tag
Argument-Injection
High
Weblate Arbitrary File Read via ssh-keyscan Host Argument Injection — CVE-2026-24126
CVE-2026-24126·
Weblate (self-hosted translation platform)
patched
High
Prefect GitRepository Git Argument Injection RCE via `commit_sha` — CVE-2026-5366
CVE-2026-5366 (Huntr bounty e2e88a0f-a8f6-49c9-94c5-e98dc385f07a)·
Prefect (workflow orchestration platform), GitRepository storage class
patched
High
Pardus Software Center Local Privilege Escalation via APT Option Injection (CVE-2026-14459 / CVE-2026-14460)
CVE-2026-14459 (also covers CVE-2026-14460)·
pardus-software (Pardus Software Center)
patched
Not disclosed
Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337
CVE-2026-54337 (see [GHSA-hmh2-6g84-q8jx](https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-hmh2-6g84-q8jx))·
Fireshare (self-hosted video sharing app), <= 1.16.3
unpatched
High
exiftool-vendored.js Argument Injection via Newline-Delimited Tag Names (CVE-2026-43893)
CVE-2026-43893 / GHSA-cw26-7653-2rp5·
exiftool-vendored (npm package, Node.js wrapper around Phil Harvey's ExifTool)
patched
Critical
Cockpit Unauthenticated Remote Code Execution via SSH Argument Injection (CVE-2026-4631)
CVE-2026-4631 (GHSA-m4gv-x78h-3427)·
Cockpit (Linux web-based server admin console)
patched