Vulnerabilities (CVE)

Filtered by CWE-77
Angry Yack Logo
Total 3060 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-2548 2026-02-18 6.5 MEDIUM 6.3 MEDIUM
A flaw has been found in WAYOS FBM-220G 24.10.19. This affects the function sub_40F820 of the file rc. Executing a manipulation of the argument upnp_waniface/upnp_ssdp_interval/upnp_max_age can lead to command injection. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-2560 2026-02-18 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoResize.class.php of the component Media File Preview Plugin. Such manipulation of the argument localFile leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-20671 1 Apple 6 Ipados, Iphone Os, Macos and 3 more 2026-02-17 N/A 3.1 LOW
A logic issue was addressed with improved checks. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An attacker in a privileged network position may be able to intercept network traffic.
CVE-2026-20675 1 Apple 6 Ipados, Iphone Os, Macos and 3 more 2026-02-17 N/A 5.5 MEDIUM
The issue was addressed with improved bounds checks. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3. Processing a maliciously crafted image may lead to disclosure of user information.
CVE-2026-2000 1 Dcnetworks 2 Dcme-320, Dcme-320 Firmware 2026-02-17 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was found in DCN DCME-320 up to 20260121. Impacted is the function apply_config of the file /function/system/basic/bridge_cfg.php of the component Web Management Backend. Performing a manipulation of the argument ip_list results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-70093 1 Opensourcepos 1 Open Source Point Of Sale 2026-02-17 N/A 7.4 HIGH
An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.
CVE-2025-3546 1 H3c 10 Magic Be18000, Magic Be18000 Firmware, Magic Nx15 and 7 more 2026-02-13 7.7 HIGH 8.0 HIGH
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getLanguage of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used. It is recommended to u ...

Show More

CVE-2026-2080 1 Utt 2 810, 810 Firmware 2026-02-13 8.3 HIGH 7.2 HIGH
A vulnerability has been found in UTT HiPER 810 1.7.4-141218. This issue affects the function setSysAdm of the file /goform/formUser. The manipulation of the argument passwd1 leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-2118 1 Utt 2 810, 810 Firmware 2026-02-13 8.3 HIGH 7.2 HIGH
A vulnerability was determined in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_4407D4 of the file /goform/formReleaseConnect of the component rehttpd. Executing a manipulation of the argument Isp_Name can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-2135 1 Utt 2 810, 810 Firmware 2026-02-13 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was detected in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_43F020 of the file /goform/formPdbUpConfig. Performing a manipulation of the argument policyNames results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
CVE-2025-37162 1 Arubanetworks 1 Arubaos 2026-02-13 N/A 6.5 MEDIUM
A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
CVE-2025-64090 1 Zenitel 2 Tcis-3, Tcis-3 Firmware 2026-02-12 N/A 10.0 CRITICAL
This vulnerability allows authenticated attackers to execute commands via the hostname of the device.
CVE-2026-2085 1 Dlink 2 Dwr-m921, Dwr-m921 Firmware 2026-02-12 8.3 HIGH 7.2 HIGH
A security vulnerability has been detected in D-Link DWR-M921 1.1.50. Affected is the function sub_419F20 of the file /boafrm/formUSSDSetup of the component USSD Configuration Endpoint. The manipulation of the argument ussdValue leads to command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
CVE-2026-2260 1 Dlink 2 Dcs-931l, Dcs-931l Firmware 2026-02-12 8.3 HIGH 7.2 HIGH
A vulnerability was found in D-Link DCS-931L up to 1.13.0. This affects an unknown part of the file /goform/setSysAdmin. The manipulation of the argument AdminID results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-21516 1 Microsoft 1 Github Copilot 2026-02-11 N/A 8.8 HIGH
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.
CVE-2026-21256 1 Microsoft 1 Visual Studio 2022 2026-02-11 N/A 8.8 HIGH
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2025-59818 1 Zenitel 2 Tcis-3, Tcis-3 Firmware 2026-02-11 N/A 10.0 CRITICAL
This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.
CVE-2026-21257 1 Microsoft 1 Visual Studio 2022 2026-02-11 N/A 8.0 HIGH
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network.
CVE-2026-2061 1 Dlink 2 Dir-823x Firmware, Dir-832x 2026-02-11 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was determined in D-Link DIR-823X 250416. Affected by this issue is the function sub_424D20 of the file /goform/set_ipv6. Executing a manipulation can lead to os command injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-2063 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-02-11 5.8 MEDIUM 4.7 MEDIUM
A security flaw has been discovered in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/set_ac_server of the component Web Management Interface. The manipulation of the argument ac_server results in os command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-2120 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-02-11 8.3 HIGH 7.2 HIGH
A vulnerability was identified in D-Link DIR-823X 250416. This affects an unknown function of the file /goform/set_server_settings of the component Configuration Parameter Handler. The manipulation of the argument terminal_addr/server_ip/server_port leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
CVE-2026-2129 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-02-11 8.3 HIGH 7.2 HIGH
A vulnerability was found in D-Link DIR-823X 250416. Affected by this issue is some unknown functionality of the file /goform/set_ac_status. Performing a manipulation of the argument ac_ipaddr/ac_ipstatus/ap_randtime results in os command injection. The attack may be initiated remotely. The exploit has been made public and could be used.
CVE-2026-21522 1 Microsoft 1 Confcom 2026-02-11 N/A 6.7 MEDIUM
Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
CVE-2026-2151 1 Dlink 2 Dir-615, Dir-615 Firmware 2026-02-11 8.3 HIGH 7.2 HIGH
A vulnerability has been found in D-Link DIR-615 4.10. This affects an unknown part of the file adv_firewall.php of the component DMZ Host Feature. Such manipulation of the argument dmz_ipaddr  leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-2152 1 Dlink 2 Dir-615, Dir-615 Firmware 2026-02-11 8.3 HIGH 7.2 HIGH
A vulnerability was found in D-Link DIR-615 4.10. This vulnerability affects unknown code of the file adv_routing.php of the component Web Configuration Interface. Performing a manipulation of the argument dest_ip/ submask/ gw results in os command injection. The attack may be initiated remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-2155 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-02-11 8.3 HIGH 7.2 HIGH
A security flaw has been discovered in D-Link DIR-823X 250416. The affected element is the function sub_4208A0 of the file /goform/set_dmz of the component Configuration Handler. The manipulation of the argument dmz_host/dmz_enable results in os command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-2157 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-02-11 8.3 HIGH 7.2 HIGH
A security vulnerability has been detected in D-Link DIR-823X 250416. This affects the function sub_4175CC of the file /goform/set_static_route_table. Such manipulation of the argument interface/destip/netmask/gateway/metric leads to os command injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
CVE-2026-2163 1 Dlink 2 Dir-600, Dir-600 Firmware 2026-02-11 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was identified in D-Link DIR-600 up to 2.15WWb02. This vulnerability affects unknown code of the file ssdp.cgi. Such manipulation of the argument HTTP_ST/REMOTE_ADDR/REMOTE_PORT/SERVER_ID leads to command injection. The attack may be launched remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-2167 1 Totolink 2 Wa300, Wa300 Firmware 2026-02-11 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was detected in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setAPNetwork of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Ipaddr results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.
CVE-2026-2168 1 Dlink 2 Dwr-m921, Dwr-m921 Firmware 2026-02-11 6.5 MEDIUM 6.3 MEDIUM
A flaw has been found in D-Link DWR-M921 1.1.50. This affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
CVE-2026-2169 1 Dlink 2 Dwr-m921, Dwr-m921 Firmware 2026-02-11 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in D-Link DWR-M921 1.1.50. This impacts an unknown function of the file /boafrm/formLtefotaUpgradeFibocom. Such manipulation of the argument fota_url leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2026-2175 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-02-11 8.3 HIGH 7.2 HIGH
A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420618 of the file /goform/set_upnp. This manipulation of the argument upnp_enable causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
CVE-2026-2193 1 Dlink 2 Di-7100g C1, Di-7100g C1 Firmware 2026-02-11 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was detected in D-Link DI-7100G C1 24.04.18D1. Affected by this issue is the function set_jhttpd_info. Performing a manipulation of the argument usb_username results in command injection. Remote exploitation of the attack is possible.
CVE-2026-2194 1 Dlink 2 Di-7100g C1, Di-7100g C1 Firmware 2026-02-11 6.5 MEDIUM 6.3 MEDIUM
A flaw has been found in D-Link DI-7100G C1 24.04.18D1. This affects the function start_proxy_client_email. Executing a manipulation can lead to command injection. The attack can be executed remotely. The exploit has been published and may be used.
CVE-2026-2210 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-02-11 8.3 HIGH 7.2 HIGH
A vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_filtering. Such manipulation leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2026-2218 1 Dlink 2 Dcs-933l, Dcs-933l Firmware 2026-02-11 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was determined in D-Link DCS-933L up to 1.14.11. This affects an unknown function of the file /setSystemAdmin of the component alphapd. This manipulation of the argument AdminID causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-64093 1 Zenitel 4 Icx500, Icx500 Firmware, Icx510 and 1 more 2026-02-10 N/A 10.0 CRITICAL
Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.
CVE-2025-69542 1 Dlink 2 Dir-895la1, Dir-895la1 Firmware 2026-02-10 N/A 9.8 CRITICAL
A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease renewal processing logic where the DHCP hostname parameter is directly concatenated into a system command without proper sanitization. When a DHCP client renews an existing lease with a malicious hostname, arbitrary commands can be executed with root privileges.
CVE-2026-1596 1 Dlink 2 Dwr-m961, Dwr-m961 Firmware 2026-02-10 6.5 MEDIUM 6.3 MEDIUM
A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
CVE-2026-1687 1 Tenda 2 Hg10, Hg10 Firmware 2026-02-10 7.5 HIGH 7.3 HIGH
A weakness has been identified in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. Impacted is an unknown function of the file /boaform/formSamba of the component Boa Webserver. Executing a manipulation of the argument serverString can lead to command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.