CWE-141
8 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-141page 1 of 1
- CVE-2020-7868CRITICALCVSS 9.6EG 9.62021-06-29
A remote code execution vulnerability exists in helpUS(remote administration tool) due to improper validation of parameter of ShellExecutionExA function used for login.
- CVE-2022-29872HIGHCVSS 8.8EG 8.82022-05-20
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly validate parameters of POST requests. This could allow an authenticated attacker to set the device to a denial of service state or to co…
- CVE-2022-29873CRITICALCVSS 9.8EG 9.82022-05-20
A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly validate parameters of certain GET and POST requests. This could allow an unauthenticated attacker to set the device to a denial of serv…
- CVE-2022-41665CRITICALCVSS 9.8EG 8.82022-10-11
A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA00-2AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA10-0AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA10-2AA0) …
- CVE-2023-28815CRITICALCVSS 9.8EG 9.82025-10-17
Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command injection vulnerability. Attackers may exploit this to gain platform privileges and execute arbitrary commands on the sys…
- CVE-2024-0840HIGHCVSS 8.8EG 8.82024-04-29
The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability in the HTTP interface. A remote and authenticated attacker can execute arbitrary code by sending a crafted HTTP request.…
- CVE-2025-20338MEDIUMCVSS 6.0EG 6.02025-09-24
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnera…
- CVE-2025-31329MEDIUMCVSS 6.2EG 6.22025-05-13
SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when…
Map vulnerabilities like CWE-141 to your infrastructure
EchelonGraph correlates every CVE — across CWE-141 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →