Vulnerability index

Browse CVEs

24 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Ranger CRITICAL 9.8
CVE-2026-28672

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger…

No fix yet
Fix from $5,750 2026-08-10
Airflow HIGH 8.8
CVE-2026-30898

An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be …

Fix: 3.2.0+
Fix from $1,950 2026-04-18
Continuum CRITICAL 9.9
CVE-2016-15057

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum…

Mitigation only
Fix from $2,300 2026-01-26
Brpc CRITICAL 9.8
CVE-2025-60021EPSS 25%

Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to …

Fix: 1.15.0+
Fix from $2,300 2026-01-16
Ambari HIGH 8.8
CVE-2025-23196

A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell co…

Fix: 2.7.9+
Fix from $1,950 2025-01-21
Hertzbeat HIGH 8.8
CVE-2024-45505

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerabili…

Fix: 1.6.1+
Fix from $1,950 2024-11-18
Streampark HIGH 7.2
CVE-2023-49898

In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of …

Fix: 2.1.2+
Fix from $1,950 2023-12-15
Spark HIGH 8.8
CVE-2023-32007EPSS 76%

** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an aut…

Fix: after 3.2.1
Fix from $1,950 2023-05-02
Unstructured Information Management Architecture HIGH 8.8
CVE-2023-28935

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software …

Mitigation only
Fix from $1,950 2023-03-30
Airflow CRITICAL 9.8
CVE-2023-22884EPSS 11%

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apach…

Fix: 2.5.1 / 4.0.0+
Fix from $2,300 2023-01-21
Kylin CRITICAL 9.8
CVE-2022-44621

Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.

Fix: 4.0.3+
Fix from $2,300 2022-12-30
Apache Airflow Providers Apache Hive CRITICAL 9.8
CVE-2022-46421

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive P…

Fix: 5.0.0+
Fix from $2,300 2022-12-20
Dolphinscheduler CRITICAL 9.8
CVE-2022-45462

Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade…

Fix: 2.0.6+
Fix from $2,300 2022-11-23
James HIGH 7.5
CVE-2022-28220

Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, …

Fix: after 3.6.2
Fix from $1,950 2022-09-08
Kylin CRITICAL 9.8
CVE-2021-45456EPSS 89%

Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch bet…

Mitigation only
Fix from $2,300 2022-01-06
James MEDIUM 5.9
CVE-2021-38542

Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-mi…

Fix: 3.6.1+
Fix from $1,600 2022-01-04
Apisix HIGH 7.5
CVE-2021-43557EPSS 15%

The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without…

Fix: 2.10.2+
Fix from $1,950 2021-11-22
Zeppelin CRITICAL 9.8
CVE-2019-10095EPSS 6%

bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affe…

Fix: after 0.9.0
Fix from $2,300 2021-09-02
Thrift HIGH 8.8
CVE-2016-5397EPSS 7%

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affe…

Fix: after 0.9.3
Fix from $1,950 2018-02-12
Struts HIGH 8.1
CVE-2016-3081EPSS 93%

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec…

Patch available
Fix from $1,950 2016-04-26
Ldap Studio HIGH 7.8
CVE-2015-5349

The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers …

Mitigation only
Fix from $1,950 2016-04-11
Cassandra HIGH 7.5
CVE-2015-0225EPSS 7%

The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI in…

No fix yet
Fix from $1,950 2015-04-03
Openoffice HIGH 9.3
CVE-2014-3524EPSS 15%

Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc sp…

Fix: 4.1.1 / 4.2.6+
Fix from $1,950 2014-08-26
Openoffice HIGH 9.3
CVE-2010-0136EPSS 8%

OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remo…

Mitigation only
Fix from $1,950 2010-02-16