CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 11 of 105
- CVE-2020-26238HIGHCVSS 7.9EG 7.92020-11-25
Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. In cron-utils before version 9.1.3, a template Injection vulnerability is present. This enables attackers to inject arbitra…
- CVE-2020-26260MEDIUMCVSS 6.4EG 6.42020-12-09
BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit a page could set certain image URL's to manipulate functionality in the exporting system,…
- CVE-2020-26282CRITICALCVSS 10.0EG 10.02020-12-24
BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data as a HAR file. BrowserUp Proxy works well as a standalone proxy server, but it is especially useful when embedded in Se…
- CVE-2020-26293MEDIUMCVSS 6.1EG 6.12021-01-04
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. In HtmlSanitizer before version 5.0.372, there is a possible XSS bypass if style tag is allowed. If you have explicitly…
- CVE-2020-26298MEDIUMCVSS 6.8EG 6.82021-01-11
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when proc…
- CVE-2020-26884MEDIUMCVSS 6.1EG 6.12020-11-18
RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user into executing malicious JavaScript code i…
- CVE-2020-27211MEDIUMCVSS 5.7EG 5.72021-05-21
Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during the boot phase.
- CVE-2020-27212HIGHCVSS 7.0EG 7.02021-05-21
STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by in…
- CVE-2020-27260MEDIUMCVSS 5.3EG 5.32021-01-08
Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 HL7 v2.x injection vulnerabilities exist in the affected products that allow physically proximate attackers with a connected barcode reader to inject HL7 v2.x segments in…
- CVE-2020-27602CRITICALCVSS 9.8EG 9.82022-09-29
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.
- CVE-2020-27627MEDIUMCVSS 6.1EG 6.12020-11-16
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
- CVE-2020-27687HIGHCVSS 8.8EG 8.82020-12-18
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of …
- CVE-2020-28031MEDIUMCVSS 4.3EG 4.32020-11-02
eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated users.
- CVE-2020-28246CRITICALCVSS 9.8EG 9.82022-06-02
A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL. NOTE: the email templating service was removed after 2020. Additionally, the ve…
- CVE-2020-28328HIGHCVSS 8.8EG 8.92020-11-06
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under t…
- CVE-2020-28468HIGHCVSS 8.1EG 8.12021-01-08
This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulnerable to Server-Side Template Injection (SSTI), which can lead to remote code execution.
- CVE-2020-28848HIGHCVSS 8.8EG 8.82023-08-11
CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file.
- CVE-2020-29135MEDIUMCVSS 4.1EG 4.12020-11-27
cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).
- CVE-2020-29655HIGHCVSS 7.5EG 7.52020-12-09
An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108. Accessing Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaster/task.asp will redirect to the login site, which will show the value of the parameter pro…
- CVE-2020-3246MEDIUMCVSS 4.3EG 4.32020-05-06
A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user of an affected service. The vulnerability is due to insuffici…
- CVE-2020-35213HIGHCVSS 8.1EG 8.12021-12-16
An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node.
- CVE-2020-35226HIGHCVSS 7.1EG 7.12021-03-10
NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allow unauthenticated users to modify the switch DHCP configuration by sending the corresponding write request command.
- CVE-2020-35564HIGHCVSS 7.5EG 7.52021-02-16
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malicious user input of active code.
- CVE-2020-35608HIGHCVSS 7.8EG 7.82020-12-22
A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an executable memory mapping with control…
- CVE-2020-35609MEDIUMCVSS 5.5EG 5.52020-12-22
A denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequence of specially crafted ioctl calls can cause a denial of service. An attacker can write shellcode to trigger this vu…
- CVE-2020-3561MEDIUMCVSS 4.7EG 4.72020-10-21
A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in th…
- CVE-2020-35669MEDIUMCVSS 6.1EG 6.12020-12-24
An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.
- CVE-2020-35734HIGHCVSS 7.2EG 7.22021-02-15
Sruu.pl in Batflat 1.3.6 allows an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Users tab. To exploit this, one must login to the administration panel and edit an arbitra…
- CVE-2020-35754HIGHCVSS 7.2EG 7.22021-01-28
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.
- CVE-2020-35775CRITICALCVSS 9.8EG 9.82021-02-15
CITSmart before 9.1.2.23 allows LDAP Injection.
- CVE-2020-35938HIGHCVSS 7.5EG 7.52021-01-01
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted pay…
- CVE-2020-36144MEDIUMCVSS 5.3EG 5.32021-03-18
Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.
- CVE-2020-36308MEDIUMCVSS 5.3EG 5.32021-04-06
Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.
- CVE-2020-36531HIGHCVSS 6.3EG 8.82022-06-07
A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. This issue affects the Device Manager Page. An injection leads to privilege escalation. The attack may be initiated remot…
- CVE-2020-36618MEDIUMCVSS 6.3EG 6.32022-12-19
A vulnerability classified as critical has been found in Furqan node-whois. Affected is an unknown function of the file index.coffee. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype p…
- CVE-2020-3760CRITICALCVSS 9.8EG 9.82020-02-13
Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-3884MEDIUMCVSS 6.1EG 6.12020-04-01
An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbitrary javascript code execution.
- CVE-2020-3924MEDIUMCVSS 6.4EG 6.42020-02-27
DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.
- CVE-2020-3956HIGHCVSS 8.8EG 8.82020-05-20
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly handle input leading to a code injection vulnerability. An authenticated actor may be able to send mal…
- CVE-2020-4027MEDIUMCVSS 4.7EG 4.72020-07-01
Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros. The af…
- CVE-2020-4161MEDIUMCVSS 6.5EG 6.52020-02-19
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 could allow an authenticated attacker to cause a denial of service due to incorrect handling of certain commands. IBM X-Force ID: 174341.
- CVE-2020-4210CRITICALCVSS 9.8EG 9.82020-02-24
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the …
- CVE-2020-4211CRITICALCVSS 9.8EG 9.82020-02-24
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the …
- CVE-2020-4212CRITICALCVSS 9.8EG 9.82020-02-24
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the …
- CVE-2020-4213CRITICALCVSS 9.8EG 9.82020-02-24
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the …
- CVE-2020-4222CRITICALCVSS 9.8EG 9.82020-02-24
IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the …
- CVE-2020-4271MEDIUMCVSS 6.3EG 6.32020-04-15
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to send a specially crafted command which would be executed as a lower privileged user. IBM X-ForceID: 175897.
- CVE-2020-4432HIGHCVSS 7.5EG 7.52020-06-10
Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge of the system to execute commands in a SOAP API. IBM X-Force ID: 180810.
- CVE-2020-4589CRITICALCVSS 9.8EG 9.82020-08-13
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 184585.
- CVE-2020-4627CRITICALCVSS 9.0EG 9.02020-11-30
IBM Cloud Pak for Security 1.3.0.1(CP4S) potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 185367.
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →