CWE-140
18 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-140page 1 of 1
- CVE-2023-31208HIGHCVSS 8.3EG 8.32023-05-17
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
- CVE-2023-38488HIGHCVSS 7.1EG 7.12023-07-27
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that might have potential attackers in the group of authenticated Panel users or that allow ex…
- CVE-2023-6156HIGHCVSS 7.6EG 7.62023-11-22
Improper neutralization of livestatus command delimiters in the availability timeline in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.
- CVE-2023-6157HIGHCVSS 7.6EG 7.62023-11-22
Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.
- CVE-2024-38865HIGHCVSS 8.8EG 8.82025-04-10
Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to …
- CVE-2024-38866HIGHCVSS 7.5EG 7.52025-05-27
Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection
- CVE-2024-42385MEDIUMCVSS 4.0EG 4.02024-11-18
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.
- CVE-2024-42392MEDIUMCVSS 4.0EG 4.02024-11-18
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.
- CVE-2024-42482MEDIUMCVSS 4.8EG 4.82024-08-12
fish-shop/syntax-check is a GitHub action for syntax checking fish shell files. Improper neutralization of delimiters in the `pattern` input (specifically the command separator `;` and command substitution characters `(` and `)`) mean that…
- CVE-2024-6542MEDIUMCVSS 6.5EG 6.52024-07-22
Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows arbitrary livestatus command execution.
- CVE-2025-32918HIGHCVSS 8.8EG 8.82025-07-04
Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.
- CVE-2025-47779HIGHCVSS 7.7EG 7.72025-05-22
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, SIP requests of the type MESSAGE (RFC 3428) authent…
- CVE-2025-48879MEDIUMCVSS 6.5EG 6.52025-06-10
OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to send a manipulated broken multipart/form-data request to OctoPrint and through that make the web server component become u…
- CVE-2025-52989MEDIUMCVSS 5.1EG 5.12025-07-11
An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. A user with limited confi…
- CVE-2026-21691MEDIUMCVSS 5.4EG 5.42026-01-07
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in …
- CVE-2026-33455MEDIUMCVSS 6.3EG 6.32026-04-10
Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input sanitization in search filter plugins.
- CVE-2026-33456HIGHCVSS 7.6EG 7.62026-04-10
Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Livestatus commands via a crafted service description.
- CVE-2026-33457MEDIUMCVSS 6.3EG 6.32026-04-10
Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted service name parameter due to insufficient sanitization of t…
Map vulnerabilities like CWE-140 to your infrastructure
EchelonGraph correlates every CVE — across CWE-140 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →