CWE-150 · 65 kayıt
Improper Neutralization of Escape, Meta, or Control Sequences
Bu sınıftaki CVE’ler
65 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2017-0899İstismar yok | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.rubygems · rubygems · CWE-150 | Kritik9,8 | — | %10,8 | 31 Ağu 2017 |
41Planlayın | CVE-2025-55754İstismar yok | Apache Tomcat: console manipulation via escape sequences in log messagesapache · tomcat · CWE-150 | Kritik9,6 | — | %10,2 | 27 Eki 2025 |
41Planlayın | CVE-2022-30123İstismar yok | A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint arack project · rack · CWE-150 | Kritik10,0 | — | %1,9 | 5 Ara 2022 |
40Planlayın | CVE-2020-6932İstismar yok | An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platfblackberry · qnx software development platform · CWE-150 | Kritik9,8 | — | %3,6 | 12 Ağu 2020 |
39İzleyin | CVE-2023-3265İstismar yok | An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an atcyberpower · powerpanel server · CWE-150 | Kritik9,8 | — | %1,6 | 14 Ağu 2023 |
39İzleyin | CVE-2023-26055İstismar yok | XWiki Commons may allow privilege escalation to programming rights via user's first namexwiki · commons · CWE-150 | Kritik9,9 | — | %1,2 | 2 Mar 2023 |
39İzleyin | CVE-2025-25286İstismar yok | Crayfish allows Remote Code Execution via Homarus Authorization headerislandora · crayfish · CWE-150 | Kritik9,8 | — | %1,0 | 12 Şub 2025 |
39İzleyin | CVE-2025-47284İstismar yok | Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalationgardener · gardener · CWE-150 | Kritik9,9 | — | %0,4 | 19 May 2025 |
38İzleyin | GHSA-c2p2-hgjg-9r3fİstismar yok | Crayfish Allows Remote Code Execution via hypercube X-Islandora-Args HeaderPackagist · islandora/crayfish · CWE-150 | Kritik9,5 | — | — | 12 Şub 2025 |
36İzleyin | CVE-2026-26149İstismar yok | Microsoft Power Apps Desktop Client Spoofing Vulnerabilitymicrosoft · power apps · CWE-150 | Kritik9,0 | — | %0,8 | 14 Nis 2026 |
35İzleyin | CVE-2023-28446İstismar yok | Deno is vulnerable to interactive `run` permission prompt spoofing via improper ANSI neutralizationdeno · deno · CWE-150 | Yüksek8,8 | — | %1,1 | 24 Mar 2023 |
35İzleyin | CVE-2023-30844İstismar yok | Mutagen list and monitor operations do not neutralize control characters in text controlled by remote endpointsmutagen · mutagen · CWE-150 | Yüksek8,8 | — | %0,7 | 8 May 2023 |
35İzleyin | CVE-2025-0975İstismar yok | IBM MQ code executionibm · mq appliance · CWE-150 | Yüksek8,8 | — | %0,7 | 27 Şub 2025 |
35İzleyin | CVE-2026-3108İstismar yok | Terminal Escape Injection in mmctl Report Posts Commandmattermost · mattermost server · CWE-150 | Yüksek8,8 | — | %0,3 | 26 Mar 2026 |
35İzleyin | CVE-2026-19591İstismar yok | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe becopenai · codex cli · CWE-150 | Yüksek8,8 | — | %0,3 | 1 Eyl 2026 |
35İzleyin | CVE-2025-1692İstismar yok | MongoDB Shell may be susceptible to control character injection via pastingmongodb · mongosh · CWE-150 | Yüksek8,8 | — | %0,3 | 27 Şub 2025 |
34İzleyin | CVE-2023-40185İstismar yok | Shescape on Windows escaping may be bypassed in threaded contextshescape project · shescape · CWE-150 | Yüksek8,6 | — | %0,7 | 23 Ağu 2023 |
33İzleyin | CVE-2026-45038İstismar yok | Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Executiontabby · tabby · CWE-150 | Yüksek8,4 | — | %0,2 | 15 May 2026 |
33İzleyin | CVE-2026-90895İstismar yok | MISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal Injectionmisp · misp · CWE-150 | Yüksek8,4 | — | %0,1 | 14 Eyl 2026 |
32İzleyin | GHSA-27qh-8cxx-2cr5İstismar yok | AWS SDK for PHP has CloudFront Policy Document Injection via Special CharactersPackagist · aws/aws-sdk-php · CWE-150 | Yüksek8,0 | — | — | 27 Mar 2026 |
32İzleyin | GHSA-8qx3-8gm5-9cj2İstismar yok | pickem vulnerable to terminal escape-sequence injection via unsanitized item textnpm · pickem · CWE-150 | Yüksek8,0 | — | — | 25 Ağu 2026 |
31İzleyin | CVE-2026-41526İstismar yok | In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command.kde · kcoreaddons · CWE-150 | Yüksek7,8 | — | %0,3 | 28 Nis 2026 |
31İzleyin | CVE-2025-15311İstismar yok | Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.tanium · tanos · CWE-150 | Yüksek7,8 | — | %0,2 | 5 Şub 2026 |
30İzleyin | CVE-2024-24784İstismar yok | Comments in display names are incorrectly handled in net/mailgo standard library · net/mail · CWE-150 | Yüksek7,5 | — | %1,1 | 5 Mar 2024 |
30İzleyin | CVE-2024-36052İstismar yok | RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-202rarlab · winrar · CWE-150 | Yüksek7,5 | — | %0,7 | 21 May 2024 |
- CVE-2017-089942Planlayın
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.
