CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 19 of 105
- CVE-2022-33011HIGHCVSS 8.8EG 8.82022-07-08
Known v1.3.1+2020120201 was discovered to allow attackers to perform an account takeover via a host header injection attack.
- CVE-2022-33012HIGHCVSS 8.8EG 8.82022-11-22
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
- CVE-2022-33900HIGHCVSS 4.1EG 7.22022-08-22
PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.
- CVE-2022-34160MEDIUMCVSS 5.4EG 5.42022-07-08
IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. I…
- CVE-2022-34165MEDIUMCVSS 5.4EG 5.42022-09-09
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation. This could allow an attacker to conduct …
- CVE-2022-34294CRITICALCVSS 9.8EG 9.82022-08-15
totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.
- CVE-2022-34306MEDIUMCVSS 5.4EG 5.42022-07-08
IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cro…
- CVE-2022-34466MEDIUMCVSS 6.5EG 6.52022-07-12
A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.3). An expression injection vulnerability was discovered in the Wor…
- CVE-2022-34773CRITICALCVSS 4.9EG 9.82022-08-22
Tabit - HTTP Method manipulation. https://bridge.tabit.cloud/configuration/addresses-query - can be POST-ed to add addresses to the DB. This is an example of OWASP:API8 – Injection.
- CVE-2022-34903MEDIUMCVSS 6.5EG 6.52022-07-01
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
- CVE-2022-34914CRITICALCVSS 9.8EG 9.82022-07-08
Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in the configuration page. The {clientIp} variable can be used as an application startup argument. The X-Forwarded-For head…
- CVE-2022-34966HIGHCVSS 7.5EG 7.52022-07-25
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via the location parameter at http://ip_address/:port/ossn/home.
- CVE-2022-35246MEDIUMCVSS 4.3EG 4.32022-09-23
A NoSQL-Injection information disclosure vulnerability vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 in the getS3FileUrl Meteor server method that can disclose arbitrary file upload URLs to users that should not be able to a…
- CVE-2022-35507HIGHCVSS 7.1EG 7.12022-12-04
A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, ca…
- CVE-2022-35735HIGHCVSS 7.2EG 7.22022-08-04
In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, an authenticated attacker with Resource Administrator or Manager privileges can create or modify existing monitor object…
- CVE-2022-35739MEDIUMCVSS 5.3EG 5.32022-10-25
PRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a device’s icon, which can be modified to insert arbitrary content into the style tag for that device. When the device page loads, the arbitrary Cascading Style …
- CVE-2022-35914CRITICALCVSS 9.8EG 9.8⚠ KEV2022-09-19
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
- CVE-2022-35948MEDIUMCVSS 5.3EG 5.32022-08-15
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header. Exam…
- CVE-2022-35954MEDIUMCVSS 5.0EG 5.02022-08-15
The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other …
- CVE-2022-3607MEDIUMCVSS 6.0EG 6.02022-10-19
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/octoprint prior to 1.8.3.
- CVE-2022-36084CRITICALCVSS 9.9EG 9.92022-09-08
cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl starting with version 1.1.0 and prior to versions 2.7.0 and 3.0.2 is used to generate a schema that uses `@flexSearchFulltext`…
- CVE-2022-36302HIGHCVSS 8.8EG 8.82022-08-01
File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sensitive information.
- CVE-2022-36323CRITICALCVSS 9.1EG 9.12022-08-10
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.
- CVE-2022-3643CRITICALCVSS 6.5EG 10.02022-12-07
Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets. It appears to be an (unwritten?) a…
- CVE-2022-36775MEDIUMCVSS 6.5EG 6.52023-02-17
IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks aga…
- CVE-2022-37027HIGHCVSS 7.2EG 7.22022-09-21
Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. Fo…
- CVE-2022-37108HIGHCVSS 8.7EG 8.72022-09-07
An injection vulnerability in the syslog-ng configuration wizard in Securonix Snypr 6.4 allows an application user with the "Manage Ingesters" permission to execute arbitrary code on remote ingesters by appending arbitrary text to text fil…
- CVE-2022-3724HIGHCVSS 6.3EG 7.52022-12-09
Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file on Windows
- CVE-2022-37240CRITICALCVSS 9.8EG 9.82022-08-25
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.
- CVE-2022-37242CRITICALCVSS 9.8EG 9.82022-08-25
MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.
- CVE-2022-37933HIGHCVSS 7.3EG 7.82023-01-05
A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be exploited to allow local unauthorized data injection. HPE has made the following software updates to re…
- CVE-2022-38191MEDIUMCVSS 6.1EG 6.12022-08-15
There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authenticated attacker to inject HTML into some locations in the home application.
- CVE-2022-38357HIGHCVSS 8.8EG 8.82022-08-15
Improper neutralization of special elements leaves the Eyes of Network Web application vulnerable to an iFrame injection attack, via the url parameter of /module/module_frame/index.php.
- CVE-2022-3844MEDIUMCVSS 3.5EG 6.12022-11-02
A vulnerability, which was classified as problematic, was found in Webmin 2.001. Affected is an unknown function of the file xterm/index.cgi. The manipulation leads to basic cross site scripting. It is possible to launch the attack remotel…
- CVE-2022-38796MEDIUMCVSS 6.1EG 6.12022-09-14
A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.
- CVE-2022-39016HIGHCVSS 8.2EG 8.82022-10-31
Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload.
- CVE-2022-3918HIGHCVSS 8.8EG 8.82023-01-20
A program using FoundationNetworking in swift-corelibs-foundation is potentially vulnerable to CRLF ( ) injection in URLRequest headers. In this vulnerability, a client can insert one or several CRLF sequences into a URLRequest header valu…
- CVE-2022-39217MEDIUMCVSS 5.8EG 5.82022-09-17
some-natalie/ghas-to-csv (GitHub Advanced Security to CSV) is a GitHub action which scrapes the GitHub Advanced Security API and shoves it into a CSV. In affected versions this GitHub Action creates a CSV file without sanitizing the output…
- CVE-2022-39265HIGHCVSS 7.2EG 7.22022-10-06
MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, in connection with the configured mail program's options and behavior, may allow access t…
- CVE-2022-39382CRITICALCVSS 9.8EG 9.82022-11-03
Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/[email protected] || 3.0.1` users that use `NODE_ENV` to trigger security-sensitive functionality in their production builds are vulnerable to `NODE_ENV` being i…
- CVE-2022-3941CRITICALCVSS 5.3EG 9.82022-11-11
A vulnerability has been found in Activity Log Plugin and classified as critical. This vulnerability affects unknown code of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to improper output neutr…
- CVE-2022-3962MEDIUMCVSS 4.3EG 4.32023-09-23
A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection…
- CVE-2022-3967HIGHCVSS 5.3EG 7.82022-11-13
A vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the file func/main.sh of the component sed Handler. The manipulation leads to argument injection. An attack has to be a…
- CVE-2022-4011CRITICALCVSS 6.5EG 9.82022-11-16
A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue affects some unknown processing of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper output neutra…
- CVE-2022-40145CRITICALCVSS 9.8EG 9.82022-12-21
This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasourc…
- CVE-2022-40248MEDIUMCVSS 5.4EG 5.42022-10-10
An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using the "Product Affected" field.
- CVE-2022-40257MEDIUMCVSS 5.4EG 5.42022-10-10
An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field.
- CVE-2022-40434CRITICALCVSS 9.8EG 9.82022-12-19
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.
- CVE-2022-4064LOWCVSS 3.7EG 3.72022-11-19
A vulnerability was found in Dalli up to 3.2.2. It has been classified as problematic. Affected is the function self.meta_set of the file lib/dalli/protocol/meta/request_formatter.rb of the component Meta Protocol Handler. The manipulation…
- CVE-2022-4092HIGHCVSS 5.7EG 8.02023-01-26
An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input.
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →