Перейти к содержимому
Noroxi

CWE-150 · 65 записей

Improper Neutralization of Escape, Meta, or Control Sequences

CVE этого класса

65 записей

  • CVE-2017-0899
    42В плане

    RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.

    КритическаяCVSS 9,8Эксплойта нетEPSS 11 %

    rubygems · rubygems31 авг. 2017 г.

  • CVE-2025-55754
    41В плане

    Apache Tomcat: console manipulation via escape sequences in log messages

    КритическаяCVSS 9,6Эксплойта нетEPSS 10 %

    apache · tomcat27 окт. 2025 г.

  • CVE-2022-30123
    41В плане

    A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint a

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    rack project · rack5 дек. 2022 г.

  • CVE-2020-6932
    40В плане

    An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platf

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    blackberry · qnx software development platform12 авг. 2020 г.

  • CVE-2023-3265
    39Наблюдать

    An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an at

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    cyberpower · powerpanel server14 авг. 2023 г.

  • CVE-2023-26055
    39Наблюдать

    XWiki Commons may allow privilege escalation to programming rights via user's first name

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    xwiki · commons2 мар. 2023 г.

  • CVE-2025-25286
    39Наблюдать

    Crayfish allows Remote Code Execution via Homarus Authorization header

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    islandora · crayfish12 февр. 2025 г.

  • CVE-2025-47284
    39Наблюдать

    Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalation

    КритическаяCVSS 9,9Эксплойта нетEPSS 0 %

    gardener · gardener19 мая 2025 г.

  • GHSA-c2p2-hgjg-9r3f
    38Наблюдать

    Crayfish Allows Remote Code Execution via hypercube X-Islandora-Args Header

    КритическаяCVSS 9,5Эксплойта нет

    Packagist · islandora/crayfish12 февр. 2025 г.

  • CVE-2026-26149
    36Наблюдать

    Microsoft Power Apps Desktop Client Spoofing Vulnerability

    КритическаяCVSS 9,0Эксплойта нетEPSS 1 %

    microsoft · power apps14 апр. 2026 г.

  • CVE-2023-28446
    35Наблюдать

    Deno is vulnerable to interactive `run` permission prompt spoofing via improper ANSI neutralization

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    deno · deno24 мар. 2023 г.

  • CVE-2023-30844
    35Наблюдать

    Mutagen list and monitor operations do not neutralize control characters in text controlled by remote endpoints

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    mutagen · mutagen8 мая 2023 г.

  • CVE-2025-0975
    35Наблюдать

    IBM MQ code execution

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    ibm · mq appliance27 февр. 2025 г.

  • CVE-2026-3108
    35Наблюдать

    Terminal Escape Injection in mmctl Report Posts Command

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    mattermost · mattermost server26 мар. 2026 г.

  • CVE-2026-19591
    35Наблюдать

    OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe bec

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    openai · codex cli1 сент. 2026 г.

  • CVE-2025-1692
    35Наблюдать

    MongoDB Shell may be susceptible to control character injection via pasting

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    mongodb · mongosh27 февр. 2025 г.

  • CVE-2023-40185
    34Наблюдать

    Shescape on Windows escaping may be bypassed in threaded context

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    shescape project · shescape23 авг. 2023 г.

  • CVE-2026-45038
    33Наблюдать

    Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Execution

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    tabby · tabby15 мая 2026 г.

  • CVE-2026-90895
    33Наблюдать

    MISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal Injection

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    misp · misp14 сент. 2026 г.

  • GHSA-27qh-8cxx-2cr5
    32Наблюдать

    AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters

    ВысокаяCVSS 8,0Эксплойта нет

    Packagist · aws/aws-sdk-php27 мар. 2026 г.

  • GHSA-8qx3-8gm5-9cj2
    32Наблюдать

    pickem vulnerable to terminal escape-sequence injection via unsanitized item text

    ВысокаяCVSS 8,0Эксплойта нет

    npm · pickem25 авг. 2026 г.

  • CVE-2026-41526
    31Наблюдать

    In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    kde · kcoreaddons28 апр. 2026 г.

  • CVE-2025-15311
    31Наблюдать

    Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    tanium · tanos5 февр. 2026 г.

  • CVE-2024-24784
    30Наблюдать

    Comments in display names are incorrectly handled in net/mail

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    go standard library · net/mail5 мар. 2024 г.

  • CVE-2024-36052
    30Наблюдать

    RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-202

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    rarlab · winrar21 мая 2024 г.

Все классы уязвимостей