CWE-150 · 65 records
Improper Neutralization of Escape, Meta, or Control Sequences
CVEs in this class
65 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2017-0899No exploit | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.rubygems · rubygems · CWE-150 | Critical9.8 | — | 10.8% | Aug 31, 2017 |
41Plan | CVE-2025-55754No exploit | Apache Tomcat: console manipulation via escape sequences in log messagesapache · tomcat · CWE-150 | Critical9.6 | — | 10.2% | Oct 27, 2025 |
41Plan | CVE-2022-30123No exploit | A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint arack project · rack · CWE-150 | Critical10.0 | — | 1.9% | Dec 5, 2022 |
40Plan | CVE-2020-6932No exploit | An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platfblackberry · qnx software development platform · CWE-150 | Critical9.8 | — | 3.6% | Aug 12, 2020 |
39Monitor | CVE-2023-3265No exploit | An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an atcyberpower · powerpanel server · CWE-150 | Critical9.8 | — | 1.6% | Aug 14, 2023 |
39Monitor | CVE-2023-26055No exploit | XWiki Commons may allow privilege escalation to programming rights via user's first namexwiki · commons · CWE-150 | Critical9.9 | — | 1.2% | Mar 2, 2023 |
39Monitor | CVE-2025-25286No exploit | Crayfish allows Remote Code Execution via Homarus Authorization headerislandora · crayfish · CWE-150 | Critical9.8 | — | 1.0% | Feb 12, 2025 |
39Monitor | CVE-2025-47284No exploit | Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalationgardener · gardener · CWE-150 | Critical9.9 | — | 0.4% | May 19, 2025 |
38Monitor | GHSA-c2p2-hgjg-9r3fNo exploit | Crayfish Allows Remote Code Execution via hypercube X-Islandora-Args HeaderPackagist · islandora/crayfish · CWE-150 | Critical9.5 | — | — | Feb 12, 2025 |
36Monitor | CVE-2026-26149No exploit | Microsoft Power Apps Desktop Client Spoofing Vulnerabilitymicrosoft · power apps · CWE-150 | Critical9.0 | — | 0.8% | Apr 14, 2026 |
35Monitor | CVE-2023-28446No exploit | Deno is vulnerable to interactive `run` permission prompt spoofing via improper ANSI neutralizationdeno · deno · CWE-150 | High8.8 | — | 1.1% | Mar 24, 2023 |
35Monitor | CVE-2023-30844No exploit | Mutagen list and monitor operations do not neutralize control characters in text controlled by remote endpointsmutagen · mutagen · CWE-150 | High8.8 | — | 0.7% | May 8, 2023 |
35Monitor | CVE-2025-0975No exploit | IBM MQ code executionibm · mq appliance · CWE-150 | High8.8 | — | 0.7% | Feb 27, 2025 |
35Monitor | CVE-2026-3108No exploit | Terminal Escape Injection in mmctl Report Posts Commandmattermost · mattermost server · CWE-150 | High8.8 | — | 0.3% | Mar 26, 2026 |
35Monitor | CVE-2026-19591No exploit | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe becopenai · codex cli · CWE-150 | High8.8 | — | 0.3% | Sep 1, 2026 |
35Monitor | CVE-2025-1692No exploit | MongoDB Shell may be susceptible to control character injection via pastingmongodb · mongosh · CWE-150 | High8.8 | — | 0.3% | Feb 27, 2025 |
34Monitor | CVE-2023-40185No exploit | Shescape on Windows escaping may be bypassed in threaded contextshescape project · shescape · CWE-150 | High8.6 | — | 0.7% | Aug 23, 2023 |
33Monitor | CVE-2026-45038No exploit | Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Executiontabby · tabby · CWE-150 | High8.4 | — | 0.2% | May 15, 2026 |
33Monitor | CVE-2026-90895No exploit | MISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal Injectionmisp · misp · CWE-150 | High8.4 | — | 0.1% | Sep 14, 2026 |
32Monitor | GHSA-27qh-8cxx-2cr5No exploit | AWS SDK for PHP has CloudFront Policy Document Injection via Special CharactersPackagist · aws/aws-sdk-php · CWE-150 | High8.0 | — | — | Mar 27, 2026 |
32Monitor | GHSA-8qx3-8gm5-9cj2No exploit | pickem vulnerable to terminal escape-sequence injection via unsanitized item textnpm · pickem · CWE-150 | High8.0 | — | — | Aug 25, 2026 |
31Monitor | CVE-2026-41526No exploit | In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command.kde · kcoreaddons · CWE-150 | High7.8 | — | 0.3% | Apr 28, 2026 |
31Monitor | CVE-2025-15311No exploit | Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.tanium · tanos · CWE-150 | High7.8 | — | 0.2% | Feb 5, 2026 |
30Monitor | CVE-2024-24784No exploit | Comments in display names are incorrectly handled in net/mailgo standard library · net/mail · CWE-150 | High7.5 | — | 1.1% | Mar 5, 2024 |
30Monitor | CVE-2024-36052No exploit | RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-202rarlab · winrar · CWE-150 | High7.5 | — | 0.7% | May 21, 2024 |
- CVE-2017-089942Plan
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.
