CWE-150 · 65 записей
Improper Neutralization of Escape, Meta, or Control Sequences
CVE этого класса
65 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2017-0899Эксплойта нет | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.rubygems · rubygems · CWE-150 | Критическая9,8 | — | 10,8 % | 31 авг. 2017 г. |
41В плане | CVE-2025-55754Эксплойта нет | Apache Tomcat: console manipulation via escape sequences in log messagesapache · tomcat · CWE-150 | Критическая9,6 | — | 10,2 % | 27 окт. 2025 г. |
41В плане | CVE-2022-30123Эксплойта нет | A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint arack project · rack · CWE-150 | Критическая10,0 | — | 1,9 % | 5 дек. 2022 г. |
40В плане | CVE-2020-6932Эксплойта нет | An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platfblackberry · qnx software development platform · CWE-150 | Критическая9,8 | — | 3,6 % | 12 авг. 2020 г. |
39Наблюдать | CVE-2023-3265Эксплойта нет | An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an atcyberpower · powerpanel server · CWE-150 | Критическая9,8 | — | 1,6 % | 14 авг. 2023 г. |
39Наблюдать | CVE-2023-26055Эксплойта нет | XWiki Commons may allow privilege escalation to programming rights via user's first namexwiki · commons · CWE-150 | Критическая9,9 | — | 1,2 % | 2 мар. 2023 г. |
39Наблюдать | CVE-2025-25286Эксплойта нет | Crayfish allows Remote Code Execution via Homarus Authorization headerislandora · crayfish · CWE-150 | Критическая9,8 | — | 1,0 % | 12 февр. 2025 г. |
39Наблюдать | CVE-2025-47284Эксплойта нет | Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalationgardener · gardener · CWE-150 | Критическая9,9 | — | 0,4 % | 19 мая 2025 г. |
38Наблюдать | GHSA-c2p2-hgjg-9r3fЭксплойта нет | Crayfish Allows Remote Code Execution via hypercube X-Islandora-Args HeaderPackagist · islandora/crayfish · CWE-150 | Критическая9,5 | — | — | 12 февр. 2025 г. |
36Наблюдать | CVE-2026-26149Эксплойта нет | Microsoft Power Apps Desktop Client Spoofing Vulnerabilitymicrosoft · power apps · CWE-150 | Критическая9,0 | — | 0,8 % | 14 апр. 2026 г. |
35Наблюдать | CVE-2023-28446Эксплойта нет | Deno is vulnerable to interactive `run` permission prompt spoofing via improper ANSI neutralizationdeno · deno · CWE-150 | Высокая8,8 | — | 1,1 % | 24 мар. 2023 г. |
35Наблюдать | CVE-2023-30844Эксплойта нет | Mutagen list and monitor operations do not neutralize control characters in text controlled by remote endpointsmutagen · mutagen · CWE-150 | Высокая8,8 | — | 0,7 % | 8 мая 2023 г. |
35Наблюдать | CVE-2025-0975Эксплойта нет | IBM MQ code executionibm · mq appliance · CWE-150 | Высокая8,8 | — | 0,7 % | 27 февр. 2025 г. |
35Наблюдать | CVE-2026-3108Эксплойта нет | Terminal Escape Injection in mmctl Report Posts Commandmattermost · mattermost server · CWE-150 | Высокая8,8 | — | 0,3 % | 26 мар. 2026 г. |
35Наблюдать | CVE-2026-19591Эксплойта нет | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe becopenai · codex cli · CWE-150 | Высокая8,8 | — | 0,3 % | 1 сент. 2026 г. |
35Наблюдать | CVE-2025-1692Эксплойта нет | MongoDB Shell may be susceptible to control character injection via pastingmongodb · mongosh · CWE-150 | Высокая8,8 | — | 0,3 % | 27 февр. 2025 г. |
34Наблюдать | CVE-2023-40185Эксплойта нет | Shescape on Windows escaping may be bypassed in threaded contextshescape project · shescape · CWE-150 | Высокая8,6 | — | 0,7 % | 23 авг. 2023 г. |
33Наблюдать | CVE-2026-45038Эксплойта нет | Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Executiontabby · tabby · CWE-150 | Высокая8,4 | — | 0,2 % | 15 мая 2026 г. |
33Наблюдать | CVE-2026-90895Эксплойта нет | MISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal Injectionmisp · misp · CWE-150 | Высокая8,4 | — | 0,1 % | 14 сент. 2026 г. |
32Наблюдать | GHSA-27qh-8cxx-2cr5Эксплойта нет | AWS SDK for PHP has CloudFront Policy Document Injection via Special CharactersPackagist · aws/aws-sdk-php · CWE-150 | Высокая8,0 | — | — | 27 мар. 2026 г. |
32Наблюдать | GHSA-8qx3-8gm5-9cj2Эксплойта нет | pickem vulnerable to terminal escape-sequence injection via unsanitized item textnpm · pickem · CWE-150 | Высокая8,0 | — | — | 25 авг. 2026 г. |
31Наблюдать | CVE-2026-41526Эксплойта нет | In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command.kde · kcoreaddons · CWE-150 | Высокая7,8 | — | 0,3 % | 28 апр. 2026 г. |
31Наблюдать | CVE-2025-15311Эксплойта нет | Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.tanium · tanos · CWE-150 | Высокая7,8 | — | 0,2 % | 5 февр. 2026 г. |
30Наблюдать | CVE-2024-24784Эксплойта нет | Comments in display names are incorrectly handled in net/mailgo standard library · net/mail · CWE-150 | Высокая7,5 | — | 1,1 % | 5 мар. 2024 г. |
30Наблюдать | CVE-2024-36052Эксплойта нет | RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-202rarlab · winrar · CWE-150 | Высокая7,5 | — | 0,7 % | 21 мая 2024 г. |
- CVE-2017-089942В плане
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %rubygems · rubygems31 авг. 2017 г.
