Fallos del tipo CWE-78

3786 resultados
CVE-2022-0557HIGHOS Command Injection in microweber/microweberEPSS 51.2%CVE-2023-49897HIGHAn OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. IEPSS 50.7%KEVCVE-2025-9528MEDIUMLinksys E1700 systemCommand os command injectionEPSS 50.1%CVE-2022-28171HIGHThe web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient inpuEPSS 49.9%CVE-2024-3346MEDIUMByzoro Smart S80 webmailattach.php os command injectionEPSS 49.3%CVE-2026-2701CRITICALRCE vulnerability in Progress ShareFile Storage Zones Controller (SZC)EPSS 48.8%CVE-2026-39808CRITICALA improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 thEPSS 48.7%CVE-2024-1520CRITICALOS Command Injection in parisneo/lollms-webuiEPSS 48.2%CVE-2021-40407CRITICALAn OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] orEPSS 47.9%KEVCVE-2023-6018CRITICALMLflow Arbitrary File WriteEPSS 47.9%CVE-2022-2550CRITICALOS Command Injection in hestiacp/hestiacpEPSS 47.5%CVE-2021-33552HIGHUDP Technology/Geutebrück camera devices: Command injection in date parameter leading to RCEEPSS 47.5%CVE-2021-33551HIGHUDP Technology/Geutebrück camera devices: Command injection in environment.lang parameter leading to RCEEPSS 47.5%CVE-2021-33553HIGHUDP Technology/Geutebrück camera devices: Command injection in command parameter leading to RCEEPSS 47.5%CVE-2019-1636HIGHCisco Webex Teams URI Handler Insecure Library Loading VulnerabilityEPSS 46.9%CVE-2025-54782CRITICAL@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS DevelopersEPSS 46.2%CVE-2023-3450MEDIUMRuijie RG-BCR860 Network Diagnostic Page os command injectionEPSS 46.1%CVE-2023-7002HIGHBackup Migration <= 1.3.9 - Authenticated (Admin+) OS Command Injection via urlEPSS 45.9%CVE-2024-28254HIGHSpEL Injection in `GET /api/v1/events/subscriptions/validation/condition/<expr>` in OpenMetadataEPSS 45.7%CVE-2024-51568CRITICALCyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There EPSS 45.7%