Skip to content
Noroxi

CWE-150 · 65 records

Improper Neutralization of Escape, Meta, or Control Sequences

CVEs in this class

65 records

  • RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.

    CriticalCVSS 9.8No exploitEPSS 11%

    rubygems · rubygemsAug 31, 2017

  • Apache Tomcat: console manipulation via escape sequences in log messages

    CriticalCVSS 9.6No exploitEPSS 10%

    apache · tomcatOct 27, 2025

  • A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint a

    CriticalCVSS 10.0No exploitEPSS 2%

    rack project · rackDec 5, 2022

  • An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platf

    CriticalCVSS 9.8No exploitEPSS 4%

    blackberry · qnx software development platformAug 12, 2020

  • CVE-2023-3265
    39Monitor

    An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an at

    CriticalCVSS 9.8No exploitEPSS 2%

    cyberpower · powerpanel serverAug 14, 2023

  • XWiki Commons may allow privilege escalation to programming rights via user's first name

    CriticalCVSS 9.9No exploitEPSS 1%

    xwiki · commonsMar 2, 2023

  • Crayfish allows Remote Code Execution via Homarus Authorization header

    CriticalCVSS 9.8No exploitEPSS 1%

    islandora · crayfishFeb 12, 2025

  • Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalation

    CriticalCVSS 9.9No exploitEPSS 0%

    gardener · gardenerMay 19, 2025

  • Crayfish Allows Remote Code Execution via hypercube X-Islandora-Args Header

    CriticalCVSS 9.5No exploit

    Packagist · islandora/crayfishFeb 12, 2025

  • Microsoft Power Apps Desktop Client Spoofing Vulnerability

    CriticalCVSS 9.0No exploitEPSS 1%

    microsoft · power appsApr 14, 2026

  • Deno is vulnerable to interactive `run` permission prompt spoofing via improper ANSI neutralization

    HighCVSS 8.8No exploitEPSS 1%

    deno · denoMar 24, 2023

  • Mutagen list and monitor operations do not neutralize control characters in text controlled by remote endpoints

    HighCVSS 8.8No exploitEPSS 1%

    mutagen · mutagenMay 8, 2023

  • CVE-2025-0975
    35Monitor

    IBM MQ code execution

    HighCVSS 8.8No exploitEPSS 1%

    ibm · mq applianceFeb 27, 2025

  • CVE-2026-3108
    35Monitor

    Terminal Escape Injection in mmctl Report Posts Command

    HighCVSS 8.8No exploitEPSS 0%

    mattermost · mattermost serverMar 26, 2026

  • OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe bec

    HighCVSS 8.8No exploitEPSS 0%

    openai · codex cliSep 1, 2026

  • CVE-2025-1692
    35Monitor

    MongoDB Shell may be susceptible to control character injection via pasting

    HighCVSS 8.8No exploitEPSS 0%

    mongodb · mongoshFeb 27, 2025

  • Shescape on Windows escaping may be bypassed in threaded context

    HighCVSS 8.6No exploitEPSS 1%

    shescape project · shescapeAug 23, 2023

  • Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Execution

    HighCVSS 8.4No exploitEPSS 0%

    tabby · tabbyMay 15, 2026

  • MISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal Injection

    HighCVSS 8.4No exploitEPSS 0%

    misp · mispSep 14, 2026

  • AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters

    HighCVSS 8.0No exploit

    Packagist · aws/aws-sdk-phpMar 27, 2026

  • pickem vulnerable to terminal escape-sequence injection via unsanitized item text

    HighCVSS 8.0No exploit

    npm · pickemAug 25, 2026

  • In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command.

    HighCVSS 7.8No exploitEPSS 0%

    kde · kcoreaddonsApr 28, 2026

  • Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.

    HighCVSS 7.8No exploitEPSS 0%

    tanium · tanosFeb 5, 2026

  • Comments in display names are incorrectly handled in net/mail

    HighCVSS 7.5No exploitEPSS 1%

    go standard library · net/mailMar 5, 2024

  • RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-202

    HighCVSS 7.5No exploitEPSS 1%

    rarlab · winrarMay 21, 2024

All vulnerability classes