Skip to main content

CWE archive

CWE-138 CVEs

Programmatic archive

13 CVEs tagged with CWE-1382 Critical, 4 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2026-26129

Published May 7, 2026

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-20009

Published Mar 4, 2026

A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allo…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-48939

Published Jul 3, 2025

tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in tarteaucitron.js where document.currentScript was accessed…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5878

Published Jun 29, 2025

A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Encoder.encodeForSQL of the SQL Injection Defense. An attack l…

CVSS 5.5 · Medium

CVE-2024-51500

Published Nov 4, 2024

Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast address (0xFFFFFF…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-7012

Published Jul 16, 2024

Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a malicious app to potentially perfo…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-42117

Published May 3, 2024

Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-22288

Published Mar 20, 2023

HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0024

Published May 11, 2022

A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated network-based PAN-OS administrator to upload a specifically created configuration that d…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0750

Published Sep 11, 2018

The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by inject…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1