CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 13 of 105
- CVE-2020-7947CRITICALCVSS 9.8EG 9.82020-04-01
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validat…
- CVE-2020-7982HIGHCVSS 8.1EG 8.12020-03-16
An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before 2020-01-25 prevents correct parsing of embedded checksums in the signed repository index, …
- CVE-2020-8093MEDIUMCVSS 5.3EG 5.32020-01-30
A vulnerability in the AntivirusforMac binary as used in Bitdefender Antivirus for Mac allows an attacker to inject a library using DYLD environment variable to cause third-party code execution
- CVE-2020-8177HIGHCVSS 7.8EG 7.82020-12-14
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.
- CVE-2020-8468CRITICALCVSS 8.8EG 9.0⚠ KEV2020-03-18
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An a…
- CVE-2020-8478MEDIUMCVSS 5.3EG 5.32020-04-29
Insufficient protection of the inter-process communication functions in ABB System 800xA products OPC Server for AC 800M, MMS Server for AC 800M and Base Software for SoftControl (all published versions) enables an attacker authenticated o…
- CVE-2020-8515CRITICALCVSS 9.8EG 9.8⚠ KEV2020-02-01
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. T…
- CVE-2020-8644CRITICALCVSS 9.8EG 9.8⚠ KEV2020-02-05
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
- CVE-2020-8797MEDIUMCVSS 6.7EG 6.72020-04-23
Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection), if the undocumented telnetd service is enabled and the attacker can authenticate as admin…
- CVE-2020-8800HIGHCVSS 8.8EG 8.82020-02-13
SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.
- CVE-2020-8801HIGHCVSS 7.2EG 7.22020-02-13
SuiteCRM through 7.11.11 allows PHAR Deserialization.
- CVE-2020-8821HIGHCVSS 5.4EG 8.72020-10-12
An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML code into the Command field and submit it. Then, after visiting the Action Logs Menu and displaying lo…
- CVE-2020-9017HIGHCVSS 8.0EG 8.02020-02-25
LiteCart through 2.2.1 allows CSV injection via a customer's profile.
- CVE-2020-9092MEDIUMCVSS 4.6EG 4.62020-10-19
HUAWEI Mate 20 versions earlier than 10.1.0.163(C00E160R3P8) have a JavaScript injection vulnerability. A module does not verify a specific input. This could allow attackers to bypass filter mechanism to launch JavaScript injection. This c…
- CVE-2020-9254HIGHCVSS 7.8EG 7.82020-07-17
HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earlier than 10.1.0.160(C00E160R2P8) have a logic check error vulnerability. A logic error occ…
- CVE-2020-9297CRITICALCVSS 9.8EG 9.82020-07-14
Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supported, includi…
- CVE-2020-9314MEDIUMCVSS 4.8EG 4.82020-05-10
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012…
- CVE-2020-9347CRITICALCVSS 9.8EG 9.82020-03-16
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they…
- CVE-2020-9372HIGHCVSS 7.8EG 7.82020-03-04
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.…
- CVE-2020-9376HIGHCVSS 7.5EG 7.52020-07-09
D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
- CVE-2020-9382MEDIUMCVSS 5.4EG 5.42020-02-24
An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via MediaWiki's {{#widget:}} parser function.
- CVE-2020-9406CRITICALCVSS 9.8EG 9.82020-02-26
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
- CVE-2020-9410HIGHCVSS 7.3EG 8.82020-05-20
The report generator component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Serv…
- CVE-2020-9428HIGHCVSS 7.5EG 7.52020-02-27
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.
- CVE-2020-9466MEDIUMCVSS 6.1EG 6.12020-02-28
The Export Users to CSV plugin through 1.4.2 for WordPress allows CSV Injection.
- CVE-2020-9495MEDIUMCVSS 5.3EG 5.32020-06-19
Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP server by providing special values to the login form. With certain characters it is possi…
- CVE-2020-9688HIGHCVSS 7.8EG 7.82020-07-17
Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9757CRITICALCVSS 9.8EG 9.82020-03-04
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.
- CVE-2021-0268CRITICALCVSS 8.8EG 9.32021-04-22
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buffer overflows, segment faults, or other impacts, which allows an attacker to modify the int…
- CVE-2021-0551MEDIUMCVSS 6.5EG 6.52021-06-22
In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. …
- CVE-2021-0553HIGHCVSS 7.3EG 7.32021-06-22
In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for…
- CVE-2021-0567HIGHCVSS 7.8EG 7.82021-06-22
In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …
- CVE-2021-0594HIGHCVSS 8.0EG 8.02021-07-14
In onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to improper input validation. This could lead to remote (proximal, NFC) escalation of privilege allowing an attacker to deceive a user into allowi…
- CVE-2021-1221MEDIUMCVSS 4.1EG 4.12021-02-04
A vulnerability in the user interface of Cisco Webex Meetings and Cisco Webex Meetings Server Software could allow an authenticated, remote attacker to inject a hyperlink into a meeting invitation email. The vulnerability is due to insuffi…
- CVE-2021-1359MEDIUMCVSS 6.3EG 6.32021-07-08
A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. This vulnerability is due to…
- CVE-2021-1432HIGHCVSS 7.3EG 7.32021-03-24
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected d…
- CVE-2021-20101MEDIUMCVSS 6.1EG 6.12021-06-29
Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers. This could cause a victim to receive malformed content.
- CVE-2021-20509CRITICALCVSS 9.8EG 9.82021-08-12
IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243.
- CVE-2021-20543MEDIUMCVSS 5.4EG 5.42022-06-24
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of…
- CVE-2021-20574HIGHCVSS 8.8EG 8.82021-06-28
IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and takeover other accounts. IB…
- CVE-2021-20644MEDIUMCVSS 6.1EG 6.12021-02-12
ELECOM WRC-1467GHBK-A allows arbitrary scripts to be executed on the user's web browser by displaying a specially crafted SSID on the web setup page.
- CVE-2021-20736CRITICALCVSS 9.1EG 9.12021-06-22
NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors.
- CVE-2021-20802MEDIUMCVSS 5.3EG 5.32021-10-13
HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product.
- CVE-2021-21137MEDIUMCVSS 6.5EG 6.52021-02-09
Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.
- CVE-2021-21141MEDIUMCVSS 6.5EG 6.52021-02-09
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy via a crafted HTML page.
- CVE-2021-21242CRITICALCVSS 10.0EG 10.02021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` …
- CVE-2021-21243CRITICALCVSS 10.0EG 10.02021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted data from the request body. These endpoints do not enforce any authentication or authorizati…
- CVE-2021-21244CRITICALCVSS 10.0EG 10.02021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full details in the reference GHSA. This issue wa…
- CVE-2021-21247CRITICALCVSS 9.6EG 9.62021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX event listener (`AbstractPostAjaxBehavior`) in all pages other than the login page. This listener decodes and deserialize…
- CVE-2021-21248CRITICALCVSS 9.6EG 9.62021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. InputSpec is used to define parameters of a Build spec. It does so by using dynamically gen…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →