606v2pro OS Command Injection via webui.pyGPT-SoVITS9.3 (v4.0)Critical
CVE-2026-64625AVideo before 29.0 OS Command Injection via execAsyncAVideo9.3 (v4.0)Critical
CVE-2026-64824Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restoreHome Assistant Core9.3 (v4.0)Critical
CVE-2026-65008Grav before 2.0.7 Remote Code Execution via Blueprint dynamicDatagrav9.3 (v4.0)Critical
CVE-2026-67308Wazuh GitHub Actions Shell Injection via Fork Pull Requestwazuh9.3 (v4.0)Critical
CVE-2026-70553MaxSite CMS Unauthenticated RCE via Install EndpointMaxSite CMS9.3 (v4.0)Critical
CVE-2026-71921DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgiVigorSwitch G2540xs9.3 (v4.0)Critical
CVE-2026-71944D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectelDWR-M9619.3 (v4.0)Critical
CVE-2026-71945D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocomDWR-M9619.3 (v4.0)Critical
CVE-2026-71946D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRunDWR-M9619.3 (v4.0)Critical
CVE-2026-71947D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRunDWR-M9619.3 (v4.0)Critical
CVE-2026-71948D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRunDWR-M9619.3 (v4.0)Critical
CVE-2026-71949D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetupDWR-M9619.3 (v4.0)Critical
CVE-2026-71950D-Link DWR-M961 Command Injection via /boafrm/formSmsManageDWR-M9619.3 (v4.0)Critical
CVE-2026-71951D-Link DWR-M961 Command Injection via /boafrm/formIMEISetupDWR-M9619.3 (v4.0)Critical
CVE-2026-71952D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetupDWR-M9619.3 (v4.0)Critical
CVE-2026-71953D-Link DWR-M961 Command Injection via /boafrm/formNtpDWR-M9619.3 (v4.0)Critical
CVE-2026-71954D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetupDWR-M9619.3 (v4.0)Critical
CVE-2026-71955D-Link DWR-M961 Command Injection via /boafrm/formWscDWR-M9619.3 (v4.0)Critical
CVE-2026-71956D-Link DWR-M961 Command Injection via app.cgiDWR-M9619.3 (v4.0)Critical
CVE-2026-71984MSI Radix AXE6600 v781521 Command Injection via urlfilterRadix AXE66009.3 (v4.0)Critical
CVE-2026-71992MSI Radix AXE6600 v781521 Command Injection via macfilterRadix AXE66009.3 (v4.0)Critical
CVE-2026-72710SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue InjectionSPIP9.3 (v4.0)Critical
CVE-2026-76070Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password ParameterNC639.3 (v4.0)Critical
CVE-2026-76071Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost ParameterNC639.3 (v4.0)Critical
CVE-2023-7305SmartBI RMIServlet Unrestricted File Upload RCESmartBI9.2 (v4.0)Critical
CVE-2026-63304AVideo through 29.0 OS Command Injection via listFFmpegProcessesAVideo9.2 (v4.0)Critical
CVE-2026-63305AVideo through 29.0 OS Command Injection via ffmpeg.json.phpAVideo9.2 (v4.0)Critical
CVE-2026-80138ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameterclipbucket-v59.2 (v4.0)Critical
CVE-2026-46621Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injectionyamcs9.1 (v3.1)Critical
CVE-2026-55511Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs executeSqlyamcs9.1 (v3.1)Critical
CVE-2026-57499Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE)core9.1 (v3.1)Critical
CVE-2026-58400GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formattercore-geonetwork9.1 (v3.1)Critical
CVE-2021-45046Apache Log4j2 - Remote Code Injectionlog4j9.0 (v3.1)Critical
CVE-2026-34612Kestra: Remote Code Execution via SQL Injectionkestra9.0 (v3.1)Critical
CVE-2026-45630Dokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo Statementdokploy9.0 (v3.1)Critical
CVE-2026-62674Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCEomnigent9.0 (v3.1)Critical
CVE-2026-69251Flowise RCE via TypeORM DataSourceFlowise9.0 (v4.0)Critical
CVE-2026-73485Flowise before 3.1.3 Remote Code Execution via Airtable Agentflowise9.0 (v4.0)Critical
CVE-2026-73486Flowise before 3.1.3 Code Injection via CSV Agent customReadCSVflowise9.0 (v4.0)Critical
CVE-2026-73487Flowise before 3.1.3 Prompt Injection RCE via CSV Agentflowise9.0 (v4.0)Critical
CVE-2026-43945FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration InjectionFUXA8.9 (v4.0)High
CVE-2026-7202Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injectionA8000RU8.9 (v4.0)High
CVE-2026-7203Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injectionA8000RU8.9 (v4.0)High
CVE-2026-7204Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-73570zimbra collaboration suite Arbitrary Code Execution Vulnerabilityzimbra collaboration suite8.9 (v3.1)High
CVE-2026-9384Totolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9385Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9386Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9387Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9388Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9404Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9405Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9406Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9407Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9408Totolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9432Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9433Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9434Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9435Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9436Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9454Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9455Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9456Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9457Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9458Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9476Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9477Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injectionA8000RU8.9 (v4.0)High
CVE-2026-9478Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injectionA8000RU8.9 (v4.0)High
CVE-2016-4977Spring Security OAuth2 Remote Command Executionspring security oauth8.8 (v3.0)High
CVE-2017-6884Zyxel_ EMG2926 < V1.00(AAQT.4)b8 - OS Command Injectionemg2926 firmware8.8 (v3.1)High
CVE-2020-15874Command Injection-8.8 (v3.1)High
CVE-2020-24949PHP-Fusion 9.03.50 - Remote Code Executionphp-fusion8.8 (v3.1)High
CVE-2021-3577Motorola Baby Monitors - Remote Command Executionhalo+ camera firmware8.8 (v3.1)High
CVE-2022-4223pgAdmin < 6.17 - Unauthenticated Remote Code Executionpgadmin 48.8 (v3.1)High
CVE-2023-1389TP-Link Archer AX21 (AX1800) - Unauthenticated Command Injectionarcher-ax218.8 (v3.1)High
CVE-2024-39024In Packetfence 13.2.0, the WebGui interface setting Arbitrary Code Execution Vulnerability-8.8 (v3.1)High
CVE-2024-41667OpenAM<=15.0.3 FreeMarker - Template InjectionOpenAM8.8 (v3.1)High
CVE-2025-56798Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier Cross-Site Request Forgery VulnerabilityLime Technology, Inc.'s Unraid OS version 6.12.14 and earlier8.8 (v3.1)High
CVE-2025-59710biztalk360 Arbitrary Code Execution Vulnerabilitybiztalk3608.8 (v3.1)High
CVE-2026-24893openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansionopenitcockpit8.8 (v3.1)High
CVE-2026-26899OS Command Injection-8.8 (v3.1)High
CVE-2026-34197Apache ActiveMQ - Remote Code Executionactivemq8.8 (v3.1)High
CVE-2026-35031Jellyfin: Potential RCE via subtitle upload path traversal + .strm chainjellyfin8.8 (v3.1)High
CVE-2026-35196Chamilo LMS has OS Command Injection via export_all_certificates actionchamilo lms8.8 (v3.1)High
CVE-2026-45505Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia addNetworkConnector Discovery Wrapper Bypassactivemq8.8 (v3.1)High
CVE-2026-45578WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URLavideo8.8 (v3.1)High
CVE-2026-45662Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion)dokploy8.8 (v3.1)High
CVE-2026-48017DbGate: Remote Code Execution via functionName injection in loadReader endpointdbgate8.8 (v3.1)High
CVE-2026-55585QWED: Authenticated Remote Code Execution via Unsafe SymPy parse_expr()qwed-verification8.8 (v3.1)High
CVE-2026-58195Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into exagentic-flow8.8 (v3.1)High
CVE-2026-62675Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Toolsomnigent8.8 (v3.1)High
CVE-2026-72875Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFiledokploy8.8 (v3.1)High
CVE-2026-73222Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (–studio)claude-code-templates8.8 (v3.1)High
CVE-2026-78834Code Injection-8.8 (v3.1)High
CVE-2026-79423seacms v13.6 Arbitrary Code Execution Vulnerabilityseacms v13.68.8 (v3.1)High
CVE-2026-82217Eclipse Theia Path Traversal VulnerabilityEclipse Theia8.8 (v3.1)High
CVE-2019-25671VA MAX 8.3.4 Remote Code Execution via changeip.phpVA MAX8.7 (v4.0)High
CVE-2021-47943TextPattern CMS 4.8.7 Remote Code Execution via File UploadTextPattern CMS8.7 (v4.0)High
CVE-2022-50944Aero CMS 0.0.1 PHP Code Injection via posts.phpAero CMS8.7 (v4.0)High
CVE-2023-54350WordPress Augmented-Reality Plugin Remote Code Execution UnauthenticatedAugmented Reality8.7 (v4.0)High
CVE-2025-30007HestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record Managementcontrol panel8.7 (v4.0)High
CVE-2025-34115OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.phpOP5 Monitor8.7 (v4.0)High
CVE-2025-4008MeteoBridge <= 6.1 - Remote Code Executionmeteobridge vm8.7 (v4.0)High
CVE-2026-28797RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Componeragflow8.7 (v4.0)High
CVE-2026-34228Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Writeemlog8.7 (v4.0)High
CVE-2026-34735Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileControllerwiki8.7 (v4.0)High
CVE-2026-34792Endian Firewall /cgi-bin/logs_clamav.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34793Endian Firewall /cgi-bin/logs_firewall.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34794Endian Firewall /cgi-bin/logs_ids.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34795Endian Firewall /cgi-bin/logs_log.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34796Endian Firewall /cgi-bin/logs_openvpn.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-34797Endian Firewall /cgi-bin/logs_smtp.cgi DATE Perl Command Injectionfirewall community8.7 (v4.0)High
CVE-2026-46746sinec ins OS Command Injection Vulnerabilitysinec ins8.7 (v4.0)High
CVE-2026-49143BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handlerbrowserstack-runner8.7 (v4.0)High
CVE-2026-63722ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.phpICEcoder8.7 (v4.0)High
CVE-2026-64850Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()grav8.7 (v4.0)High
CVE-2026-67206Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Uploadwolfcms8.7 (v4.0)High
CVE-2026-69096OpenWrt luci-app-dockerman Read ACL Remote Code Executionluci8.7 (v4.0)High
CVE-2026-69100LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Executionlamp-cloud8.7 (v4.0)High
CVE-2026-71966CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfercyberpanel8.7 (v4.0)High
CVE-2026-72819Grav CMS before 2.0.13 Remote Code Execution via ZIP Uploadgrav8.7 (v4.0)High
CVE-2026-72827Grav CMS before 2.0.13 Remote Code Execution via Twiggrav8.7 (v4.0)High
CVE-2026-72830Grav API Plugin before 1.0.13 RCE via ConfigController scope bypassgrav8.7 (v4.0)High
CVE-2026-72870Dokploy: Command Injection via Docker Credentials in buildRemoteDockerdokploy8.7 (v4.0)High
CVE-2026-72874Dokploy: Command Injection via Unescaped Git URL in Clone Commandsdokploy8.7 (v4.0)High
CVE-2026-73680Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg FilenameCockpit CMS8.7 (v4.0)High
CVE-2026-76060OS Command Injection in PayRange APIZoneminder8.7 (v4.0)High
CVE-2026-76836AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group BypassAzuraCast8.7 (v4.0)High
CVE-2026-78416Authenticated RCE via condition.config JSON cleanse bypasscms8.7 (v4.0)High
CVE-2026-79756Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platformnuclio8.7 (v4.0)High
CVE-2026-79987Low-privilege RCE through element-search eager loadingcms8.7 (v4.0)High
CVE-2026-82278BISHENG Authenticated Arbitrary Python Code Execution via Workflow run_oncebisheng8.7 (v4.0)High
CVE-2026-85604Grav before 2.0.19 Remote Code Execution via sort filtergrav8.7 (v4.0)High
CVE-2026-85610OpenPanel before 2.3.0 Remote Code Execution via chart formulasopenpanel8.7 (v4.0)High
CVE-2026-86732Craft CMS before 5.10.12 Remote Code Execution via element-indexcms8.7 (v4.0)High
CVE-2023-47105Chaosblade < 1.7.4 - Remote Code Executionchaosblade8.6 (v3.1)High
CVE-2024-20353adaptive security appliance software Denial of Service Vulnerabilityadaptive security appliance software8.6 (v3.1)High
CVE-2026-40187Authenticated RCE via Malicious eTemplate Upload in EGroupwareegroupware8.6 (v4.0)High
CVE-2026-42785OpenKM 6.3.12 Remote Code Execution via Administrative ScriptingOpenKM Community Edition8.6 (v4.0)High
CVE-2026-53804OTRS Community Edition OS Command Injection via PGP ConfigurationOTRS Community Edition8.6 (v4.0)High
CVE-2026-55182LibreNMS: Remote Code Execution by Signal Alert Transportation Modulelibrenms8.6 (v4.0)High
CVE-2026-56703Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTOadminer8.6 (v4.0)High
CVE-2026-5917libgit2 Shell Command Injection via ssh_libssh2 Backendlibgit28.6 (v4.0)High
CVE-2026-61517Netis NX10 OS Command Injection via Ping Diagnostic HandlerNX108.6 (v4.0)High
CVE-2026-61523WebsiteBaker CMS < 2.13.10 Code Injection via Droplets EditorWebsiteBaker CMS8.6 (v4.0)High
CVE-2026-63725sysPass FileBackupService Authenticated OS Command Injection via Backup PathsysPass8.6 (v4.0)High
CVE-2026-65693Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templatesmicroweber8.6 (v4.0)High
CVE-2026-65711sysPass 3.2.11 Authenticated OS Command Injection via Backup PathsysPass8.6 (v4.0)High
CVE-2026-67599ClearOS 7.9 OS Command Injection via Log Viewer filter parameterClearOS8.6 (v4.0)High
CVE-2026-69088Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprintgrav8.6 (v4.0)High
CVE-2026-71906DrayTek VigorAP Multiple Models OS Command Injection via setLanVigorAP 918R8.6 (v4.0)High
CVE-2026-71907DrayTek VigorAP Multiple Models OS Command Injection via setcamsetVigorAP 918R8.6 (v4.0)High
CVE-2026-71908DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_testVigorAP 918R8.6 (v4.0)High
CVE-2026-71913DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgiVigorAP 918R8.6 (v4.0)High
CVE-2026-71915DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatusVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71918DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupActionVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71919DrayTek VigorSwitch Multiple Models OS Command Injection via sysrebootVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71923DrayTek VigorSwitch Multiple Models OS Command Injection via auth_setVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71924DrayTek VigorSwitch Multiple Models OS Command Injection via getVidVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71925DrayTek VigorSwitch Multiple Models OS Command Injection via getDetailVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71926DrayTek VigorSwitch Multiple Models OS Command Injection via setDeviceVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71927DrayTek VigorSwitch Multiple Models OS Command Injection via rebDeviceVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71928DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDeviceVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71929DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProtoVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71930DrayTek VigorSwitch Multiple Models OS Command Injection via setTimeVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71931DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgradeVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-71943DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNetVigorSwitch G2540xs8.6 (v4.0)High
CVE-2026-73664FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Modulebackup8.6 (v4.0)High
CVE-2026-75121PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_postPLANET GS-4210-16P2S V38.6 (v4.0)High
CVE-2026-75122PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgiPLANET GS-4210-16P2S V38.6 (v4.0)High
CVE-2026-75123PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_postPLANET GS-4210-16P2S V38.6 (v4.0)High
CVE-2026-80214LibreNMS Virtualisation Discovery Module RCElibrenms8.6 (v4.0)High
CVE-2026-82692D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injectionDNS-340L8.6 (v4.0)High
CVE-2026-84194LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostnamelibrenms8.6 (v4.0)High
CVE-2026-85223D-Link DNS-340L CGI dropbox.cgi os command injectionDNS-340L8.6 (v4.0)High
CVE-2026-86299Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injectionRE70008.6 (v4.0)High
CVE-2026-86438Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Actionlaradashboard8.6 (v4.0)High
CVE-2026-86733Snipe-IT before 8.7.0 Remote Code Execution via Backup Restoresnipe-it8.6 (v4.0)High
CVE-2026-22244OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCEopenmetadata8.5 (v4.0)High
CVE-2026-82690D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injectionDNS-327L8.5 (v4.0)High
CVE-2026-82691D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injectionDNS-320L8.5 (v4.0)High
CVE-2026-85222D-Link DNS-340L Add-On Center addon_center.cgi os command injectionDNS-340L8.5 (v4.0)High
CVE-2026-85224D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injectionDNS-320 ShareCenter8.5 (v4.0)High
CVE-2025-59711biztalk360 Path Traversal Vulnerabilitybiztalk3608.3 (v3.1)High
CVE-2026-49471Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCEserena8.3 (v3.1)High
CVE-2025-69755Neterbit NW-431F Router vNW-431F-20241014-IR03 Arbitrary Code Execution Vulnerability-8.2 (v3.1)High
CVE-2018-6961VMware NSX SD-WAN Edge - Command Injectionnsx sd-wan edge8.1 (v3.1)High
CVE-2026-42588Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnectoractivemq8.1 (v3.1)High
CVE-2026-45344LinkAce: Setup database password newline injection enables pre-auth RCE on uninitialized instancesLinkAce8.1 (v3.1)High
CVE-2026-47398PraisonAI: Arbitrary code execution via unguarded spec.loader.exec_module in agents_generator.py - sibling of CVE-20PraisonAI8.1 (v3.1)High
CVE-2026-48695fastnetmon Command Injection Vulnerabilityfastnetmon8.1 (v3.1)High
CVE-2026-71320Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Propsnuxt8.1 (v3.1)High
CVE-2026-79755Nuclio: Unauthenticated OS command injection via function namespace in docker ps –filter label (local Docker platform)nuclio8.0 (v3.1)High
CVE-2021-21315Node.JS System Information Library <5.3.1 - Remote Command Injectionsysteminformation7.8 (v3.1)High
CVE-2026-67179Genkit improper host header validationgenkit7.8 (v3.1)High
CVE-2025-27621UpTrain has a Constant Default API Keyuptrain7.7 (v4.0)High
CVE-2019-16469Adobe Experience Manager - Expression Language Injectionexperience manager7.5 (v3.1)High
CVE-2025-4427Ivanti Endpoint Manager Mobile - Unauthenticated Remote Code Executionendpoint manager mobile7.5 (v3.1)High
CVE-2026-34239Chamilo Authenticated Remote Code Executionchamilo-lms7.5 (v4.0)High
CVE-2026-36783Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to Denial of Service Vulnerability-7.5 (v3.1)High
CVE-2026-36796Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to Denial of Service Vulnerability-7.5 (v3.1)High
CVE-2026-46581mojarra Path Traversal Vulnerabilitymojarra7.5 (v3.1)High
CVE-2026-51078Dede CMS v.5.7.118 Information Disclosure Vulnerability-7.5 (v3.1)High
CVE-2026-53599Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mocore7.5 (v3.1)High
CVE-2026-10870Shibby Tomato Web UI rc start_dhcpc os command injectionTomato7.3 (v4.0)High
CVE-2026-10871Shibby Tomato Web UI rc start_6rd_tunnel os command injectionTomato7.3 (v4.0)High
CVE-2026-10873Shibby Tomato Web UI rstats rstats_path os command injectionTomato7.3 (v4.0)High
CVE-2026-18900H3C NX15 Backend RPC esps file.exec os command injectionNX157.3 (v4.0)High
CVE-2026-19771Baicells EG3661M LuCI Web luci os command injectionEG3661M7.3 (v4.0)High
CVE-2021-33544Geutebruck - Remote Command Injectiong-cam ebc-21107.2 (v3.1)High
CVE-2025-32813Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_requestnetmri7.2 (v3.1)High
CVE-2026-13392ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite)ElementsKit Elementor Addons7.2 (v3.1)High
CVE-2026-15686Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution VulnerabilityAdminer7.2 (v3.0)High
CVE-2026-27891Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanismfacturascripts7.2 (v3.1)High
CVE-2026-28409WeGIA <= 3.6.4 - Remote Code Executionwegia7.2 (v3.1)High
CVE-2026-71284Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filenamefledge7.2 (v3.1)High
CVE-2026-71964CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Uploadcyberpanel7.1 (v4.0)High
CVE-2026-77939Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpointflextype7.1 (v4.0)High
CVE-2024-12987DrayTek Vigor - Command InjectionVigor300B6.9 (v4.0)Medium
CVE-2026-11450GL.iNet GL-MT3000 Path Normalization dlopen command injectionGL-MT30006.9 (v4.0)Medium
CVE-2026-19983GL.iNet XE3000 NAS Command Service gl_nas_sys os command injectionA13006.9 (v4.0)Medium
CVE-2026-5739PowerJob OpenAPI Endpoint addWorkflowNode GroovyEvaluator.evaluate code injectionPowerJob6.9 (v4.0)Medium
CVE-2025-59709biztalk360 Path Traversal Vulnerabilitybiztalk3606.8 (v3.1)Medium
CVE-2026-34216CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in SettingsController.phppanel6.6 (v3.1)Medium
CVE-2026-72739Dokploy: Command Injection via Compose Shell Executiondokploy6.5 (v3.1)Medium
CVE-2026-44287FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*(/ is bypassableFastGPT6.3 (v3.1)Medium
CVE-2026-45626Arcane: OS Command Injection in Volume Browser ListDirectory via path query parameterarcane6.3 (v3.1)Medium
CVE-2023-5244Microweber < V.2.0 - Cross-Site Scriptingmicroweber6.1 (v3.1)Medium
CVE-2025-13786taosir WTCMS index.php fetch code injectionwtcms5.5 (v4.0)Medium
CVE-2025-13792Qualitor getResumo.php eval code injectionthe file /html/st/stdeslocamento/request/getResumo.php5.5 (v4.0)Medium
CVE-2026-10214zhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injectionchatgpt-on-wechat5.5 (v4.0)Medium
CVE-2026-11474Kushan2k student-management-system Registration Endpoint RegisterService.php unrestricted uploadstudent-management-system5.5 (v4.0)Medium
CVE-2026-18641Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginCOperation and Maintenance Security Management System5.5 (v4.0)Medium
CVE-2026-19379EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injectionipTIME AX8004M5.5 (v4.0)Medium
CVE-2026-54611InstantCMS has Remote Code Execution in package installericms25.5 (v3.1)Medium
CVE-2026-5631assafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injectiongpt-researcher5.5 (v4.0)Medium
CVE-2026-5677Totolink A7100RU cstecgi.cgi CsteSystem os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5678Totolink A7100RU cstecgi.cgi setScheduleCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5688Totolink A7100RU cstecgi.cgi setDdnsCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5689Totolink A7100RU cstecgi.cgi setNtpCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5690Totolink A7100RU cstecgi.cgi setRemoteCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5691Totolink A7100RU cstecgi.cgi setFirewallType os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5692Totolink A7100RU cstecgi.cgi setGameSpeedCfg os command injectionA7100RU5.5 (v4.0)Medium
CVE-2026-5736PowerJob detailPlus Endpoint InstanceController.java sql injectionPowerJob5.5 (v4.0)Medium
CVE-2026-5741suvarchal docker-mcp-server HTTP index.ts pull_image os command injectiondocker-mcp-server5.5 (v4.0)Medium
CVE-2026-5802idachev mcp-javadc HTTP os command injectionmcp-javadc5.5 (v4.0)Medium
CVE-2026-7220jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injectionFastlyMCP5.5 (v4.0)Medium
CVE-2026-76760chenhg5 cc-connect webhook.go authenticate code injectioncc-connect5.5 (v4.0)Medium
CVE-2026-76761chenhg5 cc-connect Management API engine.go shellExecCommand os command injectioncc-connect5.5 (v4.0)Medium
CVE-2026-82598SeaCMS Template search.php parseIf code injectionSeaCMS5.5 (v4.0)Medium
CVE-2026-85137SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injectionSeaCMS5.5 (v4.0)Medium
CVE-2026-9474yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injectionStudentManagementSystem5.5 (v4.0)Medium
CVE-2026-54543Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fieldsfroxlor5.4 (v3.1)Medium
CVE-2023-7299DataGear resolveSql sql injectiondatagear5.3 (v4.0)Medium
CVE-2026-19785francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injectionRosarioSIS5.3 (v4.0)Medium
CVE-2026-5547Tenda AC10 httpd formAddMacfilterRule os command injectionac10 firmware5.3 (v4.0)Medium
CVE-2011-0518LotusCMS 3.0 - Remote Code Executionfraise5.1 (v2.0)Medium
CVE-2026-10172Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted uploadMulti-Store Inventory Management System2.1 (v4.0)Low
CVE-2026-10279hiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injectionwezterm-mcp2.1 (v4.0)Low
CVE-2026-11408vertex-app vertex Log Viewer Endpoint LogMod.js os command injectionvertex2.1 (v4.0)Low
CVE-2026-19932DefaultFuction Notice-System-Managent NoticeController execute GroovyShell.evaluate code injectionNotice-System-Managent2.1 (v4.0)Low
CVE-2026-19958iatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injectionpptr-mcp2.1 (v4.0)Low
CVE-2026-5351Trendnet TEW-657BRM setup.cgi add_wps_client os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5352Trendnet TEW-657BRM setup.cgi edit os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5353Trendnet TEW-657BRM setup.cgi ping_test os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5354Trendnet TEW-657BRM setup.cgi vpn_connect os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-5355Trendnet TEW-657BRM setup.cgi vpn_drop os command injectiontew-657brm firmware2.1 (v4.0)Low
CVE-2026-78166provectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest code injectionkafka-ui2.1 (v4.0)Low
CVE-2026-8188Wavlink NU516U1 adm.cgi change_wifi_password os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8189Wavlink NU516U1 adm.cgi wzdrepeater os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8190Wavlink NU516U1 adm.cgi wan os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8191Wavlink NU516U1 adm.cgi wifi_region os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8192Wavlink NU516U1 adm.cgi wzdap os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8227Wavlink NU516U1 adm.cgi wzdapMesh os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8228Wavlink NU516U1 wireless.cgi advance os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8229Wavlink NU516U1 wireless.cgi WifiBasic os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8230Wavlink NU516U1 login.cgi sys_login1 os command injectionwl-nu516u1 firmware2.1 (v4.0)Low
CVE-2026-8264Tenda AC6 httpd WifiApScan formWifiApScan os command injectionac6 firmware2.1 (v4.0)Low
CVE-2026-9302546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injectionvps-inventory-monitoring2.1 (v4.0)Low
CVE-2026-9343Edimax EW-7438RPn webs formWpsStart os command injectionEW-7438RPn2.1 (v4.0)Low
CVE-2026-9347Edimax EW-7438RPn webs formWizSurvey os command injectionEW-7438RPn2.1 (v4.0)Low
CVE-2026-9424Edimax EW-7438RPn Content-Type formWlanMP os command injectionEW-7438RPn2.1 (v4.0)Low
CVE-2026-9511Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9512Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9514Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9515Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9531Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9532Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9533Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-9534Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injectionCA750-PoE2.1 (v4.0)Low
CVE-2026-19964Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injectionJij-MCP-Server2.0 (v4.0)Low
CVE-2026-81835RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions code injectionRoo-Code2.0 (v4.0)Low
CVE-2026-8259Tenda AC6 httpd telnet os command injectionac6 firmware2.0 (v4.0)Low
CVE-2026-8265Tenda AC6 httpd getLogFile get_log_file os command injectionac6 firmware2.0 (v4.0)Low
CVE-2026-82702Edimax BR-6214K asp_WlanMP Endpoint wlanMP.asp system os command injectionBR-6214K2.0 (v4.0)Low
CVE-2026-82703Edimax BR-6214K asp_setPing Endpoint ping.asp system os command injectionBR-6214K2.0 (v4.0)Low
CVE-2026-85040ZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injectionCRMEB2.0 (v4.0)Low
CVE-2026-16129princezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklistSafestClaw1.9 (v4.0)Low
CVE-2026-5621ChrisChinchilla Vale-MCP HTTP index.ts os command injectionVale-MCP1.9 (v4.0)Low

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-19CVE-2016-4977
CWE-20CVE-2021-44228 , CVE-2026-57499 , CVE-2026-24893 , CVE-2026-34197 , CVE-2026-35031 , CVE-2026-45505 , CVE-2025-34115 , CVE-2026-28797 , CVE-2026-42588 , CVE-2026-27891
CWE-22CVE-2019-25687 , CVE-2026-64824 , CVE-2026-35031 , CVE-2026-82217 , CVE-2019-25671 , CVE-2025-59711 , CVE-2026-46581 , CVE-2025-59709 , CVE-2011-0518
