Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-28672
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger.
This issue affects Apache Ranger…
Ranger
No fix yet
HIGH 8.8
CVE-2026-30898
An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be …
Airflow
3.2.0+
CRITICAL 9.9
CVE-2016-15057
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum…
Continuum
Mitigation only
CRITICAL 9.8
CVE-2025-60021EPSS 25%
Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to …
Brpc
1.15.0+
HIGH 8.8
CVE-2025-23196
A code injection vulnerability exists in the Ambari Alert Definition
feature, allowing authenticated users to inject and execute arbitrary
shell co…
Ambari
2.7.9+
HIGH 8.8
CVE-2024-45505
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating).
This vulnerabili…
Hertzbeat
1.6.1+
HIGH 7.2
CVE-2023-49898
In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of …
Streampark
2.1.2+
HIGH 8.8
CVE-2023-32007EPSS 76%
** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an aut…
Spark
after 3.2.1
HIGH 8.8
CVE-2023-28935
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software …
Unstructured Information Management Architecture
Mitigation only
CRITICAL 9.8
CVE-2023-22884EPSS 11%
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apach…
Airflow
2.5.1 / 4.0.0+
CRITICAL 9.8
CVE-2022-44621
Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.
Kylin
4.0.3+
CRITICAL 9.8
CVE-2022-46421
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive P…
Apache Airflow Providers Apache Hive
5.0.0+
CRITICAL 9.8
CVE-2022-45462
Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade…
Dolphinscheduler
2.0.6+
HIGH 7.5
CVE-2022-28220
Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, …
James
after 3.6.2
CRITICAL 9.8
CVE-2021-45456EPSS 89%
Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch bet…
Kylin
Mitigation only
MEDIUM 5.9
CVE-2021-38542
Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-mi…
James
3.6.1+
HIGH 7.5
CVE-2021-43557EPSS 15%
The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without…
Apisix
2.10.2+
CRITICAL 9.8
CVE-2019-10095EPSS 6%
bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affe…
Zeppelin
after 0.9.0
HIGH 8.8
CVE-2016-5397EPSS 7%
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affe…
Thrift
after 0.9.3
HIGH 8.1
CVE-2016-3081EPSS 93%
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec…
Struts
Patch available
HIGH 7.8
CVE-2015-5349
The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers …
Ldap Studio
Mitigation only
HIGH 7.5
CVE-2015-0225EPSS 7%
The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI in…
Cassandra
No fix yet
HIGH 9.3
CVE-2014-3524EPSS 15%
Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc sp…
Openoffice
4.1.1 / 4.2.6+
HIGH 9.3
CVE-2010-0136EPSS 8%
OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remo…
Openoffice
Mitigation only