Threats Tagged 'cwe-140'
View all threats tagged with 'cwe-140'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-140'
Click on any threat for detailed analysis and mitigation recommendations
0 Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted service name parameter due to insufficient sanitization of the service description value. Join the discussion | CVE Database V5 | 04/10/2026, 08:31:35 UTC Added: 04/10/2026, 08:50:47 UTC |
0 Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Livestatus commands via a crafted service description. Join the discussion | CVE Database V5 | 04/10/2026, 08:31:27 UTC Added: 04/10/2026, 08:50:47 UTC |
0 Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input sanitization in search filter plugins. Join the discussion | CVE Database V5 | 04/10/2026, 08:30:20 UTC Added: 04/10/2026, 08:50:47 UTC |
0 iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `CIccTag:IsTypeCompressed()`. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available. Join the discussion | CVE Database V5 | 01/07/2026, 21:53:02 UTC Added: 01/07/2026, 22:02:35 UTC |
0 An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. A user with limited configuration and commit permissions, using a specifically crafted annotate configuration command, can change any part of the device configuration. This issue affects: Junos OS: * all versions before 22.2R3-S7, * 22.4 versions before 22.4R3-S7, * 23.2 versions before 23.2R2-S4, * 23.4 versions before 23.4R2-S4, * 24.2 versions before 24.2R2-S1, * 24.4 versions before 24.4R1-S2, 24.4R2; Junos OS Evolved: * all versions before 22.4R3-S7-EVO, * 23.2-EVO versions before 23.2R2-S4-EVO, * 23.4-EVO versions before 23.4R2-S5-EVO, * 24.2-EVO versions before 24.2R2-S1-EVO * 24.4-EVO versions before 24.4R2-EVO. Join the discussion | CVE Database V5 | 07/11/2025, 15:10:47 UTC Added: 07/11/2025, 15:31:07 UTC |
0 Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands. Join the discussion | CVE Database V5 | 07/04/2025, 08:12:21 UTC Added: 07/04/2025, 08:24:29 UTC |
0 OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to send a manipulated broken multipart/form-data request to OctoPrint and through that make the web server component become unresponsive. The issue can be triggered by a broken multipart/form-data request lacking an end boundary to any of OctoPrint's endpoints implemented through the octoprint.server.util.tornado.UploadStorageFallbackHandler request handler. The request handler will get stuck in an endless busy loop, looking for a part of the request that will never come. As Tornado is single-threaded, that will effectively block the whole web server. The vulnerability has been patched in version 1.11.2. Join the discussion | CVE Database V5 | 06/10/2025, 15:23:54 UTC Added: 06/10/2025, 18:54:11 UTC |
Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection Join the discussion | CVE Database V5 | 05/27/2025, 07:01:35 UTC Added: 05/27/2025, 12:20:35 UTC |
0 Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters. Join the discussion | CVE Database V5 | 11/18/2024, 09:07:09 UTC Added: 09/08/2026, 08:53:41 UTC |
0 Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters. Join the discussion | CVE Database V5 | 11/18/2024, 09:05:03 UTC Added: 09/08/2026, 08:53:41 UTC |
Showing 1 to 10 of 10 results