CWE-59CVE-2026-71964
CWE-74CVE-2013-2251 , CVE-2023-4450 , CVE-2026-45344 , CVE-2026-71320 , CVE-2026-11450 , CVE-2026-5739 , CVE-2025-13786 , CVE-2025-13792 , CVE-2026-5631 , CVE-2026-5736 , CVE-2026-76760 , CVE-2026-82598 , CVE-2026-85137 , CVE-2026-9474 , CVE-2026-54543 , CVE-2023-7299 , CVE-2026-19785 , CVE-2026-19932 , CVE-2026-19958 , CVE-2026-78166 , CVE-2026-9302 , CVE-2026-19964 , CVE-2026-81835
CWE-77CVE-2026-72869 , CVE-2022-40881 , CVE-2026-35847 , CVE-2026-8037 , CVE-2026-47670 , CVE-2026-7202 , CVE-2026-7203 , CVE-2026-7204 , CVE-2026-9384 , CVE-2026-9385 , CVE-2026-9386 , CVE-2026-9387 , CVE-2026-9388 , CVE-2026-9404 , CVE-2026-9405 , CVE-2026-9406 , CVE-2026-9407 , CVE-2026-9408 , CVE-2026-9432 , CVE-2026-9433 , CVE-2026-9434 , CVE-2026-9435 , CVE-2026-9436 , CVE-2026-9454 , CVE-2026-9455 , CVE-2026-9456 , CVE-2026-9457 , CVE-2026-9458 , CVE-2026-9476 , CVE-2026-9477 , CVE-2026-9478 , CVE-2020-15874 , CVE-2023-1389 , CVE-2025-4008 , CVE-2026-55182 , CVE-2026-82692 , CVE-2026-85223 , CVE-2026-86299 , CVE-2026-82690 , CVE-2026-82691 , CVE-2026-85222 , CVE-2026-85224 , CVE-2026-10870 , CVE-2026-10871 , CVE-2026-10873 , CVE-2026-18900 , CVE-2026-19771 , CVE-2025-32813 , CVE-2024-12987 , CVE-2026-11450 , CVE-2026-19983 , CVE-2026-10214 , CVE-2026-18641 , CVE-2026-19379 , CVE-2026-5677 , CVE-2026-5678 , CVE-2026-5688 , CVE-2026-5689 , CVE-2026-5690 , CVE-2026-5691 , CVE-2026-5692 , CVE-2026-5741 , CVE-2026-5802 , CVE-2026-7220 , CVE-2026-76761 , CVE-2026-5547 , CVE-2026-10279 , CVE-2026-11408 , CVE-2026-5351 , CVE-2026-5352 , CVE-2026-5353 , CVE-2026-5354 , CVE-2026-5355 , CVE-2026-8188 , CVE-2026-8189 , CVE-2026-8190 , CVE-2026-8191 , CVE-2026-8192 , CVE-2026-8227 , CVE-2026-8228 , CVE-2026-8229 , CVE-2026-8230 , CVE-2026-8264 , CVE-2026-9343 , CVE-2026-9347 , CVE-2026-9424 , CVE-2026-9511 , CVE-2026-9512 , CVE-2026-9514 , CVE-2026-9515 , CVE-2026-9531 , CVE-2026-9532 , CVE-2026-9533 , CVE-2026-9534 , CVE-2026-8259 , CVE-2026-8265 , CVE-2026-82702 , CVE-2026-82703 , CVE-2026-85040 , CVE-2026-5621
CWE-78CVE-2025-34037 , CVE-2026-19188 , CVE-2026-34234 , CVE-2026-49869 , CVE-2026-42454 , CVE-2026-45629 , CVE-2026-45632 , CVE-2026-48030 , CVE-2026-63298 , CVE-2026-72738 , CVE-2026-72740 , CVE-2026-72865 , CVE-2026-72868 , CVE-2026-72869 , CVE-2026-72872 , CVE-2026-72876 , CVE-2026-72882 , CVE-2026-72902 , CVE-2026-73263 , CVE-2026-73294 , CVE-2019-12988 , CVE-2021-36260 , CVE-2022-29303 , CVE-2022-44877 , CVE-2023-3368 , CVE-2023-46359 , CVE-2024-50603 , CVE-2026-12940 , CVE-2026-15733 , CVE-2026-18482 , CVE-2026-37281 , CVE-2026-45018 , CVE-2026-45695 , CVE-2026-48687 , CVE-2026-49819 , CVE-2026-53545 , CVE-2026-79408 , CVE-2026-35906 , CVE-2026-72878 , CVE-2025-34152 , CVE-2026-47670 , CVE-2026-63732 , CVE-2026-72879 , CVE-2026-73483 , CVE-2025-2611 , CVE-2025-32778 , CVE-2026-19586 , CVE-2026-53975 , CVE-2026-59111 , CVE-2026-60121 , CVE-2026-61498 , CVE-2026-63766 , CVE-2026-64625 , CVE-2026-67308 , CVE-2026-71921 , CVE-2026-71944 , CVE-2026-71945 , CVE-2026-71946 , CVE-2026-71947 , CVE-2026-71948 , CVE-2026-71949 , CVE-2026-71950 , CVE-2026-71951 , CVE-2026-71952 , CVE-2026-71953 , CVE-2026-71954 , CVE-2026-71955 , CVE-2026-71956 , CVE-2026-71984 , CVE-2026-71992 , CVE-2026-63304 , CVE-2026-63305 , CVE-2026-80138 , CVE-2026-57499 , CVE-2026-45630 , CVE-2026-7202 , CVE-2026-7203 , CVE-2026-7204 , CVE-2026-73570 , CVE-2026-9384 , CVE-2026-9385 , CVE-2026-9386 , CVE-2026-9387 , CVE-2026-9388 , CVE-2026-9404 , CVE-2026-9405 , CVE-2026-9406 , CVE-2026-9407 , CVE-2026-9408 , CVE-2026-9432 , CVE-2026-9433 , CVE-2026-9434 , CVE-2026-9435 , CVE-2026-9436 , CVE-2026-9454 , CVE-2026-9455 , CVE-2026-9456 , CVE-2026-9457 , CVE-2026-9458 , CVE-2026-9476 , CVE-2026-9477 , CVE-2026-9478 , CVE-2017-6884 , CVE-2021-3577 , CVE-2026-24893 , CVE-2026-26899 , CVE-2026-34197 , CVE-2026-35196 , CVE-2026-45578 , CVE-2026-45662 , CVE-2026-58195 , CVE-2026-72875 , CVE-2026-73222 , CVE-2026-79423 , CVE-2025-30007 , CVE-2025-34115 , CVE-2026-28797 , CVE-2026-34792 , CVE-2026-34793 , CVE-2026-34794 , CVE-2026-34795 , CVE-2026-34796 , CVE-2026-34797 , CVE-2026-46746 , CVE-2026-69096 , CVE-2026-71966 , CVE-2026-72870 , CVE-2026-72874 , CVE-2026-73680 , CVE-2026-76060 , CVE-2026-79756 , CVE-2023-47105 , CVE-2026-40187 , CVE-2026-53804 , CVE-2026-5917 , CVE-2026-61517 , CVE-2026-63725 , CVE-2026-65711 , CVE-2026-67599 , CVE-2026-71906 , CVE-2026-71907 , CVE-2026-71908 , CVE-2026-71913 , CVE-2026-71915 , CVE-2026-71918 , CVE-2026-71919 , CVE-2026-71923 , CVE-2026-71924 , CVE-2026-71925 , CVE-2026-71926 , CVE-2026-71927 , CVE-2026-71928 , CVE-2026-71929 , CVE-2026-71930 , CVE-2026-71931 , CVE-2026-71943 , CVE-2026-75121 , CVE-2026-75122 , CVE-2026-75123 , CVE-2026-80214 , CVE-2026-82692 , CVE-2026-84194 , CVE-2026-85223 , CVE-2026-86299 , CVE-2026-86733 , CVE-2026-82690 , CVE-2026-82691 , CVE-2026-85222 , CVE-2026-85224 , CVE-2025-69755 , CVE-2018-6961 , CVE-2026-48695 , CVE-2026-79755 , CVE-2021-21315 , CVE-2026-10870 , CVE-2026-10871 , CVE-2026-10873 , CVE-2026-18900 , CVE-2026-19771 , CVE-2021-33544 , CVE-2026-28409 , CVE-2026-71284 , CVE-2024-12987 , CVE-2026-19983 , CVE-2026-72739 , CVE-2026-45626 , CVE-2026-10214 , CVE-2026-18641 , CVE-2026-19379 , CVE-2026-5677 , CVE-2026-5678 , CVE-2026-5688 , CVE-2026-5689 , CVE-2026-5690 , CVE-2026-5691 , CVE-2026-5692 , CVE-2026-5741 , CVE-2026-5802 , CVE-2026-7220 , CVE-2026-76761 , CVE-2026-5547 , CVE-2026-10279 , CVE-2026-11408 , CVE-2026-5351 , CVE-2026-5352 , CVE-2026-5353 , CVE-2026-5354 , CVE-2026-5355 , CVE-2026-8188 , CVE-2026-8189 , CVE-2026-8190 , CVE-2026-8191 , CVE-2026-8192 , CVE-2026-8227 , CVE-2026-8228 , CVE-2026-8229 , CVE-2026-8230 , CVE-2026-8264 , CVE-2026-9343 , CVE-2026-9347 , CVE-2026-9424 , CVE-2026-9511 , CVE-2026-9512 , CVE-2026-9514 , CVE-2026-9515 , CVE-2026-9531 , CVE-2026-9532 , CVE-2026-9533 , CVE-2026-9534 , CVE-2026-8259 , CVE-2026-8265 , CVE-2026-82702 , CVE-2026-82703 , CVE-2026-85040 , CVE-2026-5621
CWE-79CVE-2026-73041 , CVE-2026-73042 , CVE-2024-39024 , CVE-2023-5244
CWE-88CVE-2026-44450 , CVE-2026-73294
CWE-89CVE-2026-55634 , CVE-2020-5722 , CVE-2022-27927 , CVE-2022-40032 , CVE-2022-40347 , CVE-2026-38428 , CVE-2026-33324 , CVE-2026-34612 , CVE-2026-5736 , CVE-2026-9474 , CVE-2023-7299 , CVE-2026-19785
CWE-93CVE-2026-84372
CWE-94CVE-2022-22947 , CVE-2026-53753 , CVE-2026-8984 , CVE-2026-55565 , CVE-2026-55634 , CVE-2026-8481 , CVE-2020-11546 , CVE-2022-22954 , CVE-2023-25717 , CVE-2025-29306 , CVE-2026-31040 , CVE-2026-38431 , CVE-2026-46562 , CVE-2026-55559 , CVE-2026-67919 , CVE-2026-75411 , CVE-2026-75414 , CVE-2026-70477 , CVE-2026-88062 , CVE-2025-62593 , CVE-2026-45272 , CVE-2026-69256 , CVE-2026-82244 , CVE-2026-29014 , CVE-2026-58138 , CVE-2026-65008 , CVE-2026-70553 , CVE-2026-46621 , CVE-2026-55511 , CVE-2026-58400 , CVE-2026-62674 , CVE-2026-69251 , CVE-2026-73485 , CVE-2026-73486 , CVE-2026-73487 , CVE-2026-43945 , CVE-2022-4223 , CVE-2024-41667 , CVE-2026-34197 , CVE-2026-45505 , CVE-2026-48017 , CVE-2026-55585 , CVE-2026-62675 , CVE-2026-78834 , CVE-2022-50944 , CVE-2026-28797 , CVE-2026-49143 , CVE-2026-64850 , CVE-2026-69100 , CVE-2026-72819 , CVE-2026-76836 , CVE-2026-82278 , CVE-2026-85604 , CVE-2026-85610 , CVE-2026-86732 , CVE-2026-42785 , CVE-2026-56703 , CVE-2026-61523 , CVE-2026-65693 , CVE-2026-69088 , CVE-2026-22244 , CVE-2026-42588 , CVE-2026-47398 , CVE-2026-71320 , CVE-2026-46581 , CVE-2026-13392 , CVE-2026-77939 , CVE-2026-5739 , CVE-2026-44287 , CVE-2025-13786 , CVE-2025-13792 , CVE-2026-54611 , CVE-2026-5631 , CVE-2026-76760 , CVE-2026-82598 , CVE-2026-85137 , CVE-2026-19932 , CVE-2026-19958 , CVE-2026-78166 , CVE-2026-9302 , CVE-2026-19964 , CVE-2026-81835
CWE-95CVE-2026-46562 , CVE-2026-47391 , CVE-2026-39932 , CVE-2025-31114 , CVE-2026-61511 , CVE-2026-40187
CWE-120CVE-2026-36796
CWE-121CVE-2026-76070 , CVE-2026-76071 , CVE-2026-36783
CWE-183CVE-2026-16129
CWE-184CVE-2026-49869 , CVE-2026-44287 , CVE-2026-16129
CWE-187CVE-2026-35031
CWE-200CVE-2025-69755 , CVE-2026-51078
CWE-253CVE-2026-15686
CWE-269CVE-2026-45632 , CVE-2026-49819 , CVE-2026-72830 , CVE-2026-73664
CWE-284CVE-2026-34234 , CVE-2019-2729 , CVE-2026-43945 , CVE-2026-73664 , CVE-2026-11474 , CVE-2026-10172
CWE-285CVE-2026-34239
CWE-287CVE-2026-49869 , CVE-2025-27621
CWE-288CVE-2026-43945 , CVE-2025-4427
CWE-306CVE-2026-81735 , CVE-2026-45695 , CVE-2026-47391 , CVE-2026-49819 , CVE-2026-53649 , CVE-2026-88062 , CVE-2026-73222 , CVE-2023-54350 , CVE-2025-34115 , CVE-2025-4008 , CVE-2026-63722 , CVE-2026-49471
CWE-352CVE-2026-53649 , CVE-2025-62593 , CVE-2025-56798 , CVE-2026-73222 , CVE-2026-34228 , CVE-2026-49471
CWE-400CVE-2021-44228
CWE-434CVE-2026-72592 , CVE-2026-53649 , CVE-2024-58348 , CVE-2026-44402 , CVE-2023-7305 , CVE-2025-59710 , CVE-2021-47943 , CVE-2026-34735 , CVE-2026-67206 , CVE-2026-53599 , CVE-2026-27891 , CVE-2026-11474 , CVE-2026-54611 , CVE-2026-10172
CWE-470CVE-2026-46562 , CVE-2026-55559 , CVE-2026-58400 , CVE-2026-79987 , CVE-2026-34216
CWE-494CVE-2026-66398
CWE-502CVE-2021-44228 , CVE-2025-55182
CWE-639CVE-2026-72876
CWE-641CVE-2026-46581
CWE-644CVE-2026-67179
CWE-732CVE-2026-73664
CWE-829CVE-2026-45272 , CVE-2026-47398
CWE-835CVE-2024-20353
CWE-862CVE-2026-45632 , CVE-2026-72868 , CVE-2026-72876 , CVE-2026-49819 , CVE-2022-4223 , CVE-2026-86438
CWE-863CVE-2026-43945 , CVE-2021-3577 , CVE-2026-76836
CWE-913CVE-2026-53753
CWE-915CVE-2026-72710 , CVE-2026-78416
CWE-917CVE-2021-44228 , CVE-2022-22947 , CVE-2021-45046 , CVE-2019-16469
CWE-918CVE-2026-49869
CWE-942CVE-2026-34449 , CVE-2026-53649
CWE-1336CVE-2026-44181 , CVE-2026-55559 , CVE-2026-28797 , CVE-2026-72827 , CVE-2026-22244 , CVE-2026-77939
CWE-1392CVE-2026-41939