İçeriğe atla
Noroxi

CWE-150 · 65 kayıt

Improper Neutralization of Escape, Meta, or Control Sequences

Bu sınıftaki CVE’ler

65 kayıt

  • CVE-2017-0899
    42Planlayın

    RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.

    KritikCVSS 9,8İstismar yokEPSS %11

    rubygems · rubygems31 Ağu 2017

  • CVE-2025-55754
    41Planlayın

    Apache Tomcat: console manipulation via escape sequences in log messages

    KritikCVSS 9,6İstismar yokEPSS %10

    apache · tomcat27 Eki 2025

  • CVE-2022-30123
    41Planlayın

    A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint a

    KritikCVSS 10,0İstismar yokEPSS %2

    rack project · rack5 Ara 2022

  • CVE-2020-6932
    40Planlayın

    An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platf

    KritikCVSS 9,8İstismar yokEPSS %4

    blackberry · qnx software development platform12 Ağu 2020

  • CVE-2023-3265
    39İzleyin

    An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an at

    KritikCVSS 9,8İstismar yokEPSS %2

    cyberpower · powerpanel server14 Ağu 2023

  • CVE-2023-26055
    39İzleyin

    XWiki Commons may allow privilege escalation to programming rights via user's first name

    KritikCVSS 9,9İstismar yokEPSS %1

    xwiki · commons2 Mar 2023

  • CVE-2025-25286
    39İzleyin

    Crayfish allows Remote Code Execution via Homarus Authorization header

    KritikCVSS 9,8İstismar yokEPSS %1

    islandora · crayfish12 Şub 2025

  • CVE-2025-47284
    39İzleyin

    Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalation

    KritikCVSS 9,9İstismar yokEPSS %0

    gardener · gardener19 May 2025

  • Crayfish Allows Remote Code Execution via hypercube X-Islandora-Args Header

    KritikCVSS 9,5İstismar yok

    Packagist · islandora/crayfish12 Şub 2025

  • CVE-2026-26149
    36İzleyin

    Microsoft Power Apps Desktop Client Spoofing Vulnerability

    KritikCVSS 9,0İstismar yokEPSS %1

    microsoft · power apps14 Nis 2026

  • CVE-2023-28446
    35İzleyin

    Deno is vulnerable to interactive `run` permission prompt spoofing via improper ANSI neutralization

    YüksekCVSS 8,8İstismar yokEPSS %1

    deno · deno24 Mar 2023

  • CVE-2023-30844
    35İzleyin

    Mutagen list and monitor operations do not neutralize control characters in text controlled by remote endpoints

    YüksekCVSS 8,8İstismar yokEPSS %1

    mutagen · mutagen8 May 2023

  • CVE-2025-0975
    35İzleyin

    IBM MQ code execution

    YüksekCVSS 8,8İstismar yokEPSS %1

    ibm · mq appliance27 Şub 2025

  • CVE-2026-3108
    35İzleyin

    Terminal Escape Injection in mmctl Report Posts Command

    YüksekCVSS 8,8İstismar yokEPSS %0

    mattermost · mattermost server26 Mar 2026

  • CVE-2026-19591
    35İzleyin

    OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe bec

    YüksekCVSS 8,8İstismar yokEPSS %0

    openai · codex cli1 Eyl 2026

  • CVE-2025-1692
    35İzleyin

    MongoDB Shell may be susceptible to control character injection via pasting

    YüksekCVSS 8,8İstismar yokEPSS %0

    mongodb · mongosh27 Şub 2025

  • CVE-2023-40185
    34İzleyin

    Shescape on Windows escaping may be bypassed in threaded context

    YüksekCVSS 8,6İstismar yokEPSS %1

    shescape project · shescape23 Ağu 2023

  • CVE-2026-45038
    33İzleyin

    Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Execution

    YüksekCVSS 8,4İstismar yokEPSS %0

    tabby · tabby15 May 2026

  • CVE-2026-90895
    33İzleyin

    MISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal Injection

    YüksekCVSS 8,4İstismar yokEPSS %0

    misp · misp14 Eyl 2026

  • AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters

    YüksekCVSS 8,0İstismar yok

    Packagist · aws/aws-sdk-php27 Mar 2026

  • pickem vulnerable to terminal escape-sequence injection via unsanitized item text

    YüksekCVSS 8,0İstismar yok

    npm · pickem25 Ağu 2026

  • CVE-2026-41526
    31İzleyin

    In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command.

    YüksekCVSS 7,8İstismar yokEPSS %0

    kde · kcoreaddons28 Nis 2026

  • CVE-2025-15311
    31İzleyin

    Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.

    YüksekCVSS 7,8İstismar yokEPSS %0

    tanium · tanos5 Şub 2026

  • CVE-2024-24784
    30İzleyin

    Comments in display names are incorrectly handled in net/mail

    YüksekCVSS 7,5İstismar yokEPSS %1

    go standard library · net/mail5 Mar 2024

  • CVE-2024-36052
    30İzleyin

    RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-202

    YüksekCVSS 7,5İstismar yokEPSS %1

    rarlab · winrar21 May 2024

Tüm zafiyet sınıfları