Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-150
Weakness type CWE-150 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 35 | 35 | 0 |
Monthly trend
▂▁▁▂▂█▃▇▇▂
2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 1 · 2026-06 10 · 2026-07 3 · 2026-08 8 · 2026-09 9 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-73414 | 9.2 | 57.9 | — | Shescape: Shell injection via unescaped parentheses on Windows with CMD |
| CVE-2026-64654 | 5.3 | 54.0 | — | GitHub CLI: Terminal escape sequence injection in multiple `gh` commands |
| CVE-2026-26149 | 9.0 | 54.0 | — | Microsoft Power Apps Desktop Client Spoofing Vulnerability |
| CVE-2026-82710 | 2.3 | 50.0 | — | Terminal escape sequence injection in mix usage_rules.search_docs via package documenta… |
| CVE-2026-21521 | 7.4 | 46.8 | — | Word Copilot Information Disclosure Vulnerability |
| CVE-2026-62948 | 9.6 | 45.8 | — | OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN… |
| CVE-2026-11373 | 9.1 | 45.1 | — | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections |
| CVE-2026-50638 | 9.1 | 44.3 | — | Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against… |
| CVE-2026-9270 | 9.1 | 43.2 | — | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections |
| CVE-2026-82584 | 2.3 | 42.7 | — | Terminal escape sequence injection in the mix igniter.install confirmation prompt via p… |
| CVE-2026-50637 | 8.2 | 40.9 | — | Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against me… |
| CVE-2026-49147 | 7.5 | 39.8 | — | App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences f… |
| CVE-2026-11362 | 9.8 | 36.6 | — | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags |
| CVE-2026-93421 | 5.3 | 32.3 | — | Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint |
| CVE-2026-46739 | 5.3 | 32.0 | — | Net::Statsd versions before 0.13 for Perl allow metric injections |
| CVE-2026-46741 | 7.5 | 31.9 | — | Etsy::StatsD versions through 1.002002 for Perl allow metric injections |
| CVE-2026-46740 | 5.3 | 31.7 | — | Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections |
| CVE-2026-50639 | 6.5 | 31.4 | — | Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against … |
| CVE-2026-73035 | 5.3 | 29.0 | — | npm-check-updates 23.0.2 Terminal Injection via Unsanitized Escape Sequences |
| CVE-2026-102601 | 3.5 | 24.8 | — | Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetected) check i… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| pevans | 3 |
| ash-project | 2 |
| binary | 2 |
| kovidgoyal | 2 |
| microsoft | 2 |
| bash-it | 1 |
| canop | 1 |
| cli | 1 |
| cosimo | 1 |
| dalance | 1 |
| ericcornelissen | 1 |
| jandedobbeleer | 1 |
| jasei | 1 |
| mesop-dev | 1 |
| meta platforms | 1 |