Skip to main content

CWE archive

CWE-140 CVEs

Programmatic archive

20 CVEs tagged with CWE-1400 Critical, 7 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2026-47162

Published Jun 11, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/p…

CVSS 7.3 · High
evidence mentions
7
Buzz score
38.8
Vendor/product tagsBeta · best-effort

CVE-2026-6322

Published May 5, 2026

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined a…

CVSS 7.5 · High
evidence mentions
35
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-33457

Published Apr 10, 2026

Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33456

Published Apr 10, 2026

Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Liv…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33455

Published Apr 10, 2026

Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient inpu…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21691

Published Jan 7, 2026

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versi…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-52989

Published Jul 11, 2025

An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to m…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32918

Published Jul 4, 2025

Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48879

Published Jun 10, 2025

OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to send a manipulated broken multipart/form-data request to OctoP…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38866

Published May 27, 2025

Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38865

Published Apr 10, 2025

Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestat…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42392

Published Nov 18, 2024

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42385

Published Nov 18, 2024

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42482

Published Aug 12, 2024

fish-shop/syntax-check is a GitHub action for syntax checking fish shell files. Improper neutralization of delimiters in the `pattern` input (specifically the command separator `;…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6542

Published Jul 22, 2024

Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows arbitrary livestatus command execution.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6157

Published Nov 22, 2023

Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for author…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6156

Published Nov 22, 2023

Improper neutralization of livestatus command delimiters in the availability timeline in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execut…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38488

Published Jul 27, 2023

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that might have potential attacker…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31208

Published May 17, 2023

Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for a…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1