CWE-114Class1 in KEV

Process Control

Incomplete in the CWE catalog · 22 CVEs mapped

22
CVEs mapped
1
In KEV
8.1
Median CVSS
What it is

Executing commands or loading libraries from an untrusted source or in an untrusted environment can cause an application to execute malicious commands (and payloads) on behalf of an attacker.

Recent examples
5.3cvss
CVE-2026-26945

Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50 and Dell Integrated Dell Remote…

Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain a Process Control vulnerability. A high privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to code execution.

MEDIUMno explanation yet
0%
epss
9.2cvss
CVE-2026-29046

TinyWeb: HTTP Header Control Character Injection into CGI Environment

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them into CGI environment variables (HTTP_*). The parser did not strictly reject dangerous control characters in header lines and header values, including CR, LF, and NUL, and did not consistently defend against encoded forms such as %0d, %0a, and %00. This can enable header value confusion across parser boundaries and may create unsafe data in the CGI execution context. This issue has been patched in version 2.04.

CRITICALno explanation yet
0%
epss
10.0cvss
CVE-2025-36250

AIX Code Execution

🚨 An improper process control in IBM AIX 7.2, 7.3, and VIOS 3.1, 4.1 can let attackers execute arbitrary commands remotely — that's like a chef getting access to the locked pantry and changing the entire menu without anyone noticing! 🔥 Think of it like a restaurant kitchen where the head chef has a secret key to the pantry and can change any recipe at will. The lack of proper controls allows an unwanted guest to slip in and whip up their own dish, potentially ruining everything! An attacker could run any command they choose, potentially leading to devastating consequences like data breaches, system failures, or unauthorized access to sensitive information. This is an absolute nightmare scenario for any organization, leaving the door wide open for major disruptions and damages!

CRITICAL
1%
epss
The record
Technical detail
CWE ID
CWE-114
Abstraction
Class
Structure
Simple
Status
Incomplete
References (1)