Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,285 CVEs tagged with CWE-782,019 Critical, 3,175 High, 898 Medium, 193 Low, 0 Unrated.

CVE-2026-9404

Published May 24, 2026

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Inter…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9388

Published May 24, 2026

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component Web M…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9387

Published May 24, 2026

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component We…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9386

Published May 24, 2026

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management In…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9385

Published May 24, 2026

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Mana…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9384

Published May 24, 2026

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component Web Ma…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9367

Published May 24, 2026

A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63. This affects the function detect_dangerous_command of the file tools/ap…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-9347

Published May 24, 2026

A vulnerability has been found in Edimax EW-7438RPn up to 1.31. Affected is the function formWizSurvey of the file /goform/formWizSurvey of the component webs. The manipulation of…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-9343

Published May 23, 2026

A weakness has been identified in Edimax EW-7438RPn up to 1.31. The affected element is the function formWpsStart of the file /goform/formWpsStart of the component webs. This mani…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-9277

Published May 22, 2026

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character us…

CVSS 9.2 · Critical
evidence mentions
35
Buzz score
49.5

CVE-2026-45255

Published May 21, 2026

When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and use bsddialog(1) to prompt the user to select a network. Th…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44076

Published May 21, 2026

Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS commands and execute arbitrary code via a crafted volume path.

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-44072

Published May 21, 2026

Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which allows a local privileged user to execute unintended comman…

CVSS 3.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-44055

Published May 21, 2026

A logic error involving bitwise OR operations in Netatalk 3.1.4 through 4.4.2 allows a remote authenticated attacker to inject OS commands and execute arbitrary code.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8632

Published May 20, 2026

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitr…

CVSS 8.5 · High
evidence mentions
14
Buzz score
40.1
Vendor/product tagsBeta · best-effort

CVE-2026-20206

Published May 20, 2026

A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-34234

Published May 19, 2026

CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is vulnerable to unauthenticated…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-8603

Published May 19, 2026

In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-36828

Published May 19, 2026

A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to exe…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-36827

Published May 19, 2026

A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes the backend helper /usr/sbin/pappiw and passes user-co…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-37281

Published May 19, 2026

An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url para…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2026-27130

Published May 18, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this probl…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-25244

Published May 18, 2026

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulner…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-8767

Published May 17, 2026

A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Inte…

CVSS 1.3 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-45036

Published May 15, 2026

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby before 1.0.233 automatically confirms ZMODEM protocol detection on all terminal sessi…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 501-525 of 6,285 CVEsPage 21 of 252