CWE-141: Improper Neutralization of Parameter/Argument Delimiters
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as parameter or argument delimiters when they are sent to a downstream component.
11 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-0840 — Grandstream UCM Series IP PBX HTTP Parameter Injection
- CVE-2026-20200 — Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability
- CVE-2026-19594 — Path Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege Escalation
- CVE-2025-31329 — Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
- CVE-2025-20338 — A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative pri
- CVE-2026-56813 — Cookie attribute injection in Plug.Conn.Cookies.encode/2
Recently published
- CVE-2026-19594 — Path Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege Escalation
- CVE-2026-20200 — Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability
- CVE-2026-56813 — Cookie attribute injection in Plug.Conn.Cookies.encode/2
- CVE-2025-20338 — A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative pri
- CVE-2025-31329 — Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
- CVE-2024-0840 — Grandstream UCM Series IP PBX HTTP Parameter Injection