CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 17 of 105
- CVE-2021-43097HIGHCVSS 7.2EG 7.22022-03-28
A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrary code.
- CVE-2021-43185CRITICALCVSS 9.8EG 9.82021-11-09
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.
- CVE-2021-43269HIGHCVSS 8.8EG 8.82022-01-20
In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Advanced, and Gov F1;…
- CVE-2021-43350CRITICALCVSS 9.8EG 9.82021-11-11
An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.
- CVE-2021-43437HIGHCVSS 8.8EG 8.82021-12-20
In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the web application and cause the application to behave in unexpected ways. Very often multiple websites are hosted on the sa…
- CVE-2021-43439CRITICALCVSS 9.8EG 9.82021-12-20
RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely
- CVE-2021-43441MEDIUMCVSS 5.3EG 5.32021-12-20
An HTML Injection Vulnerability in iOrder 1.0 allows the remote attacker to execute Malicious HTML codes via the signup form
- CVE-2021-43782MEDIUMCVSS 6.7EG 6.72021-12-15
Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. This is a follow up to GHSA-887w-pv2r-x8pm/CVE-2021-41276, the initial fix was incomplete. Tuleap does not sanitize properly the sea…
- CVE-2021-43818HIGHCVSS 8.2EG 8.22021-12-13
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. …
- CVE-2021-43837HIGHCVSS 8.4EG 8.42021-12-16
vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli features the ability for rendering templated values. When a secret starts with the prefix `!t…
- CVE-2021-43852HIGHCVSS 8.8EG 8.82022-01-04
OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties into existing JavaScript language construct prototypes, such as objects. Later this inject…
- CVE-2021-43929MEDIUMCVSS 6.5EG 6.52022-02-07
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authenticated users to inject…
- CVE-2021-43961MEDIUMCVSS 4.3EG 4.32022-03-17
Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.
- CVE-2021-44042CRITICALCVSS 9.8EG 9.82021-12-14
An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in attacker-controlled content being injected …
- CVE-2021-44530CRITICALCVSS 9.8EG 9.82022-01-14
An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a malicious actor to control the application.
- CVE-2021-44537HIGHCVSS 7.8EG 7.82022-01-15
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.
- CVE-2021-44550CRITICALCVSS 9.8EG 9.82022-02-24
An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).
- CVE-2021-44832CRITICALCVSS 6.6EG 9.02021-12-28
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an at…
- CVE-2021-45092CRITICALCVSS 9.8EG 9.82021-12-16
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.
- CVE-2021-45655MEDIUMCVSS 6.9EG 6.92021-12-26
NETGEAR R6400 devices before 1.0.1.70 are affected by server-side injection.
- CVE-2021-45656HIGHCVSS 7.1EG 7.82021-12-26
Certain NETGEAR devices are affected by server-side injection. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6050 before 1.0.1.26, JR6150 before 1.0.1.26, R6120 before 1.0.0.66, …
- CVE-2021-45657HIGHCVSS 7.1EG 7.82021-12-26
Certain NETGEAR devices are affected by server-side injection. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6050 before 1.0.1.26, JR6150 before 1.0.1.26, R6120 before 1.0.0.66, …
- CVE-2021-45658HIGHCVSS 7.1EG 7.12021-12-26
Certain NETGEAR devices are affected by server-side injection. This affects D7800 before 1.0.1.58, DM200 before 1.0.0.66, EX2700 before 1.0.1.56, EX6150v2 before 1.0.1.86, EX6100v2 before 1.0.1.86, EX6200v2 before 1.0.1.78, EX6250 before 1…
- CVE-2021-45659HIGHCVSS 7.1EG 7.82021-12-26
Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RB…
- CVE-2021-45660HIGHCVSS 7.1EG 7.82021-12-26
Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RB…
- CVE-2021-45661HIGHCVSS 7.1EG 7.82021-12-26
Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RB…
- CVE-2021-45818MEDIUMCVSS 6.1EG 6.12021-12-30
SAFARI Montage 8.7.32 is affected by a CRLF injection vulnerability which can lead to HTTP response splitting.
- CVE-2021-46063CRITICALCVSS 9.1EG 9.12022-02-18
MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.
- CVE-2022-0391HIGHCVSS 7.5EG 7.52022-02-09
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characte…
- CVE-2022-0581HIGHCVSS 6.3EG 7.52022-02-14
Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
- CVE-2022-0582CRITICALCVSS 6.3EG 9.82022-02-14
Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
- CVE-2022-1074MEDIUMCVSS 4.3EG 5.42022-03-29
A vulnerability has been found in TEM FLEX-1085 1.6.0 and classified as problematic. Using the input <h1>HTML Injection</h1> in the WiFi settings of the dashboard leads to html injection.
- CVE-2022-1287CRITICALCVSS 6.5EG 9.82022-04-09
A vulnerability classified as critical was found in School Club Application System 1.0. This vulnerability affects a request to the file /scas/classes/Users.php?f=save_user. The manipulation with a POST request leads to privilege escalatio…
- CVE-2022-1509CRITICALCVSS 9.9EG 9.92022-04-28
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
- CVE-2022-20001HIGHCVSS 7.8EG 7.82022-03-14
fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including running arbitrary comman…
- CVE-2022-20693HIGHCVSS 4.7EG 7.22022-04-15
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker…
- CVE-2022-20718HIGHCVSS 5.5EG 7.22022-04-15
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying …
- CVE-2022-20719HIGHCVSS 5.5EG 7.22022-04-15
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying …
- CVE-2022-20772MEDIUMCVSS 4.7EG 5.32022-11-04
A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the…
- CVE-2022-21663MEDIUMCVSS 6.6EG 6.62022-01-06
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object i…
- CVE-2022-21705HIGHCVSS 7.2EG 7.22022-02-23
Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before rendering. An authenticated user with the permissions to create, modify and delete website pages…
- CVE-2022-22344MEDIUMCVSS 6.1EG 6.12022-03-14
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable s…
- CVE-2022-22360HIGHCVSS 8.8EG 8.82022-07-19
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could …
- CVE-2022-22411MEDIUMCVSS 6.5EG 6.52022-08-10
IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate cluster resources due to excessive permissions. IBM X-Force ID: 223016.
- CVE-2022-22975MEDIUMCVSS 6.6EG 6.62022-05-11
An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider resources. An attack would involve the malicious user changing the common name (CN) of their user entry on the LDAP or A…
- CVE-2022-23064HIGHCVSS 8.8EG 8.82022-05-02
In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to a…
- CVE-2022-23068MEDIUMCVSS 5.4EG 5.42022-05-18
ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.
- CVE-2022-23614HIGHCVSS 8.8EG 8.82022-02-04
Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was n…
- CVE-2022-23616HIGHCVSS 8.8EG 8.82022-02-09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for an unprivileged user to perform a remote code execution by injecting a groovy script in her own…
- CVE-2022-23701MEDIUMCVSS 5.3EG 5.32022-02-24
A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior to 2.60. This vulnerability could be remotely exploited to allow an attacker to supply in…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →