CWE-114: Process Control
Executing commands or loading libraries from an untrusted source or in an untrusted environment can cause an application to execute malicious commands (and payloads) on behalf of an attacker.
22 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-36250 — AIX Code Execution
- CVE-2024-56346 — IBM AIX command execution
- CVE-2025-36251 — AIX Command Execution
- CVE-2024-56347 — IBM AIX command execution
- CVE-2025-1950 — IBM Hardware Management Console - Power Systems command execution
- CVE-2026-29046 — TinyWeb: HTTP Header Control Character Injection into CGI Environment
- CVE-2024-32004 — Git vulnerable to Remote Code Execution while cloning special-crafted local repositories
- CVE-2025-0160 — IBM FlashSystem code execution
- CVE-2025-23385 — In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace
- CVE-2026-26945 — Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.1
- CVE-2025-46370 — Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Process Control vulnerability. A low pr
Recently published
- CVE-2026-26945 — Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.1
- CVE-2026-29046 — TinyWeb: HTTP Header Control Character Injection into CGI Environment
- CVE-2025-36250 — AIX Code Execution
- CVE-2025-36251 — AIX Command Execution
- CVE-2025-46370 — Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Process Control vulnerability. A low pr
- CVE-2025-1950 — IBM Hardware Management Console - Power Systems command execution
- CVE-2024-56347 — IBM AIX command execution
- CVE-2024-56346 — IBM AIX command execution
- CVE-2025-0160 — IBM FlashSystem code execution
- CVE-2025-23385 — In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace
- CVE-2024-32004 — Git vulnerable to Remote Code Execution while cloning special-crafted local repositories