CWE-141 · 11 records
Improper Neutralization of Parameter/Argument Delimiters
CVEs in this class
11 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-7868No exploit | Helpu remote code execution vulnerabilityhelpu · helpu · CWE-141 | Critical9.8 | — | 2.7% | Jun 29, 2021 |
39Monitor | CVE-2023-28815No exploit | Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command injection vulnerabilithikvision · isecure center · CWE-141 | Critical9.8 | — | 1.4% | Oct 17, 2025 |
38Monitor | CVE-2022-29873No exploit | A vulnerability has been identified in SICAM T (All versions < V3.0).siemens · 7kg8500-0aa00-0aa0 firmware · CWE-141 | Critical9.3 | — | 2.0% | May 20, 2022 |
35Monitor | CVE-2022-41665No exploit | A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA00-2AA0) (All versionssiemens · 7kg8500-0aa00-0aa0 firmware · CWE-141 | High8.8 | — | 1.1% | Oct 11, 2022 |
35Monitor | CVE-2024-0840No exploit | Grandstream UCM Series IP PBX HTTP Parameter Injectiongrandstream · ucm series · CWE-141 | High8.8 | — | 0.9% | Apr 29, 2024 |
35Monitor | CVE-2026-20200Proof of concept | Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerabilitycisco · unified computing system · CWE-141 | High8.8 | — | 0.7% | Aug 5, 2026 |
34Monitor | CVE-2022-29872No exploit | A vulnerability has been identified in SICAM T (All versions < V3.0).siemens · 7kg8500-0aa00-0aa0 firmware · CWE-141 | High8.7 | — | 1.5% | May 20, 2022 |
26Monitor | CVE-2025-20338No exploit | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute acisco · ios xe · CWE-141 | Medium6.7 | — | 0.2% | Sep 24, 2025 |
24Monitor | CVE-2025-31329No exploit | Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platformsap_se · sap netweaver application server abap and abap platform · CWE-141 | Medium6.2 | — | 0.3% | May 12, 2025 |
21Monitor | CVE-2026-66323No exploit | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerabilitymicrosoft · edge chromium · CWE-141 | Medium5.4 | — | 0.4% | Aug 28, 2026 |
8Monitor | CVE-2026-56813No exploit | Cookie attribute injection in Plug.Conn.Cookies.encode/2elixir-plug · plug · CWE-141 | Low2.1 | — | 0.2% | Jul 10, 2026 |
- CVE-2020-786840Plan
Helpu remote code execution vulnerability
CriticalCVSS 9.8No exploitEPSS 3%helpu · helpuJun 29, 2021
- CVE-2023-2881539Monitor
Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command injection vulnerabilit
CriticalCVSS 9.8No exploitEPSS 1%hikvision · isecure centerOct 17, 2025
- CVE-2022-2987338Monitor
A vulnerability has been identified in SICAM T (All versions < V3.0).
CriticalCVSS 9.3No exploitEPSS 2%siemens · 7kg8500-0aa00-0aa0 firmwareMay 20, 2022
- CVE-2022-4166535Monitor
A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA00-2AA0) (All versions
HighCVSS 8.8No exploitEPSS 1%siemens · 7kg8500-0aa00-0aa0 firmwareOct 11, 2022
- CVE-2024-084035Monitor
Grandstream UCM Series IP PBX HTTP Parameter Injection
HighCVSS 8.8No exploitEPSS 1%grandstream · ucm seriesApr 29, 2024
- CVE-2026-2020035Monitor
Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability
HighCVSS 8.8Proof of conceptEPSS 1%cisco · unified computing systemAug 5, 2026
- CVE-2022-2987234Monitor
A vulnerability has been identified in SICAM T (All versions < V3.0).
HighCVSS 8.7No exploitEPSS 2%siemens · 7kg8500-0aa00-0aa0 firmwareMay 20, 2022
- CVE-2025-2033826Monitor
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute a
MediumCVSS 6.7No exploitEPSS 0%cisco · ios xeSep 24, 2025
- CVE-2025-3132924Monitor
Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
MediumCVSS 6.2No exploitEPSS 0%sap_se · sap netweaver application server abap and abap platformMay 12, 2025
- CVE-2026-6632321Monitor
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
MediumCVSS 5.4No exploitEPSS 0%microsoft · edge chromiumAug 28, 2026
- CVE-2026-568138Monitor
Cookie attribute injection in Plug.Conn.Cookies.encode/2
LowCVSS 2.1No exploitEPSS 0%elixir-plug · plugJul 10, 2026