Vulnerability index

Browse CVEs

24 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2026-28672 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger… Ranger No fix yet Fix from $5,7502026-08-10 HIGH 8.8 CVE-2026-30898 An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be … Airflow 3.2.0+ Fix from $1,9502026-04-18 CRITICAL 9.9 CVE-2016-15057 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum… Continuum Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.8 CVE-2025-60021EPSS 25% Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to … Brpc 1.15.0+ Fix from $2,3002026-01-16 HIGH 8.8 CVE-2025-23196 A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell co… Ambari 2.7.9+ Fix from $1,9502025-01-21 HIGH 8.8 CVE-2024-45505 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerabili… Hertzbeat 1.6.1+ Fix from $1,9502024-11-18 HIGH 7.2 CVE-2023-49898 In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of … Streampark 2.1.2+ Fix from $1,9502023-12-15 HIGH 8.8 CVE-2023-32007EPSS 76% ** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an aut… Spark after 3.2.1 Fix from $1,9502023-05-02 HIGH 8.8 CVE-2023-28935 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software … Unstructured Information Management Architecture Mitigation only Fix from $1,9502023-03-30 CRITICAL 9.8 CVE-2023-22884EPSS 11% Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apach… Airflow 2.5.1 / 4.0.0+ Fix from $2,3002023-01-21 CRITICAL 9.8 CVE-2022-44621 Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request. Kylin 4.0.3+ Fix from $2,3002022-12-30 CRITICAL 9.8 CVE-2022-46421 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive P… Apache Airflow Providers Apache Hive 5.0.0+ Fix from $2,3002022-12-20 CRITICAL 9.8 CVE-2022-45462 Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade… Dolphinscheduler 2.0.6+ Fix from $2,3002022-11-23 HIGH 7.5 CVE-2022-28220 Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, … James after 3.6.2 Fix from $1,9502022-09-08 CRITICAL 9.8 CVE-2021-45456EPSS 89% Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch bet… Kylin Mitigation only Fix from $2,3002022-01-06 MEDIUM 5.9 CVE-2021-38542 Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-mi… James 3.6.1+ Fix from $1,6002022-01-04 HIGH 7.5 CVE-2021-43557EPSS 15% The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without… Apisix 2.10.2+ Fix from $1,9502021-11-22 CRITICAL 9.8 CVE-2019-10095EPSS 6% bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affe… Zeppelin after 0.9.0 Fix from $2,3002021-09-02 HIGH 8.8 CVE-2016-5397EPSS 7% The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affe… Thrift after 0.9.3 Fix from $1,9502018-02-12 HIGH 8.1 CVE-2016-3081EPSS 93% Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec… Struts Patch available Fix from $1,9502016-04-26 HIGH 7.8 CVE-2015-5349 The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers … Ldap Studio Mitigation only Fix from $1,9502016-04-11 HIGH 7.5 CVE-2015-0225EPSS 7% The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI in… Cassandra No fix yet Fix from $1,9502015-04-03 HIGH 9.3 CVE-2014-3524EPSS 15% Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc sp… Openoffice 4.1.1 / 4.2.6+ Fix from $1,9502014-08-26 HIGH 9.3 CVE-2010-0136EPSS 8% OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remo… Openoffice Mitigation only Fix from $1,9502010-02-16