CriticalCVSS 9.8No exploitEPSS 11%rubygems · rubygemsAug 31, 2017
- CVE-2025-5575441Plan
Apache Tomcat: console manipulation via escape sequences in log messages
CriticalCVSS 9.6No exploitEPSS 10%apache · tomcatOct 27, 2025
- CVE-2022-3012341Plan
A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint a
CriticalCVSS 10.0No exploitEPSS 2%rack project · rackDec 5, 2022
- CVE-2020-693240Plan
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platf
CriticalCVSS 9.8No exploitEPSS 4%blackberry · qnx software development platformAug 12, 2020
- CVE-2023-326539Monitor
An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an at
CriticalCVSS 9.8No exploitEPSS 2%cyberpower · powerpanel serverAug 14, 2023
- CVE-2023-2605539Monitor
XWiki Commons may allow privilege escalation to programming rights via user's first name
CriticalCVSS 9.9No exploitEPSS 1%xwiki · commonsMar 2, 2023
- CVE-2025-2528639Monitor
Crayfish allows Remote Code Execution via Homarus Authorization header
CriticalCVSS 9.8No exploitEPSS 1%islandora · crayfishFeb 12, 2025
- CVE-2025-4728439Monitor
Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalation
CriticalCVSS 9.9No exploitEPSS 0%gardener · gardenerMay 19, 2025
- GHSA-c2p2-hgjg-9r3f38Monitor
Crayfish Allows Remote Code Execution via hypercube X-Islandora-Args Header
CriticalCVSS 9.5No exploitPackagist · islandora/crayfishFeb 12, 2025
- CVE-2026-2614936Monitor
Microsoft Power Apps Desktop Client Spoofing Vulnerability
CriticalCVSS 9.0No exploitEPSS 1%microsoft · power appsApr 14, 2026
- CVE-2023-2844635Monitor
Deno is vulnerable to interactive `run` permission prompt spoofing via improper ANSI neutralization
HighCVSS 8.8No exploitEPSS 1%deno · denoMar 24, 2023
- CVE-2023-3084435Monitor
Mutagen list and monitor operations do not neutralize control characters in text controlled by remote endpoints
HighCVSS 8.8No exploitEPSS 1%mutagen · mutagenMay 8, 2023
- CVE-2025-097535Monitor
IBM MQ code execution
HighCVSS 8.8No exploitEPSS 1%ibm · mq applianceFeb 27, 2025
- CVE-2026-310835Monitor
Terminal Escape Injection in mmctl Report Posts Command
HighCVSS 8.8No exploitEPSS 0%mattermost · mattermost serverMar 26, 2026
- CVE-2026-1959135Monitor
OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe bec
HighCVSS 8.8No exploitEPSS 0%openai · codex cliSep 1, 2026
- CVE-2025-169235Monitor
MongoDB Shell may be susceptible to control character injection via pasting
HighCVSS 8.8No exploitEPSS 0%mongodb · mongoshFeb 27, 2025
- CVE-2023-4018534Monitor
Shescape on Windows escaping may be bypassed in threaded context
HighCVSS 8.6No exploitEPSS 1%shescape project · shescapeAug 23, 2023
- CVE-2026-4503833Monitor
Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Execution
HighCVSS 8.4No exploitEPSS 0%tabby · tabbyMay 15, 2026
- CVE-2026-9089533Monitor
MISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal Injection
HighCVSS 8.4No exploitEPSS 0%misp · mispSep 14, 2026
- GHSA-27qh-8cxx-2cr532Monitor
AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters
HighCVSS 8.0No exploitPackagist · aws/aws-sdk-phpMar 27, 2026
- GHSA-8qx3-8gm5-9cj232Monitor
pickem vulnerable to terminal escape-sequence injection via unsanitized item text
HighCVSS 8.0No exploitnpm · pickemAug 25, 2026
- CVE-2026-4152631Monitor
In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command.
HighCVSS 7.8No exploitEPSS 0%kde · kcoreaddonsApr 28, 2026
- CVE-2025-1531131Monitor
Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.
HighCVSS 7.8No exploitEPSS 0%tanium · tanosFeb 5, 2026
- CVE-2024-2478430Monitor
Comments in display names are incorrectly handled in net/mail
HighCVSS 7.5No exploitEPSS 1%go standard library · net/mailMar 5, 2024
- CVE-2024-3605230Monitor
RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-202
HighCVSS 7.5No exploitEPSS 1%rarlab · winrarMay 21, 2024