Vulnerability index

Browse CVEs

31 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Kylin CRITICAL 9.8
CVE-2026-62392

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job…

Fix: 5.0.4+
Fix from $2,300 2026-07-14
Activemq HIGH 8.8
CVE-2026-34197 KEVEPSS 97%

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach…

Fix: 5.19.4 / 6.2.3+
Fix from $1,950 2026-04-07
Subversion HIGH 7.8
CVE-2024-45720

On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead…

Fix: 1.14.4+
Fix from $1,950 2024-10-09
Airflow CRITICAL 9.8
CVE-2022-40189

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airfl…

Fix: 2.3.0 / 4.0.0+
Fix from $2,300 2022-11-22
Airflow HIGH 7.8
CVE-2022-41131

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airf…

Fix: 2.3.0 / 4.1.0+
Fix from $1,950 2022-11-22
Airflow MEDIUM 5.5
CVE-2022-40954

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Air…

Fix: 2.3.0 / 4.0.0+
Fix from $1,600 2022-11-22
Airflow CRITICAL 9.8
CVE-2022-38649

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Air…

Fix: 2.3.0 / 4.0.0+
Fix from $2,300 2022-11-22
Kylin CRITICAL 9.8
CVE-2022-24697EPSS 85%

Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can…

Fix: 2.6.6+
Fix from $2,300 2022-10-13
Hadoop CRITICAL 9.8
CVE-2022-25168

Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary…

Fix: after 3.3.2
Fix from $2,300 2022-08-04
Spark HIGH 8.8
CVE-2022-33891 KEVEPSS 93%

The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks …

Fix: after 3.2.1
Fix from $1,950 2022-07-18
Nifi HIGH 8.8
CVE-2022-33140

The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group …

Fix: after 1.16.2
Fix from $1,950 2022-06-15
Airflow HIGH 8.8
CVE-2022-24288EPSS 78%

In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command In…

Fix: 2.2.4+
Fix from $1,950 2022-02-25
Storm CRITICAL 9.8
CVE-2021-38294EPSS 84%

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4…

Fix: 1.2.4 / 2.1.1+
Fix from $2,300 2021-10-25
Nifi Minifi C\+\+ CRITICAL 9.8
CVE-2021-33191

From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. Th…

Fix: 0.10.0+
Fix from $2,300 2021-08-24
Spamassassin CRITICAL 9.8
CVE-2020-1946EPSS 6%

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. …

Fix: 3.4.5+
Fix from $2,300 2021-03-25
Activemq CRITICAL 9.9
CVE-2021-21345EPSS 72%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Cordova HIGH 7.8
CVE-2021-21315 KEVEPSS 91%

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware,…

Fix: 5.3.1+
Fix from $1,950 2021-02-16
Struts MEDIUM 6.8
CVE-2020-26259EPSS 82%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion o…

Fix: 1.4.15 / 6.0.0+
Fix from $1,600 2020-12-16
Airflow CRITICAL 9.8
CVE-2020-11981EPSS 37%

An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ…

Fix: after 1.10.10
Fix from $2,300 2020-07-17
Airflow HIGH 8.8
CVE-2020-11978 KEVEPSS 99%

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example D…

Fix: 1.10.11+
Fix from $1,950 2020-07-17
Kylin CRITICAL 9.8
CVE-2020-13925EPSS 20%

Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi…

Fix: 3.1.0+
Fix from $2,300 2020-07-14
Kylin HIGH 8.8
CVE-2020-1956 KEVEPSS 97%

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is …

Fix: after 2.6.5
Fix from $1,950 2020-05-22
Spamassassin HIGH 8.1
CVE-2020-1930EPSS 7%

A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configur…

Fix: 3.4.3+
Fix from $1,950 2020-01-30
Spamassassin HIGH 8.1
CVE-2020-1931EPSS 6%

A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to…

Fix: 3.4.3+
Fix from $1,950 2020-01-30
Spamassassin MEDIUM 6.7
CVE-2018-11805

In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits ca…

Fix: 3.4.3+
Fix from $1,600 2019-12-12
Activemq CRITICAL 9.8
CVE-2013-7285EPSS 84%

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary…

Fix: after 1.4.6
Fix from $2,300 2019-05-15
Tomcat HIGH 8.1
CVE-2019-0232EPSS 100%

When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93…

Fix: after 9.0.17
Fix from $1,950 2019-04-15
Couchdb HIGH 7.2
CVE-2017-12636EPSS 91%

CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-leve…

Fix: 1.7.0+
Fix from $1,950 2017-11-14
James Server HIGH 8.1
CVE-2015-7611EPSS 69%

Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified v…

No fix yet
Fix from $1,950 2016-06-07
HTTP Server HIGH 7.5
CVE-2002-0061EPSS 50%

Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pip…

Fix: 1.3.24 / 2.0.34+
Fix from $1,950 2002-03-21