Skip to main content

CWE archive

CWE-141 CVEs

Programmatic archive

9 CVEs tagged with CWE-1414 Critical, 2 High, 2 Medium, 1 Low, 0 Unrated.

CVE-2026-56813

Published Jul 10, 2026

Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject or override HTTP cookie attributes. The Plug.Conn.Cookies.…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.6

CVE-2023-28815

Published Oct 17, 2025

Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command injection vulnerability. Attackers may exploit this to gain p…

CVSS 9.8 · Critical

CVE-2025-20338

Published Sep 24, 2025

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root on the underl…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-31329

Published May 13, 2025

SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with adminis…

CVSS 6.2 · Medium

CVE-2024-0840

Published Apr 29, 2024

The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability in the HTTP interface. A remote and authenticated attacker c…

CVSS 8.8 · High

CVE-2020-7868

Published Jun 29, 2021

A remote code execution vulnerability exists in helpUS(remote administration tool) due to improper validation of parameter of ShellExecutionExA function used for login.

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1