Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,180 CVEs tagged with CWE-781,976 Critical, 3,126 High, 890 Medium, 188 Low, 0 Unrated.

CVE-2026-45777

Published Jun 5, 2026

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system c…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-25623

Published Jun 5, 2026

An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Authentica…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25622

Published Jun 5, 2026

A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an adminis…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25621

Published Jun 5, 2026

A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure input validation. This issue un…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25620

Published Jun 5, 2026

An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW).…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-46399

Published Jun 5, 2026

HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file overwrite vulnerability. An attac…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-46394

Published Jun 5, 2026

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an OS command injection vulnerability exists in the Git.php library of the HAXcms PHP…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-49492

Published Jun 5, 2026

Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not validate untrusted inputs taken from the markdown document - t…

CVSS 8.6 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-45750

Published Jun 5, 2026

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath end…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-45748

Published Jun 5, 2026

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /ssh/tunnel/connect` endpoint in Termix prior to version 2.…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-45744

Published Jun 5, 2026

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath end…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-11341

Published Jun 5, 2026

A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of the argument IMEI_va…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-10873

Published Jun 4, 2026

A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats of the component Web UI. Executing a manipulation can lead…

CVSS 7.3 · High
evidence mentions
7
Buzz score
27.3

CVE-2026-10872

Published Jun 4, 2026

A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. Performing a manipulation resul…

CVSS 7.3 · High
evidence mentions
6
Buzz score
26.0

CVE-2026-10871

Published Jun 4, 2026

A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the component Web UI. Such manipulation…

CVSS 7.3 · High
evidence mentions
6
Buzz score
26.0

CVE-2026-10870

Published Jun 4, 2026

A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the component Web UI. This manipulation causes os command injection…

CVSS 7.3 · High
evidence mentions
6
Buzz score
26.0

CVE-2026-10796

Published Jun 4, 2026

nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured Node.js/io.js mirror. Commands such as `nvm install` read the…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-69755

Published Jun 4, 2026

An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted command to the at_comm…

CVSS 8.2 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-67447

Published Jun 4, 2026

The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The application does not properly sanitize user inpu…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-35906

Published Jun 4, 2026

An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrary system commands as root via su…

CVSS 9.6 · Critical
evidence mentions
4
Buzz score
29.1

CVE-2026-45431

Published Jun 4, 2026

This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web management interface. An authenticated…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-3820

Published Jun 4, 2026

There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.  An attacker may obtain administrator privileges and inject specially crafted characters…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-49190

Published Jun 4, 2026

The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 276-300 of 6,180 CVEsPage 12 of 248