Vulnerability index

Browse CVEs

19 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
Openshift Container Platform CRITICAL 9.8
CVE-2026-4408

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check …

Fix: 4.21.0+
Fix from $2,300 2026-05-28
Openshift Container Platform CRITICAL 9.0
CVE-2026-4480EPSS 14%

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print…

Fix: 4.2.1+
Fix from $2,300 2026-05-26
Openshift Ai HIGH 8.8
CVE-2026-42271 KEVEPSS 83%

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints use…

Fix: 1.83.7 / 2.25.8+
Fix from $1,950 2026-05-08
Satellite HIGH 8.8
CVE-2026-0980

A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with …

Fix: after 0.12.1
Fix from $1,950 2026-02-27
Satellite CRITICAL 9.1
CVE-2022-3874

A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile comm…

Mitigation only
Fix from $2,300 2023-09-22
Satellite CRITICAL 9.1
CVE-2023-0118

An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on …

Fix: 6.13.3+
Fix from $2,300 2023-09-20
Virtualization HIGH 8.8
CVE-2021-3621

A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This fl…

Patch available
Fix from $1,950 2021-12-23
Satellite HIGH 7.2
CVE-2021-3584

A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to …

Fix: 2.4.1 / 2.5.1+
Fix from $1,950 2021-12-23
Ansible HIGH 7.3
CVE-2019-14904

A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name…

Fix: 2.7.15 / 2.8.7+
Fix from $1,950 2020-08-26
Cloudforms Management Engine CRITICAL 9.1
CVE-2020-14324

A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerabil…

Fix: 5.11.7.0+
Fix from $2,300 2020-08-11
Cloudforms Management Engine HIGH 7.2
CVE-2019-14894

A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution throu…

Mitigation only
Fix from $1,950 2020-06-22
Ansible Engine HIGH 7.4
CVE-2020-1734

A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=…

Fix: after 3.3.4
Fix from $1,950 2020-03-03
Openshift CRITICAL 9.8
CVE-2013-2060EPSS 6%

The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a req…

No fix yet
Fix from $2,300 2020-01-28
Openshift HIGH 8.8
CVE-2014-0163

Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.

Mitigation only
Fix from $1,950 2019-12-11
Enterprise Linux Desktop HIGH 7.8
CVE-2018-16863

It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSA…

Patch available
Fix from $1,950 2018-12-03
Cloudforms HIGH 7.8
CVE-2018-10905

CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an…

Mitigation only
Fix from $1,950 2018-07-24
Enterprise Linux HIGH 8.8
CVE-2017-15103EPSS 5%

A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted r…

Patch available
Fix from $1,950 2017-12-18
Linux HIGH 10.0
CVE-2003-0041

Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.

Patch available
Fix from $1,950 2003-02-19
Linux CRITICAL 9.8
CVE-1999-0043EPSS 45%

Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.

Mitigation only
Fix from $2,300 1996-12-04