KritikCVSS 9,8İstismar yokEPSS %11rubygems · rubygems31 Ağu 2017
- CVE-2025-5575441Planlayın
Apache Tomcat: console manipulation via escape sequences in log messages
KritikCVSS 9,6İstismar yokEPSS %10apache · tomcat27 Eki 2025
- CVE-2022-3012341Planlayın
A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint a
KritikCVSS 10,0İstismar yokEPSS %2rack project · rack5 Ara 2022
- CVE-2020-693240Planlayın
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platf
KritikCVSS 9,8İstismar yokEPSS %4blackberry · qnx software development platform12 Ağu 2020
- CVE-2023-326539İzleyin
An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an at
KritikCVSS 9,8İstismar yokEPSS %2cyberpower · powerpanel server14 Ağu 2023
- CVE-2023-2605539İzleyin
XWiki Commons may allow privilege escalation to programming rights via user's first name
KritikCVSS 9,9İstismar yokEPSS %1xwiki · commons2 Mar 2023
- CVE-2025-2528639İzleyin
Crayfish allows Remote Code Execution via Homarus Authorization header
KritikCVSS 9,8İstismar yokEPSS %1islandora · crayfish12 Şub 2025
- CVE-2025-4728439İzleyin
Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalation
KritikCVSS 9,9İstismar yokEPSS %0gardener · gardener19 May 2025
- GHSA-c2p2-hgjg-9r3f38İzleyin
Crayfish Allows Remote Code Execution via hypercube X-Islandora-Args Header
KritikCVSS 9,5İstismar yokPackagist · islandora/crayfish12 Şub 2025
- CVE-2026-2614936İzleyin
Microsoft Power Apps Desktop Client Spoofing Vulnerability
KritikCVSS 9,0İstismar yokEPSS %1microsoft · power apps14 Nis 2026
- CVE-2023-2844635İzleyin
Deno is vulnerable to interactive `run` permission prompt spoofing via improper ANSI neutralization
YüksekCVSS 8,8İstismar yokEPSS %1deno · deno24 Mar 2023
- CVE-2023-3084435İzleyin
Mutagen list and monitor operations do not neutralize control characters in text controlled by remote endpoints
YüksekCVSS 8,8İstismar yokEPSS %1mutagen · mutagen8 May 2023
- CVE-2025-097535İzleyin
IBM MQ code execution
YüksekCVSS 8,8İstismar yokEPSS %1ibm · mq appliance27 Şub 2025
- CVE-2026-310835İzleyin
Terminal Escape Injection in mmctl Report Posts Command
YüksekCVSS 8,8İstismar yokEPSS %0mattermost · mattermost server26 Mar 2026
- CVE-2026-1959135İzleyin
OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe bec
YüksekCVSS 8,8İstismar yokEPSS %0openai · codex cli1 Eyl 2026
- CVE-2025-169235İzleyin
MongoDB Shell may be susceptible to control character injection via pasting
YüksekCVSS 8,8İstismar yokEPSS %0mongodb · mongosh27 Şub 2025
- CVE-2023-4018534İzleyin
Shescape on Windows escaping may be bypassed in threaded context
YüksekCVSS 8,6İstismar yokEPSS %1shescape project · shescape23 Ağu 2023
- CVE-2026-4503833İzleyin
Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Execution
YüksekCVSS 8,4İstismar yokEPSS %0tabby · tabby15 May 2026
- CVE-2026-9089533İzleyin
MISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal Injection
YüksekCVSS 8,4İstismar yokEPSS %0misp · misp14 Eyl 2026
- GHSA-27qh-8cxx-2cr532İzleyin
AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters
YüksekCVSS 8,0İstismar yokPackagist · aws/aws-sdk-php27 Mar 2026
- GHSA-8qx3-8gm5-9cj232İzleyin
pickem vulnerable to terminal escape-sequence injection via unsanitized item text
YüksekCVSS 8,0İstismar yoknpm · pickem25 Ağu 2026
- CVE-2026-4152631İzleyin
In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command.
YüksekCVSS 7,8İstismar yokEPSS %0kde · kcoreaddons28 Nis 2026
- CVE-2025-1531131İzleyin
Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.
YüksekCVSS 7,8İstismar yokEPSS %0tanium · tanos5 Şub 2026
- CVE-2024-2478430İzleyin
Comments in display names are incorrectly handled in net/mail
YüksekCVSS 7,5İstismar yokEPSS %1go standard library · net/mail5 Mar 2024
- CVE-2024-3605230İzleyin
RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-202
YüksekCVSS 7,5İstismar yokEPSS %1rarlab · winrar21 May 2024