Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,188 CVEs tagged with CWE-781,979 Critical, 3,128 High, 890 Medium, 191 Low, 0 Unrated.

CVE-2026-9407

Published May 25, 2026

A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function setFirewallType of the file /cgi-bin/cstecgi.cgi…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9406

Published May 25, 2026

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Inte…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9405

Published May 25, 2026

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi of the component Web Manage…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9404

Published May 24, 2026

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Inter…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9388

Published May 24, 2026

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component Web M…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9387

Published May 24, 2026

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component We…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9386

Published May 24, 2026

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management In…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9385

Published May 24, 2026

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Mana…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9384

Published May 24, 2026

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component Web Ma…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9367

Published May 24, 2026

A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63. This affects the function detect_dangerous_command of the file tools/ap…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-9347

Published May 24, 2026

A vulnerability has been found in Edimax EW-7438RPn up to 1.31. Affected is the function formWizSurvey of the file /goform/formWizSurvey of the component webs. The manipulation of…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-9343

Published May 23, 2026

A weakness has been identified in Edimax EW-7438RPn up to 1.31. The affected element is the function formWpsStart of the file /goform/formWpsStart of the component webs. This mani…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-9277

Published May 22, 2026

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character us…

CVSS 9.2 · Critical
evidence mentions
30
Buzz score
49.5

CVE-2026-45255

Published May 21, 2026

When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and use bsddialog(1) to prompt the user to select a network. Th…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44076

Published May 21, 2026

Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS commands and execute arbitrary code via a crafted volume path.

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-44072

Published May 21, 2026

Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which allows a local privileged user to execute unintended comman…

CVSS 3.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-44055

Published May 21, 2026

A logic error involving bitwise OR operations in Netatalk 3.1.4 through 4.4.2 allows a remote authenticated attacker to inject OS commands and execute arbitrary code.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8632

Published May 20, 2026

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitr…

CVSS 8.5 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2026-20206

Published May 20, 2026

A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-34234

Published May 19, 2026

CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to unauthenticated…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-8603

Published May 19, 2026

In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-36828

Published May 19, 2026

A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to exe…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-36827

Published May 19, 2026

A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes the backend helper /usr/sbin/pappiw and passes user-co…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-37281

Published May 19, 2026

An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url para…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2026-27130

Published May 18, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this probl…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
16.0
Showing 401-425 of 6,188 CVEsPage 17 of 248