Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,221 CVEs tagged with CWE-781,987 Critical, 3,151 High, 892 Medium, 191 Low, 0 Unrated.

CVE-2026-17566

Published Jul 31, 2026

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql v…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-17347

Published Jul 31, 2026

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configure…

CVSS 7.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-16843

Published Jul 31, 2026

Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this fla…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12943

Published Jul 30, 2026

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticate…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-12940

Published Jul 30, 2026

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launche…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-14522

Published Jul 30, 2026

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-22622

Published Jul 30, 2026

Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting i…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-22621

Published Jul 30, 2026

Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary com…

CVSS 8.3 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-44106

Published Jul 30, 2026

A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system co…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44099

Published Jul 30, 2026

A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44098

Published Jul 30, 2026

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44096

Published Jul 30, 2026

A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44095

Published Jul 30, 2026

A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44093

Published Jul 30, 2026

A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full sys…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16524

Published Jul 30, 2026

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute a…

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-67438

Published Jul 29, 2026

OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/internal/executor/arguments.go checkShellArgumentSafety functio…

CVSS 6.6 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-56389

Published Jul 29, 2026

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can ove…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-14959

Published Jul 28, 2026

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-14958

Published Jul 28, 2026

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-61376

Published Jul 28, 2026

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS comman…

CVSS 8.6 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-59764

Published Jul 28, 2026

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be ex…

CVSS 8.6 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-55578

Published Jul 27, 2026

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the terminal feature in Pheditor uses an incomplete character blockli…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-54540

Published Jul 27, 2026

Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated terminal command whitelist bypass. The terminal feature checks…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-48030

Published Jul 27, 2026

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-24252

Published Jul 27, 2026

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tamper…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Showing 1-25 of 6,221 CVEsPage 1 of 249