Skip to main content

CWE archive

CWE-150 CVEs

Programmatic archive

68 CVEs tagged with CWE-15015 Critical, 19 High, 19 Medium, 15 Low, 0 Unrated.

CVE-2026-39879

Published Jul 20, 2026

Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), sysl…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-62948

Published Jul 15, 2026

OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefi…

CVSS 9.6 · Critical
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-49147

Published Jul 8, 2026

App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes. When ack prints a filename whose basename contains t…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-11373

Published Jun 22, 2026

Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newline…

CVSS 9.1 · Critical
evidence mentions
6
Buzz score
39.5

CVE-2026-54057

Published Jun 12, 2026

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled bytes, including newlines, into…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50639

Published Jun 10, 2026

Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple met…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-50638

Published Jun 10, 2026

Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple me…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-50637

Published Jun 10, 2026

Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions) allow mutiple metrics, separated by n…

CVSS 8.2 · High
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2026-9270

Published Jun 5, 2026

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-11362

Published Jun 5, 2026

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-46741

Published Jun 4, 2026

Etsy::StatsD versions through 1.002002 for Perl allow metric injections. The metric names and values are not checked for newlines, colons or pipes. Metrics generated from untrust…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-46739

Published Jun 4, 2026

Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-8722

Published Jun 4, 2026

Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrust…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-46740

Published May 26, 2026

Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics gene…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-47090

Published May 18, 2026

Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd and branchUrl values without stripping control characters…

CVSS 2.4 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-8788

Published May 18, 2026

Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections. The values from the set_add method were not checked for newlines, colons or pipes. Metrics generated…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-46720

Published May 17, 2026

Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from…

CVSS 8.2 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-46719

Published May 16, 2026

Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections. The metric names were not checked for newlines, colons or pipes. Metrics generated from untrusted sour…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-45038

Published May 15, 2026

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape control characters from file paths when dragging and dropping a…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45803

Published May 15, 2026

`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified in GitHub CLI that could allow terminal escape sequence inje…

CVSS 3.5 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-41526

Published Apr 28, 2026

In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle meta…

CVSS 6.5 · Medium
evidence mentions
6
Buzz score
39.5
Vendor/product tagsBeta · best-effort

CVE-2026-6019

Published Apr 22, 2026

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </sc…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
40.3
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-40505

Published Apr 16, 2026

MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-26149

Published Apr 14, 2026

Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-35651

Published Apr 10, 2026

OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompts that allows attackers to spoof terminal output. Untrusted…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort
Showing 1-25 of 68 CVEsPage 1 of 3