CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 18 of 105
- CVE-2022-23721LOWCVSS 3.8EG 3.82023-04-25
PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username collision when two people with the same username are provisioned onto the same machine at different times.
- CVE-2022-24039CRITICALCVSS 9.0EG 9.02022-05-10
A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The “addCell” JavaScript function fails to properly sanitize user-controllable input before incl…
- CVE-2022-24300CRITICALCVSS 9.8EG 9.82022-02-02
Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.
- CVE-2022-24442CRITICALCVSS 9.8EG 9.82022-02-25
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
- CVE-2022-24760CRITICALCVSS 10.0EG 10.02022-03-12
Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects Parse Server in the default configuration with MongoDB. Th…
- CVE-2022-24832HIGHCVSS 8.2EG 8.22022-04-11
GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD Server fails to correctly escape special characters when using the username to construct LDAP queries. While this does …
- CVE-2022-24838MEDIUMCVSS 5.3EG 5.52022-04-11
Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the email value in the JSON request, a malicious a…
- CVE-2022-24888MEDIUMCVSS 4.3EG 4.32022-04-27
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 20.0.14.4, 21.0.8, 22.2.4, and 23.0.1, it is possible to create files and folders that have leading and trailing \n, \r, \t,…
- CVE-2022-24989CRITICALCVSS 9.8EG 9.82023-08-20
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskstring parameters for PHP Object Instantiation to the api.php?mobile/createRaid URI. (Shell metacharacters can be placed …
- CVE-2022-25167CRITICALCVSS 9.8EG 9.82022-06-14
Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is …
- CVE-2022-25337CRITICALCVSS 9.8EG 9.82022-02-18
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames.
- CVE-2022-25366HIGHCVSS 7.8EG 7.82022-02-19
Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for Hardened Runtime, it has the com.apple.security.cs.disable-library-validation and com.apple.security.cs.allow-dyld-environment-variables entitlem…
- CVE-2022-25420CRITICALCVSS 9.8EG 9.82022-03-29
NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows attackers to execute arbitrary code via a crafted HTTP request.
- CVE-2022-26134CRITICALCVSS 9.8EG 9.8⚠ KEV2022-06-03
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions …
- CVE-2022-26205CRITICALCVSS 9.8EG 9.82022-03-27
Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields. This vulnerability allows attackers to execute arbitrary code via injection of a crafted payload.
- CVE-2022-26654HIGHCVSS 7.5EG 7.52022-07-17
Pexip Infinity before 27.3 allows remote attackers to force a software abort via HTTP.
- CVE-2022-27336CRITICALCVSS 9.8EG 9.82022-04-27
Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.
- CVE-2022-27858CRITICALCVSS 7.4EG 9.82022-11-08
CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress.
- CVE-2022-27924CRITICALCVSS 7.5EG 9.0⚠ KEV2022-04-21
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.
- CVE-2022-28345HIGHCVSS 7.5EG 7.52022-04-15
The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs beginning with a non-breaking space, when there is a hash character in the URL. This technique allows a remote unauthentica…
- CVE-2022-29166HIGHCVSS 8.0EG 8.02022-05-05
matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. The vulnerability has…
- CVE-2022-29171MEDIUMCVSS 6.6EG 6.62022-05-06
Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserver service. The Gitolite code host integration with Phabricator allows Sourcegraph site ad…
- CVE-2022-29269MEDIUMCVSS 6.5EG 6.52022-06-29
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
- CVE-2022-29631HIGHCVSS 7.5EG 7.52022-06-06
Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (…
- CVE-2022-29816LOWCVSS 2.8EG 3.32022-04-28
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
- CVE-2022-2992CRITICALCVSS 9.9EG 9.92022-10-17
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.
- CVE-2022-30506CRITICALCVSS 9.8EG 9.82022-06-02
An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file.
- CVE-2022-3060HIGHCVSS 7.3EG 7.32022-10-17
Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attacker to generate content which could cause a victim to make unintended arbitrary requests
- CVE-2022-3080HIGHCVSS 7.5EG 7.52022-09-21
By sending specific queries to the resolver, an attacker can cause named to crash.
- CVE-2022-30991MEDIUMCVSS 6.1EG 6.12022-05-18
HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240
- CVE-2022-31014MEDIUMCVSS 5.4EG 5.42022-07-05
Nextcloud server is an open source personal cloud server. Affected versions were found to be vulnerable to SMTP command injection. The impact varies based on which commands are supported by the backend SMTP server. However, the main risk h…
- CVE-2022-31086HIGHCVSS 8.8EG 8.82022-06-27
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 incorrect regular expressions allow to upload PHP scripts to config/templates/pdf. T…
- CVE-2022-31087HIGHCVSS 7.8EG 7.82022-06-27
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the tmp directory, which is accessible by /lam/tmp/, allows interpretation of .php (…
- CVE-2022-31088MEDIUMCVSS 5.3EG 5.32022-06-27
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the user name field at login could be used to enumerate LDAP data. This is only the …
- CVE-2022-31108MEDIUMCVSS 4.1EG 4.12022-06-28
Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. An attacker is able to inject arbitrary `CSS` into the generated graph allowing …
- CVE-2022-31126CRITICALCVSS 10.0EG 10.02022-07-06
Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/…
- CVE-2022-31179HIGHCVSS 8.1EG 8.12022-08-01
Shescape is a simple shell escape package for JavaScript. Versions prior to 1.5.8 were found to be subject to code injection on windows. This impacts users that use Shescape (any API function) to escape arguments for cmd.exe on Windows An …
- CVE-2022-31180CRITICALCVSS 9.8EG 9.82022-08-01
Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when interpolating output. This issue only impacts users that use the `escape` or `escapeAll` functions wit…
- CVE-2022-31181CRITICALCVSS 9.8EG 9.82022-08-01
PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call PHP's Eval function on attacker input. The problem is fixed…
- CVE-2022-31593HIGHCVSS 8.8EG 8.82022-07-12
SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
- CVE-2022-31631CRITICALCVSS 9.1EG 9.12025-02-12
In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which…
- CVE-2022-31657CRITICALCVSS 9.8EG 9.82022-08-05
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain.
- CVE-2022-31658HIGHCVSS 7.2EG 7.22022-08-05
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.
- CVE-2022-31665HIGHCVSS 7.2EG 7.22022-08-05
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.
- CVE-2022-31777MEDIUMCVSS 5.4EG 5.42022-11-01
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which woul…
- CVE-2022-3215HIGHCVSS 7.5EG 7.52022-09-28
NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack. This occurs when a HTTP/1.1 server accepts user generated input from an incoming request and reflects it into a HTTP/1.1 respo…
- CVE-2022-32269CRITICALCVSS 9.8EG 9.82022-06-03
In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (displayed by Internet Explorer core). This leads to arbitrary code execution.
- CVE-2022-3236CRITICALCVSS 9.8EG 9.8⚠ KEV2022-09-23
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
- CVE-2022-32453MEDIUMCVSS 6.5EG 6.52022-08-18
HTTP header injection vulnerability in Cybozu Office 10.0.0 to 10.8.5 may allow a remote attacker to obtain and/or alter the data of the product via unspecified vectors.
- CVE-2022-32534CRITICALCVSS 8.8EG 9.82022-06-23
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows execution of shell commands.
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →