Skip to main content

CWE archive

CWE-149 CVEs

Programmatic archive

5 CVEs tagged with CWE-1491 Critical, 3 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2026-42511

Published Apr 30, 2026

The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subseq…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2018-25135

Published Dec 24, 2025

Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attack…

CVSS 9.3 · Critical

CVE-2025-1094

Published Feb 13, 2025

Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input…

CVSS 8.1 · High
evidence mentions
12
Buzz score
45.6

CVE-2023-36479

Published Sep 15, 2023

Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command exe…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1