← All CVEs

CVE-2025-3361

critical · 9.8

The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

9.8
CVSS
1.3%
EPSS (exploit prob.)
70th
EPSS percentile
2025-04-08
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-3361