CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 16 of 105
- CVE-2021-36668HIGHCVSS 7.8EG 7.82022-07-12
URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.
- CVE-2021-36697MEDIUMCVSS 6.7EG 6.72021-11-03
With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this ne…
- CVE-2021-36913HIGHCVSS 7.5EG 7.52022-10-11
Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional e…
- CVE-2021-37033HIGHCVSS 7.5EG 7.52021-11-23
There is an Injection attack vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.
- CVE-2021-37040CRITICALCVSS 9.8EG 9.82021-12-08
There is a Parameter injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause privilege escalation of files after CIFS share mounting.
- CVE-2021-37262HIGHCVSS 7.5EG 7.52021-12-16
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.
- CVE-2021-37499MEDIUMCVSS 6.5EG 6.52023-01-20
CRLF vulnerability in Reprise License Manager (RLM) web interface through 14.2BL4 in the password parameter in View License Result function, that allows remote attackers to inject arbitrary HTTP headers.
- CVE-2021-37541MEDIUMCVSS 6.1EG 6.12021-08-06
In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.
- CVE-2021-37933HIGHCVSS 7.5EG 7.52021-10-14
An LDAP injection vulnerability in /account/login in Huntflow Enterprise before 3.10.6 could allow an unauthenticated, remote user to modify the logic of an LDAP query and bypass authentication. The vulnerability is due to insufficient ser…
- CVE-2021-38084HIGHCVSS 8.1EG 8.12021-08-03
An issue was discovered in the POP3 component of Courier Mail Server before 1.1.5. Meddler-in-the-middle attackers can pipeline commands after the POP3 STLS command, injecting plaintext commands into an encrypted user session.
- CVE-2021-38290HIGHCVSS 8.1EG 8.12021-08-09
A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/libraries/Asset.php. An attacker can use a man in the middle attack such as phishing.
- CVE-2021-38294CRITICALCVSS 9.8EG 9.82021-10-25
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RC…
- CVE-2021-38371HIGHCVSS 7.5EG 7.52021-08-10
The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.
- CVE-2021-38395CRITICALCVSS 9.1EG 9.82022-10-28
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special elements in output, which may allow an attacker to remotely execute arbitrary code and cause a denial-of-service condition.
- CVE-2021-38458CRITICALCVSS 9.8EG 9.82021-10-12
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
- CVE-2021-38873HIGHCVSS 7.8EG 7.82021-11-24
IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 208396.
- CVE-2021-39028MEDIUMCVSS 5.4EG 5.42022-07-14
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various a…
- CVE-2021-39031HIGHCVSS 8.8EG 8.82022-01-25
IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could res…
- CVE-2021-39114HIGHCVSS 8.8EG 8.82022-04-05
Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affect…
- CVE-2021-39128HIGHCVSS 7.2EG 7.22021-09-16
Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA Administrators access to execute arbitrary Java code via a server-side template injection vulnerability in t…
- CVE-2021-39175HIGHCVSS 8.1EG 8.12021-08-30
HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the speaker-notes of the slide-mode feature by embedding an iframe hosting the malicious code …
- CVE-2021-39187HIGHCVSS 7.5EG 7.52021-09-02
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version 4.10.3, Parse Server crashes when if a query request contains an invalid value for the `explain` option. This is due t…
- CVE-2021-39213MEDIUMCVSS 6.8EG 6.82021-09-15
GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in version 9.5.6. One may…
- CVE-2021-39910MEDIUMCVSS 2.6EG 4.32021-12-13
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab was vulnerable to HTML Injection thr…
- CVE-2021-40143HIGHCVSS 8.2EG 8.22021-09-07
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.
- CVE-2021-40336HIGHCVSS 5.0EG 8.82022-07-25
A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP response splitting, which if exploited could lead an attacker to channel down harmful code into …
- CVE-2021-40658MEDIUMCVSS 4.8EG 4.82022-06-14
Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.
- CVE-2021-41084HIGHCVSS 8.7EG 8.72021-09-21
http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request-splitting attacks when untrusted user input is used to create any of the following fields: Header names (`Header.…
- CVE-2021-41128CRITICALCVSS 9.1EG 9.12021-10-06
Hygeia is an application for collecting and processing personal and case data in connection with communicable diseases. In affected versions all CSV Exports (Statistics & BAG MED) contain a CSV Injection Vulnerability. Users of the system …
- CVE-2021-41163CRITICALCVSS 10.0EG 10.02021-10-20
Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of validation in subscribe_url values. This issue is patched in…
- CVE-2021-41170CRITICALCVSS 9.8EG 9.82021-11-08
neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that are callable are executed by the template engine. The issue a…
- CVE-2021-41232HIGHCVSS 8.1EG 8.12021-11-02
Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there is an LDAP injection vulnerability which affects instances with LDAP authentication enabled. The provided username is n…
- CVE-2021-41276MEDIUMCVSS 6.7EG 6.72021-12-15
Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly the search filter built from the ldap_id attribute of a user during the daily…
- CVE-2021-41282CRITICALCVSS 8.8EG 9.02022-03-01
diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then its output is parse…
- CVE-2021-41314HIGHCVSS 8.8EG 8.82021-09-16
Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the authentication scheme - allows the attacker to create (or overwrite) a file with specific content (e…
- CVE-2021-41390HIGHCVSS 8.0EG 8.02021-09-17
In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.
- CVE-2021-41392CRITICALCVSS 9.8EG 9.82021-09-17
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron AP…
- CVE-2021-41437MEDIUMCVSS 6.5EG 6.52022-09-26
An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the atta…
- CVE-2021-4181HIGHCVSS 7.5EG 7.52021-12-30
Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
- CVE-2021-4182HIGHCVSS 7.5EG 7.52021-12-30
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
- CVE-2021-41825MEDIUMCVSS 5.3EG 5.32021-10-08
Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter.
- CVE-2021-4183MEDIUMCVSS 5.5EG 5.52021-12-30
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
- CVE-2021-4186HIGHCVSS 6.3EG 7.52021-12-30
Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
- CVE-2021-41862CRITICALCVSS 9.8EG 9.82021-10-02
AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (BCEL).
- CVE-2021-42117MEDIUMCVSS 3.5EG 5.42021-11-30
Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker with Object Modification privileges to insert arbitrary HTML withou…
- CVE-2021-4227MEDIUMCVSS 5.3EG 5.32024-01-16
The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment …
- CVE-2021-4245MEDIUMCVSS 5.5EG 5.52022-12-15
A vulnerability classified as problematic has been found in chbrown rfc6902. This affects an unknown part of the file pointer.ts. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollu…
- CVE-2021-42561HIGHCVSS 8.8EG 8.82022-01-12
An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shell metacharacters (e.g., backticks "``" or dollar parenthesi…
- CVE-2021-42663MEDIUMCVSS 4.3EG 4.32021-11-05
An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visi…
- CVE-2021-43038HIGHCVSS 8.8EG 8.82021-12-06
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL trigger functions. This allowed privilege escalation from the wguest user to the postgres us…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →