Vulnerability index

Browse CVEs

19 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness OS Command InjectionCWE-78 × clear
CRITICAL 9.8 CVE-2026-4408 A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check … Openshift Container Platform 4.21.0+ Fix from $2,3002026-05-28 CRITICAL 9.0 CVE-2026-4480EPSS 14% A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print… Openshift Container Platform 4.2.1+ Fix from $2,3002026-05-26 HIGH 8.8 CVE-2026-42271 KEVEPSS 83% LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints use… Openshift Ai 1.83.7 / 2.25.8+ Fix from $1,9502026-05-08 HIGH 8.8 CVE-2026-0980 A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with … Satellite after 0.12.1 Fix from $1,9502026-02-27 CRITICAL 9.1 CVE-2022-3874 A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile comm… Satellite Mitigation only Fix from $2,3002023-09-22 CRITICAL 9.1 CVE-2023-0118 An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on … Satellite 6.13.3+ Fix from $2,3002023-09-20 HIGH 8.8 CVE-2021-3621 A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This fl… Virtualization Patch available Fix from $1,9502021-12-23 HIGH 7.2 CVE-2021-3584 A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to … Satellite 2.4.1 / 2.5.1+ Fix from $1,9502021-12-23 HIGH 7.3 CVE-2019-14904 A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name… Ansible 2.7.15 / 2.8.7+ Fix from $1,9502020-08-26 CRITICAL 9.1 CVE-2020-14324 A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerabil… Cloudforms Management Engine 5.11.7.0+ Fix from $2,3002020-08-11 HIGH 7.2 CVE-2019-14894 A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution throu… Cloudforms Management Engine Mitigation only Fix from $1,9502020-06-22 HIGH 7.4 CVE-2020-1734 A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=… Ansible Engine after 3.3.4 Fix from $1,9502020-03-03 CRITICAL 9.8 CVE-2013-2060EPSS 6% The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a req… Openshift No fix yet Fix from $2,3002020-01-28 HIGH 8.8 CVE-2014-0163 Openshift has shell command injection flaws due to unsanitized data being passed into shell commands. Openshift Mitigation only Fix from $1,9502019-12-11 HIGH 7.8 CVE-2018-16863 It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSA… Enterprise Linux Desktop Patch available Fix from $1,9502018-12-03 HIGH 7.8 CVE-2018-10905 CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an… Cloudforms Mitigation only Fix from $1,9502018-07-24 HIGH 8.8 CVE-2017-15103EPSS 5% A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted r… Enterprise Linux Patch available Fix from $1,9502017-12-18 HIGH 10.0 CVE-2003-0041 Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client. Linux Patch available Fix from $1,9502003-02-19 CRITICAL 9.8 CVE-1999-0043EPSS 45% Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others. Linux Mitigation only Fix from $2,3001996-12-04