CWE-146 · 10 записей
Improper Neutralization of Expression/Command Delimiters
CVE этого класса
10 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-20329Эксплойта нет | Cisco Adaptive Security Appliance Software Remote Command Injection Vulnerabilitycisco · adaptive security appliance software · CWE-146 | Критическая9,9 | — | 1,2 % | 23 окт. 2024 г. |
37Наблюдать | CVE-2023-20128Эксплойта нет | Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers Command Injection Vulnerabilitiescisco · rv320 firmware · CWE-146 | Высокая7,2 | — | 30,4 % | 5 апр. 2023 г. |
37Наблюдать | CVE-2023-20117Эксплойта нет | Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers Command Injection Vulnerabilitiescisco · rv320 firmware · CWE-146 | Высокая7,2 | — | 30,4 % | 5 апр. 2023 г. |
35Наблюдать | CVE-2025-53192Эксплойта нет | Apache Commons OGNL: Expression Injection leading to RCEapache · commons ognl · CWE-146 | Высокая8,8 | — | 0,6 % | 18 авг. 2025 г. |
35Наблюдать | CVE-2026-22266Эксплойта нет | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerabdell · powerprotect data manager · CWE-146 | Высокая8,8 | — | 0,3 % | 19 февр. 2026 г. |
31Наблюдать | CVE-2023-20035Эксплойта нет | Cisco IOS XE SD-WAN Software Command Injection Vulnerabilitycisco · ios xe sd-wan · CWE-146 | Высокая7,8 | — | 0,2 % | 23 мар. 2023 г. |
29Наблюдать | CVE-2022-4055Эксплойта нет | When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to tfreedesktop · xdg-utils · CWE-146 | Высокая7,4 | — | 0,7 % | 18 нояб. 2022 г. |
28Наблюдать | CVE-2024-20470Эксплойта нет | Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Remote Code Execution Vulnerabilitycisco · rv340 dual wan gigabit vpn router firmware · CWE-146 | Высокая7,2 | — | 0,6 % | 2 окт. 2024 г. |
26Наблюдать | CVE-2026-20288Эксплойта нет | Cisco IMC Remote Code Execution Vulnerability Remote Code Execution Vulnerabilitycisco · unified computing system · CWE-146 | Средняя6,5 | — | 0,6 % | 5 авг. 2026 г. |
24Наблюдать | CVE-2025-20237Эксплойта нет | A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software cisco · cisco adaptive security appliance (asa) software · CWE-146 | Средняя6,0 | — | 0,2 % | 14 авг. 2025 г. |
- CVE-2024-2032939Наблюдать
Cisco Adaptive Security Appliance Software Remote Command Injection Vulnerability
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %cisco · adaptive security appliance software23 окт. 2024 г.
- CVE-2023-2012837Наблюдать
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers Command Injection Vulnerabilities
ВысокаяCVSS 7,2Эксплойта нетEPSS 30 %cisco · rv320 firmware5 апр. 2023 г.
- CVE-2023-2011737Наблюдать
Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers Command Injection Vulnerabilities
ВысокаяCVSS 7,2Эксплойта нетEPSS 30 %cisco · rv320 firmware5 апр. 2023 г.
- CVE-2025-5319235Наблюдать
Apache Commons OGNL: Expression Injection leading to RCE
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %apache · commons ognl18 авг. 2025 г.
- CVE-2026-2226635Наблюдать
Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerab
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %dell · powerprotect data manager19 февр. 2026 г.
- CVE-2023-2003531Наблюдать
Cisco IOS XE SD-WAN Software Command Injection Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %cisco · ios xe sd-wan23 мар. 2023 г.
- CVE-2022-405529Наблюдать
When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to t
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %freedesktop · xdg-utils18 нояб. 2022 г.
- CVE-2024-2047028Наблюдать
Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Remote Code Execution Vulnerability
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %cisco · rv340 dual wan gigabit vpn router firmware2 окт. 2024 г.
- CVE-2026-2028826Наблюдать
Cisco IMC Remote Code Execution Vulnerability Remote Code Execution Vulnerability
СредняяCVSS 6,5Эксплойта нетEPSS 1 %cisco · unified computing system5 авг. 2026 г.
- CVE-2025-2023724Наблюдать
A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software
СредняяCVSS 6,0Эксплойта нетEPSS 0 %cisco · cisco adaptive security appliance (asa) software14 авг. 2025 г.