Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

type:cmd-inject — CVE vulnerabilities tagged 5448

5448 CVE security advisories tagged "type:cmd-inject" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-6992 Linksys MR9600 JNAP Action run_central2.sh BTRequestGetSmartConnectStatus os command injection — MR9600CWE-78 7.2 High2026-04-25
CVE-2026-6989 Tenda F453 Telnet Service telnet TendaTelnet command injection — F453CWE-77 6.3 Medium2026-04-25
CVE-2026-6987 PicoClaw Web Launcher Management Plane restart command injection — PicoClawCWE-77 7.3 High2026-04-25
CVE-2026-6980 Divyanshu-hash GitPilot-MCP main.py repo_path command injection — GitPilot-MCPCWE-77 7.3 High2026-04-25
CVE-2026-41411 Vim: Command injection via backtick expansion in tag filenames — vimCWE-78 6.6 Medium2026-04-24
CVE-2026-6942 radare2-mcp <=1.6.0 OS Command Injection via Shell Metacharacter Bypass — radare2 9.8 Critical2026-04-23
CVE-2026-41137 Flowise: Code Injection in CSVAgent leads to Authenticated RCE — FlowiseCWE-94 8.8AIHighAI2026-04-23
CVE-2026-41247 elFinder: Command injection in resize background color parameter when using ImageMagick CLI — elFinderCWE-78 9.8AICriticalAI2026-04-23
CVE-2026-40517 radare2 < 6.1.4 Command Injection via PDB Parser Symbol Names — radare2CWE-78 7.8 High2026-04-22
CVE-2026-41304 WWBN AVideo vulnerable to RCE caused by clonesite plugin — AVideoCWE-77 8.8AIHighAI2026-04-21
CVE-2026-6799 Comfast CF-N1-S Endpoint mbox-config command injection — CF-N1-SCWE-77 6.3 Medium2026-04-21
CVE-2026-21571 Atlassian Bamboo Data Center 安全漏洞 — Bamboo Data Center 9.8AICriticalAI2026-04-21
CVE-2026-40520 FreePBX api module Command Injection via GraphQL — apiCWE-78 7.2 High2026-04-21
CVE-2026-5965 NewSoft|NewSoftOA - OS Command Injection — NewSoftOACWE-78 9.8 Critical2026-04-21
CVE-2026-39866 Lawnchair vulnerable to Command Injection via unquoted workflow dispatch input in release_update.yml — lawnchairCWE-77 8.8AIHighAI2026-04-21
CVE-2026-38834 Tenda W30E 安全漏洞 — n/a 9.8AICriticalAI2026-04-21
CVE-2026-38835 Tenda W30E 安全漏洞 — n/a 9.8AICriticalAI2026-04-21
CVE-2026-22761 Dell PowerProtect Data Domain(Dell PowerProtect DD) 安全漏洞 — PowerProtect Data DomainCWE-78 6.7 Medium2026-04-20
CVE-2026-26942 Dell PowerProtect Data Domain(Dell PowerProtect DD) 安全漏洞 — PowerProtect Data DomainCWE-78 6.7 Medium2026-04-20
CVE-2026-26943 Dell PowerProtect Data Domain(Dell PowerProtect DD) 安全漏洞 — PowerProtect Data DomainCWE-78 7.2 High2026-04-20
CVE-2026-24506 Dell PowerProtect Data Domain(Dell PowerProtect DD) 安全漏洞 — PowerProtect Data DomainCWE-78 7.2 High2026-04-20
CVE-2026-23774 Dell PowerProtect Data Domain(Dell PowerProtect DD) 安全漏洞 — PowerProtect Data DomainCWE-78 7.2 High2026-04-20
CVE-2026-4048 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF — LoadMasterCWE-77 8.4 High2026-04-20
CVE-2026-3519 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF — LoadMasterCWE-77 8.4 High2026-04-20
CVE-2026-3518 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF — LoadMasterCWE-77 8.4 High2026-04-20
CVE-2026-3517 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF — LoadMasterCWE-77 8.4 High2026-04-20
CVE-2026-6644 A command injection vulnerability was found in the PPTP VPN Clients on the ADM — ADMCWE-78 7.2AIHighAI2026-04-20
CVE-2026-6576 liangliangyy DjangoBlog WeChat Bot commonapi.py CommandHandler command injection — DjangoBlogCWE-77 6.3 Medium2026-04-19
CVE-2026-35582 Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in Executrix — emissaryCWE-78 8.8 High2026-04-18
CVE-2026-40527 radare2 Command Injection via DWARF Parameter Names — radare2CWE-78 7.8 High2026-04-17

Vulnerabilities classified as type:cmd-inject represent 5448 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.