- CVE-2025-5575441В плане
Apache Tomcat: console manipulation via escape sequences in log messages
КритическаяCVSS 9,6Эксплойта нетEPSS 10 %apache · tomcat27 окт. 2025 г.
- CVE-2022-3012341В плане
A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint a
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %rack project · rack5 дек. 2022 г.
- CVE-2020-693240В плане
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platf
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %blackberry · qnx software development platform12 авг. 2020 г.
- CVE-2023-326539Наблюдать
An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an at
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cyberpower · powerpanel server14 авг. 2023 г.
- CVE-2023-2605539Наблюдать
XWiki Commons may allow privilege escalation to programming rights via user's first name
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %xwiki · commons2 мар. 2023 г.
- CVE-2025-2528639Наблюдать
Crayfish allows Remote Code Execution via Homarus Authorization header
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %islandora · crayfish12 февр. 2025 г.
- CVE-2025-4728439Наблюдать
Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalation
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %gardener · gardener19 мая 2025 г.
- GHSA-c2p2-hgjg-9r3f38Наблюдать
Crayfish Allows Remote Code Execution via hypercube X-Islandora-Args Header
КритическаяCVSS 9,5Эксплойта нетPackagist · islandora/crayfish12 февр. 2025 г.
- CVE-2026-2614936Наблюдать
Microsoft Power Apps Desktop Client Spoofing Vulnerability
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %microsoft · power apps14 апр. 2026 г.
- CVE-2023-2844635Наблюдать
Deno is vulnerable to interactive `run` permission prompt spoofing via improper ANSI neutralization
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %deno · deno24 мар. 2023 г.
- CVE-2023-3084435Наблюдать
Mutagen list and monitor operations do not neutralize control characters in text controlled by remote endpoints
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mutagen · mutagen8 мая 2023 г.
- CVE-2025-097535Наблюдать
IBM MQ code execution
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ibm · mq appliance27 февр. 2025 г.
- CVE-2026-310835Наблюдать
Terminal Escape Injection in mmctl Report Posts Command
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mattermost · mattermost server26 мар. 2026 г.
- CVE-2026-1959135Наблюдать
OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe bec
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %openai · codex cli1 сент. 2026 г.
- CVE-2025-169235Наблюдать
MongoDB Shell may be susceptible to control character injection via pasting
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mongodb · mongosh27 февр. 2025 г.
- CVE-2023-4018534Наблюдать
Shescape on Windows escaping may be bypassed in threaded context
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %shescape project · shescape23 авг. 2023 г.
- CVE-2026-4503833Наблюдать
Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Execution
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %tabby · tabby15 мая 2026 г.
- CVE-2026-9089533Наблюдать
MISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal Injection
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %misp · misp14 сент. 2026 г.
- GHSA-27qh-8cxx-2cr532Наблюдать
AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters
ВысокаяCVSS 8,0Эксплойта нетPackagist · aws/aws-sdk-php27 мар. 2026 г.
- GHSA-8qx3-8gm5-9cj232Наблюдать
pickem vulnerable to terminal escape-sequence injection via unsanitized item text
ВысокаяCVSS 8,0Эксплойта нетnpm · pickem25 авг. 2026 г.
- CVE-2026-4152631Наблюдать
In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %kde · kcoreaddons28 апр. 2026 г.
- CVE-2025-1531131Наблюдать
Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %tanium · tanos5 февр. 2026 г.
- CVE-2024-2478430Наблюдать
Comments in display names are incorrectly handled in net/mail
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %go standard library · net/mail5 мар. 2024 г.
- CVE-2024-3605230Наблюдать
RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-202
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rarlab · winrar21 мая 2024 г.