Vulnerability index

Browse CVEs

31 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2026-62392 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job… Kylin 5.0.4+ Fix from $2,3002026-07-14 HIGH 8.8 CVE-2026-34197 KEVEPSS 97% Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach… Activemq 5.19.4 / 6.2.3+ Fix from $1,9502026-04-07 HIGH 7.8 CVE-2024-45720 On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead… Subversion 1.14.4+ Fix from $1,9502024-10-09 CRITICAL 9.8 CVE-2022-40189 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airfl… Airflow 2.3.0 / 4.0.0+ Fix from $2,3002022-11-22 HIGH 7.8 CVE-2022-41131 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airf… Airflow 2.3.0 / 4.1.0+ Fix from $1,9502022-11-22 MEDIUM 5.5 CVE-2022-40954 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Air… Airflow 2.3.0 / 4.0.0+ Fix from $1,6002022-11-22 CRITICAL 9.8 CVE-2022-38649 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Air… Airflow 2.3.0 / 4.0.0+ Fix from $2,3002022-11-22 CRITICAL 9.8 CVE-2022-24697EPSS 85% Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can… Kylin 2.6.6+ Fix from $2,3002022-10-13 CRITICAL 9.8 CVE-2022-25168 Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary… Hadoop after 3.3.2 Fix from $2,3002022-08-04 HIGH 8.8 CVE-2022-33891 KEVEPSS 93% The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks … Spark after 3.2.1 Fix from $1,9502022-07-18 HIGH 8.8 CVE-2022-33140 The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group … Nifi after 1.16.2 Fix from $1,9502022-06-15 HIGH 8.8 CVE-2022-24288EPSS 78% In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command In… Airflow 2.2.4+ Fix from $1,9502022-02-25 CRITICAL 9.8 CVE-2021-38294EPSS 84% A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4… Storm 1.2.4 / 2.1.1+ Fix from $2,3002021-10-25 CRITICAL 9.8 CVE-2021-33191 From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. Th… Nifi Minifi C\+\+ 0.10.0+ Fix from $2,3002021-08-24 CRITICAL 9.8 CVE-2020-1946EPSS 6% In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. … Spamassassin 3.4.5+ Fix from $2,3002021-03-25 CRITICAL 9.9 CVE-2021-21345EPSS 72% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 HIGH 7.8 CVE-2021-21315 KEVEPSS 91% The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware,… Cordova 5.3.1+ Fix from $1,9502021-02-16 MEDIUM 6.8 CVE-2020-26259EPSS 82% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion o… Struts 1.4.15 / 6.0.0+ Fix from $1,6002020-12-16 CRITICAL 9.8 CVE-2020-11981EPSS 37% An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ… Airflow after 1.10.10 Fix from $2,3002020-07-17 HIGH 8.8 CVE-2020-11978 KEVEPSS 99% An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example D… Airflow 1.10.11+ Fix from $1,9502020-07-17 CRITICAL 9.8 CVE-2020-13925EPSS 20% Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi… Kylin 3.1.0+ Fix from $2,3002020-07-14 HIGH 8.8 CVE-2020-1956 KEVEPSS 97% Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is … Kylin after 2.6.5 Fix from $1,9502020-05-22 HIGH 8.1 CVE-2020-1930EPSS 7% A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configur… Spamassassin 3.4.3+ Fix from $1,9502020-01-30 HIGH 8.1 CVE-2020-1931EPSS 6% A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to… Spamassassin 3.4.3+ Fix from $1,9502020-01-30 MEDIUM 6.7 CVE-2018-11805 In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits ca… Spamassassin 3.4.3+ Fix from $1,6002019-12-12 CRITICAL 9.8 CVE-2013-7285EPSS 84% Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary… Activemq after 1.4.6 Fix from $2,3002019-05-15 HIGH 8.1 CVE-2019-0232EPSS 100% When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93… Tomcat after 9.0.17 Fix from $1,9502019-04-15 HIGH 7.2 CVE-2017-12636EPSS 91% CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-leve… Couchdb 1.7.0+ Fix from $1,9502017-11-14 HIGH 8.1 CVE-2015-7611EPSS 69% Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified v… James Server No fix yet Fix from $1,9502016-06-07 HIGH 7.5 CVE-2002-0061EPSS 50% Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pip… HTTP Server 1.3.24 / 2.0.34+ Fix from $1,9502002-03-21