Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-9477 |
|
Command Injection in CVE-2026-9477 (CVE-2026-9477)
command injection in CVE-2026-9477 (CVE-2026-9477). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9478 |
|
Command Injection in CVE-2026-9478 (CVE-2026-9478)
command injection in CVE-2026-9478 (CVE-2026-9478). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9456 |
|
Command Injection in CVE-2026-9456 (CVE-2026-9456)
command injection in CVE-2026-9456 (CVE-2026-9456). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9452 |
|
Command Injection in CVE-2026-9452 (CVE-2026-9452)
command injection in CVE-2026-9452 (CVE-2026-9452). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9457 |
|
Command Injection in CVE-2026-9457 (CVE-2026-9457)
command injection in CVE-2026-9457 (CVE-2026-9457). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9454 |
|
Command Injection in CVE-2026-9454 (CVE-2026-9454)
command injection in CVE-2026-9454 (CVE-2026-9454). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9458 |
|
Command Injection in CVE-2026-9458 (CVE-2026-9458)
command injection in CVE-2026-9458 (CVE-2026-9458). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9455 |
|
Command Injection in CVE-2026-9455 (CVE-2026-9455)
command injection in CVE-2026-9455 (CVE-2026-9455). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9433 |
|
Command Injection in CVE-2026-9433 (CVE-2026-9433)
command injection in CVE-2026-9433 (CVE-2026-9433). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9435 |
|
Command Injection in CVE-2026-9435 (CVE-2026-9435)
command injection in CVE-2026-9435 (CVE-2026-9435). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9434 |
|
Command Injection in CVE-2026-9434 (CVE-2026-9434)
command injection in CVE-2026-9434 (CVE-2026-9434). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9436 |
|
Command Injection in CVE-2026-9436 (CVE-2026-9436)
command injection in CVE-2026-9436 (CVE-2026-9436). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9432 |
|
Command Injection in CVE-2026-9432 (CVE-2026-9432)
command injection in CVE-2026-9432 (CVE-2026-9432). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9437 |
|
Command Injection in CVE-2026-9437 (CVE-2026-9437)
command injection in CVE-2026-9437 (CVE-2026-9437). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9424 |
|
Command Injection in CVE-2026-9424 (CVE-2026-9424)
command injection in CVE-2026-9424 (CVE-2026-9424). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9404 |
|
Command Injection in CVE-2026-9404 (CVE-2026-9404)
command injection in CVE-2026-9404 (CVE-2026-9404). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9406 |
|
Command Injection in CVE-2026-9406 (CVE-2026-9406)
command injection in CVE-2026-9406 (CVE-2026-9406). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9408 |
|
Command Injection in CVE-2026-9408 (CVE-2026-9408)
command injection in CVE-2026-9408 (CVE-2026-9408). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9405 |
|
Command Injection in CVE-2026-9405 (CVE-2026-9405)
command injection in CVE-2026-9405 (CVE-2026-9405). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9407 |
|
Command Injection in CVE-2026-9407 (CVE-2026-9407)
command injection in CVE-2026-9407 (CVE-2026-9407). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9387 |
|
Command Injection in CVE-2026-9387 (CVE-2026-9387)
command injection in CVE-2026-9387 (CVE-2026-9387). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9388 |
|
Command Injection in CVE-2026-9388 (CVE-2026-9388)
command injection in CVE-2026-9388 (CVE-2026-9388). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9384 |
|
Command Injection in CVE-2026-9384 (CVE-2026-9384)
command injection in CVE-2026-9384 (CVE-2026-9384). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9386 |
|
Command Injection in CVE-2026-9386 (CVE-2026-9386)
command injection in CVE-2026-9386 (CVE-2026-9386). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9385 |
|
Command Injection in CVE-2026-9385 (CVE-2026-9385)
command injection in CVE-2026-9385 (CVE-2026-9385). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9367 |
|
Command Injection in CVE-2026-9367 (CVE-2026-9367)
command injection in CVE-2026-9367 (CVE-2026-9367). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9343 |
|
Command Injection in CVE-2026-9343 (CVE-2026-9343)
command injection in CVE-2026-9343 (CVE-2026-9343). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9347 |
|
Command Injection in CVE-2026-9347 (CVE-2026-9347)
command injection in CVE-2026-9347 (CVE-2026-9347). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8652 |
|
OS Command Injection in jvn (CVE-2026-8652)
OS command injection in jvn (CVE-2026-8652). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46716 |
|
Privilege Escalation in github.com/nezhahq/nezha (CVE-2026-46716)
vulnerability in github.com/nezhahq/nezha (CVE-2026-46716). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/cron`. Mitigation: upgrade to `1.14.15-0.20260517022419-d7526351cf97` or later.
|
| CVE-2026-46643 |
|
OS Command Injection in KnpLabs/knp-snappy (CVE-2026-46643)
OS command injection in KnpLabs/knp-snappy (CVE-2026-46643). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.7.1` or later.
|
| CVE-2026-46618 |
|
Vulnerability in github.com/fission/fission (CVE-2026-46618)
vulnerability in github.com/fission/fission (CVE-2026-46618). Risk of unauthorized operations or information disclosure. Exploitable via ``Environment.spec.builder.command``. Mitigation: upgrade to `1.23.0` or later.
|
| CVE-2026-45255 |
|
OS Command Injection in freebsd (CVE-2026-45255)
OS command injection in freebsd (CVE-2026-45255). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44076 |
|
OS Command Injection in CVE-2026-44076 (CVE-2026-44076)
OS command injection in CVE-2026-44076 (CVE-2026-44076). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44072 |
|
OS Command Injection in CVE-2026-44072 (CVE-2026-44072)
OS command injection in CVE-2026-44072 (CVE-2026-44072). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44055 |
|
OS Command Injection in CVE-2026-44055 (CVE-2026-44055)
OS command injection in CVE-2026-44055 (CVE-2026-44055). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8632 |
|
Command Injection in hp (CVE-2026-8632)
command injection in hp (CVE-2026-8632). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20206 |
|
OS Command Injection in cisco (CVE-2026-20206)
OS command injection in cisco (CVE-2026-20206). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46420 |
|
OS Command Injection in shivammathur/setup-php (CVE-2026-46420)
OS command injection in shivammathur/setup-php (CVE-2026-46420). Risk of unauthorized operations or information disclosure. Exploitable via ``composer.lock``. Mitigation: upgrade to `2.37.1` or later.
|
| CVE-2026-34234 |
|
OS Command Injection in CVE-2026-34234 (CVE-2026-34234)
OS command injection in CVE-2026-34234 (CVE-2026-34234). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46339 |
|
OS Command Injection in 9router (CVE-2026-46339)
OS command injection in 9router (CVE-2026-46339). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/cli-tools/cowork-settings`. Mitigation: upgrade to `0.4.37` or later.
|
| CVE-2026-45695 |
|
OS Command Injection in github.com/kopia/kopia (CVE-2026-45695)
OS command injection in github.com/kopia/kopia (CVE-2026-45695). Successful exploitation can lead to full system takeover. Exploitable via ``blob.NewStorage``. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-8603 |
|
OS Command Injection in scadabr (CVE-2026-8603)
OS command injection in scadabr (CVE-2026-8603). Successful exploitation can lead to full system takeover.
|
| CVE-2026-36828 |
|
OS Command Injection in CVE-2026-36828 (CVE-2026-36828)
OS command injection in CVE-2026-36828 (CVE-2026-36828). Successful exploitation can lead to full system takeover.
|
| CVE-2026-36827 |
|
OS Command Injection in CVE-2026-36827 (CVE-2026-36827)
OS command injection in CVE-2026-36827 (CVE-2026-36827). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37281 |
|
OS Command Injection in express (CVE-2026-37281)
OS command injection in express (CVE-2026-37281). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27130 |
|
OS Command Injection in CVE-2026-27130 (CVE-2026-27130)
OS command injection in CVE-2026-27130 (CVE-2026-27130). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45626 |
|
OS Command Injection in github.com/getarcaneapp/arcane/backend (CVE-2026-45626)
OS command injection in github.com/getarcaneapp/arcane/backend (CVE-2026-45626). Risk of unauthorized operations or information disclosure. Exploitable via `GET /environments/{id}/volumes/{volumeName}/browse`.
|
| CVE-2026-8767 |
|
Command Injection in vercel (CVE-2026-8767)
command injection in vercel (CVE-2026-8767). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45578 |
|
OS Command Injection in WWBN/AVideo (CVE-2026-45578)
OS command injection in WWBN/AVideo (CVE-2026-45578). Successful exploitation can lead to full system takeover. Exploitable via ``on_publish.php``.
|