CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 14 of 105
- CVE-2021-21249CRITICALCVSS 9.6EG 9.62021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote code execution. In order to parse and process YAML files, OneDev uses SnakeYaml which by d…
- CVE-2021-21261HIGHCVSS 7.3EG 7.32021-01-14
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a…
- CVE-2021-21263HIGHCVSS 7.2EG 7.22021-01-19
Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is craf…
- CVE-2021-21277HIGHCVSS 8.5EG 8.52021-02-01
angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-expressions before version 1.1.2 there is a vulnerability which allows Remote Code Execution if you call "expressions.comp…
- CVE-2021-21278HIGHCVSS 8.6EG 8.62021-01-26
RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk of code injection. Some routes use `eval` or `Function constructor`, which may be injected…
- CVE-2021-21303MEDIUMCVSS 5.9EG 5.92021-02-05
Helm is open-source software which is essentially "The Kubernetes Package Manager". Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. In Helm from version 3.0 and before version 3.5.2, there a …
- CVE-2021-21305HIGHCVSS 7.4EG 7.42021-02-08
CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1, there is a code injection vulnerability. The "#manipulate!" method inapp…
- CVE-2021-21313MEDIUMCVSS 4.9EG 4.92021-03-03
GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is a vulnerability in the /ajax/common.tabs.php endpoint, …
- CVE-2021-21316MEDIUMCVSS 6.3EG 6.32021-02-16
less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10., when processing theming resources (i.e. `*.less` files) with less-openui5 that originate from an untrusted source, tho…
- CVE-2021-21333MEDIUMCVSS 6.1EG 6.12021-03-26
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the notification emails sent for notification…
- CVE-2021-21353MEDIUMCVSS 6.8EG 6.82021-03-03
Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty` option of the pug compiler, e.g. if you spread a user provided object such as the query …
- CVE-2021-21372HIGHCVSS 8.3EG 8.32021-03-26
Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in different places and can be leveraged to execute arbitrary commands. An attacker can craft a mal…
- CVE-2021-21381HIGHCVSS 7.1EG 7.12021-03-11
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which can be used by an att…
- CVE-2021-21420HIGHCVSS 7.5EG 7.52021-04-01
vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted source-code repository containing malicious settings. An attacker who successfully exploited…
- CVE-2021-21479CRITICALCVSS 9.1EG 9.12021-02-09
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
- CVE-2021-21510MEDIUMCVSS 6.1EG 6.12021-03-08
Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or …
- CVE-2021-21580MEDIUMCVSS 4.3EG 4.32021-08-03
Dell EMC iDRAC8 versions prior to 2.80.80.80 & Dell EMC iDRAC9 versions prior to 5.00.00.00 contain a Content spoofing / Text injection, where a malicious URL can inject text to present a customized message on the application that can phis…
- CVE-2021-21743MEDIUMCVSS 4.3EG 4.32021-10-20
ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP response header information through a specially crafted HTTP request.
- CVE-2021-22035MEDIUMCVSS 4.3EG 4.32021-10-13
VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges may be able to embed…
- CVE-2021-22055MEDIUMCVSS 5.3EG 5.32022-04-11
The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attackers can also insert malicious data and fake entries.
- CVE-2021-22191HIGHCVSS 6.3EG 8.82021-03-15
Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file.
- CVE-2021-22204CRITICALCVSS 6.8EG 9.0⚠ KEV2021-04-23
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
- CVE-2021-22232LOWCVSS 3.5EG 3.52021-07-06
HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE
- CVE-2021-22331HIGHCVSS 7.5EG 7.52021-04-28
There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verify some inputs sufficiently. Attackers can exploit this vulnerability by sending a malicious application request to launch JavaScript inject…
- CVE-2021-22879HIGHCVSS 8.8EG 8.82021-04-14
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
- CVE-2021-22910CRITICALCVSS 9.8EG 9.82021-08-09
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result in a NoSQL injection, potentially leading to RCE.
- CVE-2021-23335HIGHCVSS 7.5EG 7.52021-02-11
All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or information exposure.
- CVE-2021-23400MEDIUMCVSS 6.3EG 6.32021-06-29
The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.
- CVE-2021-24002HIGHCVSS 8.8EG 8.82021-06-24
When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. This vulnerability affects Firefox ESR < 7…
- CVE-2021-24144HIGHCVSS 7.8EG 7.82021-03-18
Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files.
- CVE-2021-24948HIGHCVSS 7.5EG 7.52022-01-10
The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action, which could allow unauthenticated users to retrieve sensitive information, such as priva…
- CVE-2021-25682HIGHCVSS 8.8EG 8.82021-06-11
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.
- CVE-2021-25980HIGHCVSS 8.8EG 8.82021-11-11
In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 and tyse-v0.2021.02-879ef3fe1-regular through tyse-v0.2021.28-af66b6905-regular, are vulnerable to Host Header Injection.…
- CVE-2021-25994HIGHCVSS 8.8EG 8.82022-01-03
In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victim’s…
- CVE-2021-26068HIGHCVSS 8.8EG 8.82021-02-22
An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via a template injection vulnerability.
- CVE-2021-26069MEDIUMCVSS 5.3EG 5.32021-03-22
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project keys via an Information Disclosure vulnerability in the /rest/api/1.0/issues/{id}/ActionsAn…
- CVE-2021-26084CRITICALCVSS 9.8EG 9.8⚠ KEV2021-08-30
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions …
- CVE-2021-27132CRITICALCVSS 9.8EG 9.82021-02-27
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
- CVE-2021-27182HIGHCVSS 8.8EG 8.82021-04-14
An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an attacker to perform any action with the privileges of the att…
- CVE-2021-27493MEDIUMCVSS 6.1EG 6.52022-04-01
Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well formed and that certain security properties are met before being read from an upstream component or sent to a downstre…
- CVE-2021-27611MEDIUMCVSS 6.7EG 6.72021-05-11
SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. The attacker could then get access to da…
- CVE-2021-27614HIGHCVSS 7.1EG 7.12021-05-11
SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the …
- CVE-2021-27730CRITICALCVSS 9.8EG 9.82021-03-02
Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later.
- CVE-2021-27908MEDIUMCVSS 5.8EG 5.82021-03-23
In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in Mautic’s configurat…
- CVE-2021-27971HIGHCVSS 7.8EG 7.82022-01-31
Alps Alpine Touchpad Driver 10.3201.101.215 is vulnerable to DLL Injection.
- CVE-2021-28829MEDIUMCVSS 6.5EG 6.52021-04-20
The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrato…
- CVE-2021-28963MEDIUMCVSS 5.3EG 5.32021-03-22
Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
- CVE-2021-28979MEDIUMCVSS 6.5EG 6.52021-06-16
SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is cl…
- CVE-2021-29084HIGHCVSS 7.5EG 7.52021-06-23
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attac…
- CVE-2021-29085HIGHCVSS 8.6EG 8.62021-06-23
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to rea…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →