tag
Cwe-78
High
Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Windows WMI Config Wizard (CVE-2021-25296)
CVE-2021-25296·
Nagios XI — Windows WMI monitoring configuration wizard
patched
High
Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Switch Config Wizard (CVE-2021-25297)
CVE-2021-25297·
Nagios XI — Switch (SNMP) monitoring configuration wizard
patched
High
Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Cloud-VM Config Wizard (CVE-2021-25298)
CVE-2021-25298·
Nagios XI — Cloud/VM monitoring configuration wizard (DigitalOcean provider sub-option)
patched
Critical
D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258)
CVE-2022-26258·
D-Link DIR-820L wireless router, all hardware revisions
unpatched
Critical
React Native Community CLI Metro Dev Server `/open-url` OS Command Injection (CVE-2025-11953)
CVE-2025-11953·
@react-native-community/cli / @react-native-community/cli-server-api (Metro Development Server, openURLMiddleware)
patched
Critical
HPE OneView `id-pools/executeCommand` OS Command Injection (CVE-2025-37164)
CVE-2025-37164·
HPE OneView (infrastructure management appliance) REST API
unpatched
Critical
Hoverfly Middleware Command Injection to RCE (CVE-2025-54123)
CVE-2025-54123·
SpectoLabs Hoverfly (HTTP/API service virtualization tool) — admin API, <= v1.11.3
unpatched
Critical
D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)
CVE-2025-60854·
D-Link AX1500 router firmware (HNAP/DHMAPI web management SOAP interface)
patched
Critical
TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834
CVE-2026-11834·
TP-Link router firmware (libcmm.so DHCP client), tested on Archer C20 V6
unpatched
High
OS Command Injection in KubeAI via Model URL (CVE-2026-34940)
CVE-2026-34940·
KubeAI (github.com/kubeai-project/kubeai)
patched
Critical
OliveTin OS Command Injection via Shell Mode Arguments (CVE-2026-27626)
CVE-2026-27626 / GHSA-49gm-hh7w-wfvf·
OliveTin (self-hosted web UI for exposing predefined shell commands)
unpatched
Critical
MeiG Smart FORGE_SLT711 GoAhead Unauthenticated OS Command Injection (CVE-2026-36356)
CVE-2026-36356·
MeiG Smart FORGE_SLT711 4G LTE CPE (GoAhead web server)
unpatched
High
HAXcms Git.php OS Command Injection (CVE-2026-46394)
CVE-2026-46394·
HAXcms PHP backend (elmsln/HAXcms) — system/backend/php/lib/Git.php
patched
Critical
Group-Office TNEF Attachment Handler OS Command Injection (CVE-2026-25512)
CVE-2026-25512·
Group-Office groupware/webmail suite
unpatched
Critical
Gotenberg 8.29.1 Unauthenticated ExifTool Metadata Key Injection RCE (CVE-2026-42589)
CVE-2026-42589·
Gotenberg (document/PDF conversion microservice)
patched
Critical
FortiSandbox 4.4.0-4.4.8 — OS Command Injection via tracer-behavior Endpoint (CVE-2026-39808)
CVE-2026-39808·
Fortinet FortiSandbox
unpatched
Critical
Fortinet FortiSandbox "Start VNC" OS Command Injection (CVE-2026-25089)
CVE-2026-25089·
Fortinet FortiSandbox (Web UI "start VNC" feature)
patched
Critical
Coolify Authenticated Remote Command Injection via Deployment Config (CVE-2026-34038)
CVE-2026-34038 (GHSA-qqrq-r9h4-x6wp)·
Coolify (self-hosted PaaS/deployment platform)
unpatched
Critical
Cockpit Unauthenticated Remote Code Execution via SSH Argument Injection (CVE-2026-4631)
CVE-2026-4631 (GHSA-m4gv-x78h-3427)·
Cockpit (Linux web-based server admin console)
patched
High
Cacti Authenticated OS Command Injection via Host Notes Variable (CVE-2026-39949)
CVE-2026-39949·
Cacti network monitoring platform
patched