← Back

Anomali

anomali

2 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Agave
agave
Match
match

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Anomali
1Match
Jun 20, 2025
Jan 19, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Anomali Match before 4.6.2 allows OS Command Injection. An authenticated admin user can inject and execute operating system commands. This arises from improper handling of untrusted input, enabling an attacker to elevate...Show more
Anomali Match before 4.6.2 allows OS Command Injection. An authenticated admin user can inject and execute operating system commands. This arises from improper handling of untrusted input, enabling an attacker to elevate privileges, execute system commands, and potentially compromise the underlying operating system. The fixed versions are 4.4.5, 4.5.4, and 4.6.2. The earliest affected version is 4.3.Show less
1Anomali
1Agave
Jun 17, 2026
May 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Anomali Agave (formerly Drupot) through 1.0.0 fails to avoid fingerprinting by including predictable data and minimal variation in size within HTML templates, giving attackers the ability to detect and avoid this system.