Skip to main content

CWE archive

CWE-159 CVEs

Programmatic archive

13 CVEs tagged with CWE-1591 Critical, 4 High, 6 Medium, 2 Low, 0 Unrated.

CVE-2026-35536

Published Apr 3, 2026

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted charact…

CVSS 7.2 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-29106

Published Mar 19, 2026

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the value of the return_id request pa…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-2636

Published Feb 25, 2026

This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" weakness, which leads to an unrecoverable inconsistency in the CLFS.sys driver. T…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-61984

Published Oct 6, 2025

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand…

CVSS 3.6 · Low
evidence mentions
10
Buzz score
44.0

CVE-2025-52884

Published Jun 24, 2025

RISC Zero is a zero-knowledge verifiable general computing platform, with Ethereum integration. The risc0-ethereum repository contains Solidity verifier contracts, Steel EVM view…

CVSS 1.7 · Low

CVE-2024-51500

Published Nov 4, 2024

Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast address (0xFFFFFF…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42375

Published Nov 15, 2021

An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characte…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2020-29022

Published Feb 16, 2021

Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManage…

CVSS 5.3 · Medium

CVE-2020-1653

Published Jul 17, 2020

On Juniper Networks Junos OS devices, a stream of TCP packets sent to the Routing Engine (RE) may cause mbuf leak which can lead to Flexible PIC Concentrator (FPC) crash or the sy…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1646

Published Jul 17, 2020

On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific UPDATE for an EBGP peer can lead to a routing process daemon (RPD) crash and restart. This issue o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9505

Published May 8, 2019

The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not sanitize special characters allowing for remote unauthorized changes to configuration…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1