CWE-149 · 5 records
Improper Neutralization of Quoting Syntax
CVEs in this class
5 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
59Plan | CVE-2025-1094Weaponized | PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validationCWE-149 | High8.1 | — | 90.0% | Feb 13, 2025 |
37Monitor | CVE-2018-25135No exploit | Anviz AIM CrossChex Standard 4.3.6.0 CSV Injection via User Importanviz biometric technology co., ltd. · anviz aim crosschex standard · CWE-149 | Critical9.3 | — | 0.7% | Dec 24, 2025 |
33Monitor | CVE-2025-43878No exploit | F5OS-A/C CLI vulnerabilityf5 · f5os-a · CWE-149 | High8.3 | — | 0.2% | May 7, 2025 |
32Monitor | CVE-2026-42511No exploit | Remote code execution via malicious DHCP optionsfreebsd · freebsd · CWE-149 | High8.1 | — | 0.4% | Apr 30, 2026 |
12Monitor | CVE-2023-36479No exploit | Jetty vulnerable to errant command quoting in CGI Servleteclipse · jetty · CWE-149 | Low3.1 | — | 1.2% | Sep 15, 2023 |
- CVE-2025-109459Plan
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
HighCVSS 8.1WeaponizedEPSS 90%Feb 13, 2025
- CVE-2018-2513537Monitor
Anviz AIM CrossChex Standard 4.3.6.0 CSV Injection via User Import
CriticalCVSS 9.3No exploitEPSS 1%anviz biometric technology co., ltd. · anviz aim crosschex standardDec 24, 2025
- CVE-2025-4387833Monitor
F5OS-A/C CLI vulnerability
HighCVSS 8.3No exploitEPSS 0%f5 · f5os-aMay 7, 2025
- CVE-2026-4251132Monitor
Remote code execution via malicious DHCP options
HighCVSS 8.1No exploitEPSS 0%freebsd · freebsdApr 30, 2026
- CVE-2023-3647912Monitor
Jetty vulnerable to errant command quoting in CGI Servlet
LowCVSS 3.1No exploitEPSS 1%eclipse · jettySep 15, 2023