CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 10 of 105
- CVE-2020-15238HIGHCVSS 7.1EG 7.12020-10-27
Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-mechanism is prone to an argument injection vulnerability. The impact highly depends on the system configuration. If Polk…
- CVE-2020-15244HIGHCVSS 8.0EG 8.02020-10-21
In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap credentials that can be used to trigger RCE via PHP Object Injection through product attributes and a product. The issue …
- CVE-2020-15252HIGHCVSS 8.5EG 8.52020-10-16
In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet context which contains tools allowing to instantiate arbitrary Java objects and invoke met…
- CVE-2020-15255HIGHCVSS 8.7EG 8.72020-10-16
In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equa…
- CVE-2020-15348CRITICALCVSS 9.8EG 9.82020-06-26
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python code.
- CVE-2020-15477CRITICALCVSS 9.8EG 9.82020-07-23
The WebControl in RaspberryTortoise through 2012-10-28 is vulnerable to remote code execution via shell metacharacters in a URI. The file nodejs/raspberryTortoise.js has no validation on the parameter incomingString before passing it to th…
- CVE-2020-15489CRITICALCVSS 9.8EG 9.82020-07-01
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges.
- CVE-2020-15690CRITICALCVSS 9.8EG 9.82021-01-30
In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character.
- CVE-2020-15693MEDIUMCVSS 6.5EG 6.52020-08-14
In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is possible if the attacker controls any part of the URL provided in a call (such as httpClient.get or httpClient.post), the U…
- CVE-2020-15816HIGHCVSS 8.8EG 8.82020-07-17
In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environment variables.
- CVE-2020-15951MEDIUMCVSS 6.1EG 6.12020-11-05
Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML content that is rendered as part of the application. An attacker could leverage this to redirect applicati…
- CVE-2020-15953HIGHCVSS 7.4EG 7.42020-07-27
LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a me…
- CVE-2020-16087HIGHCVSS 8.6EG 8.62020-08-13
An issue was discovered in Zalo.exe in VNG Zalo Desktop 19.8.1.0. An attacker can run arbitrary commands on a remote Windows machine running the Zalo client by sending the user of the device a crafted file.
- CVE-2020-16230LOWCVSS 2.3EG 2.32020-09-18
All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) conf…
- CVE-2020-16254MEDIUMCVSS 6.1EG 6.12020-08-05
The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute).
- CVE-2020-16268HIGHCVSS 8.8EG 8.82020-12-29
The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair option. This applies to installations that have a TRANSFORM (MST) with the option to disabl…
- CVE-2020-16875HIGHCVSS 8.4EG 8.62020-09-11
<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the Sys…
- CVE-2020-17496CRITICALCVSS 9.8EG 9.8⚠ KEV2020-08-12
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.
- CVE-2020-1790HIGHCVSS 8.8EG 8.82020-02-18
GaussDB 200 with version of 6.5.1 have a command injection vulnerability. The software constructs part of a command using external input from users, but the software does not sufficiently validate the user input. Successful exploit could a…
- CVE-2020-17952CRITICALCVSS 9.8EG 9.82021-07-26
A remote code execution (RCE) vulnerability in /library/think/App.php of Twothink v2.0 allows attackers to execute arbitrary PHP code.
- CVE-2020-1811HIGHCVSS 8.8EG 8.82020-02-18
GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions could exploit this vulnerability by sending crafted commands to the affected device. Succ…
- CVE-2020-18875HIGHCVSS 8.8EG 8.82021-08-18
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files.
- CVE-2020-1958MEDIUMCVSS 6.5EG 6.52020-04-01
When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if a valid LDAP user is allowed to authent…
- CVE-2020-1961CRITICALCVSS 9.8EG 9.82020-05-04
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (…
- CVE-2020-20601CRITICALCVSS 9.8EG 9.82021-12-22
An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
- CVE-2020-21523CRITICALCVSS 9.8EG 9.82020-09-30
A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the Freemarker template file. This file can cause arbitrary code execution when it is rendere…
- CVE-2020-22275HIGHCVSS 8.8EG 8.82020-11-04
Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on th…
- CVE-2020-22277HIGHCVSS 8.0EG 8.02020-11-04
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
- CVE-2020-23050HIGHCVSS 8.0EG 8.02021-10-22
TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a HTML injection vulnerability in the userFirstName parameter of the user account input field. This vulnerability allows attackers to execute phishing attacks, exter…
- CVE-2020-23148HIGHCVSS 7.5EG 7.52021-08-09
The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and obtain sensitive information via a crafted POST request.
- CVE-2020-24275MEDIUMCVSS 6.5EG 6.52023-07-20
A HTTP response header injection vulnerability in Swoole v4.5.2 allows attackers to execute arbitrary code via supplying a crafted URL.
- CVE-2020-24364HIGHCVSS 8.8EG 8.82020-08-24
MineTime through 1.8.5 allows arbitrary command execution via the notes field in a meeting. Could lead to RCE via meeting invite.
- CVE-2020-24821MEDIUMCVSS 5.5EG 5.52021-08-04
A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.
- CVE-2020-24822MEDIUMCVSS 5.5EG 5.52021-08-04
A vulnerability in the dwarf::cursor::uleb function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.
- CVE-2020-24823MEDIUMCVSS 5.5EG 5.52021-08-04
A vulnerability in the dwarf::to_string function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.
- CVE-2020-24825MEDIUMCVSS 5.5EG 5.52021-08-04
A vulnerability in the line_table::line_table function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.
- CVE-2020-24826MEDIUMCVSS 5.5EG 5.52021-08-04
A vulnerability in the elf::section::as_strtab function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.
- CVE-2020-25048MEDIUMCVSS 4.6EG 4.62020-08-31
An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software. In the Lockscreen state, the Quick Share feature allows unauthenticated downloads, aka file injection. The Samsung ID is SVE-2020-17760 (August 2020).
- CVE-2020-25067CRITICALCVSS 9.6EG 9.62020-09-01
NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker.
- CVE-2020-25094CRITICALCVSS 9.8EG 9.82020-12-17
LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent insta…
- CVE-2020-25268HIGHCVSS 8.8EG 8.82020-11-10
Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data.
- CVE-2020-25596MEDIUMCVSS 5.5EG 5.52020-09-23
An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves various state sanitization activities to software. One of Xen's sanitization paths injects a…
- CVE-2020-25768MEDIUMCVSS 5.3EG 5.32020-10-07
Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end forms which will be replaced when the page is rendered.
- CVE-2020-25967HIGHCVSS 8.8EG 8.82020-12-10
The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerability.
- CVE-2020-26049MEDIUMCVSS 6.1EG 6.12020-12-21
Nifty-PM CPE 2.3 is affected by stored HTML injection. The impact is remote arbitrary code execution.
- CVE-2020-26081MEDIUMCVSS 6.1EG 6.12020-11-18
Multiple vulnerabilities in the web UI of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users on an affected system. The vulnerabilities are due…
- CVE-2020-26116HIGHCVSS 7.2EG 7.22020-09-27
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in t…
- CVE-2020-26137MEDIUMCVSS 6.5EG 6.52020-09-30
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
- CVE-2020-26142MEDIUMCVSS 5.3EG 5.32021-05-11
An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. An adversary can abuse this to inject arbitrary network packets, independent of the network configur…
- CVE-2020-26222HIGHCVSS 8.7EG 8.72020-11-13
Dependabot is a set of packages for automated dependency management for Ruby, JavaScript, Python, PHP, Elixir, Rust, Java, .NET, Elm and Go. In Dependabot-Core from version 0.119.0.beta1 before version 0.125.1, there is a remote code execu…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →