Vulnerability index

Browse CVEs

36 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Debian Linux HIGH 7.8
CVE-2025-63261

AWStats 8.0 is vulnerable to Command Injection via the open function

No fix yet
Fix from $1,950 2026-03-20
Debian Linux HIGH 7.8
CVE-2024-10224EPSS 9%

Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute …

Fix: 1.36+
Fix from $1,950 2024-11-19
Debian Linux MEDIUM 6.5
CVE-2023-51385EPSS 20%

In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by a…

Fix: 9.6+
Fix from $1,600 2023-12-18
Debian Linux CRITICAL 9.8
CVE-2022-48337

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses …

Fix: after 28.2
Fix from $2,300 2023-02-20
Debian Linux HIGH 7.8
CVE-2022-4515

A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified i…

No fix yet
Fix from $1,950 2022-12-20
Debian Linux HIGH 7.8
CVE-2022-45939

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses …

Fix: after 28.2
Fix from $1,950 2022-11-28
Debian Linux HIGH 8.8
CVE-2022-3008

The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. T…

Fix: 2.6.0+
Fix from $1,950 2022-09-05
Debian Linux HIGH 7.8
CVE-2021-45845

The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted …

Patch available
Fix from $1,950 2022-01-25
Debian Linux HIGH 7.8
CVE-2021-45844

Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.

Patch available
Fix from $1,950 2022-01-25
Debian Linux HIGH 7.0
CVE-2021-31799

In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.

Fix: 6.3.1 / 9.2.6.1+
Fix from $1,950 2021-07-30
Debian Linux HIGH 7.8
CVE-2020-35459

An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute comma…

Fix: after 4.2.1
Fix from $1,950 2021-01-12
Debian Linux HIGH 8.8
CVE-2020-26217EPSS 85%

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands on…

Fix: 1.4.14 / 5.15.14+
Fix from $1,950 2020-11-16
Debian Linux CRITICAL 9.8
CVE-2020-16846 KEVEPSS 100%

An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shel…

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2020-11-06
Debian Linux CRITICAL 9.8
CVE-2020-17368

Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.

Fix: after 0.9.62
Fix from $2,300 2020-08-11
Debian Linux MEDIUM 5.3
CVE-2019-20807

In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby,…

Fix: 8.1.0881+
Fix from $1,600 2020-05-28
Debian Linux CRITICAL 9.8
CVE-2020-7247 KEVEPSS 99%

smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as…

Patch available
Fix from $2,300 2020-01-29
Debian Linux CRITICAL 9.8
CVE-2011-2523EPSS 96%

vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.

No fix yet
Fix from $2,300 2019-11-27
Debian Linux HIGH 8.8
CVE-2013-2024

OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.

Fix: after 4.8.2
Fix from $1,950 2019-10-31
Debian Linux MEDIUM 6.8
CVE-2019-18424

An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has acce…

Fix: after 4.12.1
Fix from $1,600 2019-10-31
Debian Linux HIGH 7.8
CVE-2019-14744

In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This r…

Fix: 5.61.0+
Fix from $1,950 2019-08-07
Debian Linux HIGH 7.8
CVE-2019-13638

GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style d…

Patch available
Fix from $1,950 2019-07-26
Debian Linux HIGH 7.8
CVE-2019-13574EPSS 8%

In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because Image.open input…

Fix: 4.9.4+
Fix from $1,950 2019-07-12
Debian Linux CRITICAL 9.8
CVE-2019-11627

gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID.

Fix: 2.10+
Fix from $2,300 2019-04-30
Debian Linux HIGH 7.8
CVE-2018-16741

An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to p…

Fix: 1.2.1+
Fix from $1,950 2018-09-13
Debian Linux HIGH 7.8
CVE-2018-10900EPSS 5%

Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can b…

Fix: 1.2.6+
Fix from $1,950 2018-07-26
Debian Linux HIGH 7.8
CVE-2018-3836

An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argumen…

No fix yet
Fix from $1,950 2018-04-24
Debian Linux CRITICAL 9.8
CVE-2018-7440

An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot roo…

Fix: after 1.75.3
Fix from $2,300 2018-02-23
Debian Linux MEDIUM 6.8
CVE-2018-6791

An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $(…

Fix: 5.12.0+
Fix from $1,600 2018-02-07
Debian Linux HIGH 7.8
CVE-2017-15108

spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the …

Fix: after 0.17.0
Fix from $1,950 2018-01-20
Debian Linux CRITICAL 9.8
CVE-2017-1000487EPSS 6%

Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.

Fix: 3.0.16+
Fix from $2,300 2018-01-03