CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 22 of 105
- CVE-2023-29516CRITICALCVSS 9.9EG 9.92023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on `XWiki.AttachmentSelector` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full…
- CVE-2023-29518CRITICALCVSS 9.9EG 9.92023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installat…
- CVE-2023-29519CRITICALCVSS 9.0EG 9.02023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A registered user can perform remote code execution leading to privilege escalation by injecting the proper code in the "property" fie…
- CVE-2023-29521HIGHCVSS 8.4EG 8.42023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installat…
- CVE-2023-29522CRITICALCVSS 9.9EG 9.92023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary script macros including Groovy and Python macros that allow remote code execution incl…
- CVE-2023-29523CRITICALCVSS 9.9EG 9.92023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile can execute arbitrary script macros including Groovy and Python macros that allow remote …
- CVE-2023-29524CRITICALCVSS 9.9EG 9.92023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute anything with the right of the Scheduler Application sheet page. A user without script or programming rights,…
- CVE-2023-29525CRITICALCVSS 9.9EG 9.92023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versions of xwiki are subject to code injection in the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/Leg…
- CVE-2023-29526CRITICALCVSS 9.9EG 9.92023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to display or interact with any page a user cannot access through the combination of the async and …
- CVE-2023-29527CRITICALCVSS 9.9EG 9.92023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions a user without script or programming right may edit a user profile (or any other document) with the wiki editor a…
- CVE-2023-2980MEDIUMCVSS 6.3EG 6.32023-05-30
A vulnerability classified as critical was found in Abstrium Pydio Cells 4.2.0. This vulnerability affects unknown code of the component User Creation Handler. The manipulation leads to improper control of resource identifiers. The attack …
- CVE-2023-29827CRITICALCVSS 9.8EG 9.82023-05-04
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor bec…
- CVE-2023-30547CRITICALCVSS 9.8EG 9.82023-04-17
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allowing attackers to raise an unsanitized host exception insid…
- CVE-2023-30575MEDIUMCVSS 6.5EG 6.52023-06-07
Apache Guacamole 1.5.1 and older may incorrectly calculate the lengths of instruction elements sent during the Guacamole protocol handshake, potentially allowing an attacker to inject Guacamole instructions during the handshake through spe…
- CVE-2023-30609MEDIUMCVSS 5.4EG 5.42023-04-25
matrix-react-sdk is a react-based SDK for inserting a Matrix chat/VoIP client into a web page. Prior to version 3.71.0, plain text messages containing HTML tags are rendered as HTML in the search results. To exploit this, an attacker needs…
- CVE-2023-31025MEDIUMCVSS 6.5EG 6.52024-01-12
NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of this vulnerability may lead to information disclosure.
- CVE-2023-31209HIGHCVSS 8.8EG 8.82023-08-10
Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.
- CVE-2023-32313MEDIUMCVSS 5.3EG 5.32023-05-15
vm2 is a sandbox that can run untrusted code with Node's built-in modules. In versions 3.9.17 and lower of vm2 it was possible to get a read-write reference to the node `inspect` method and edit options for `console.log`. As a result a thr…
- CVE-2023-32314CRITICALCVSS 9.8EG 9.82023-05-15
vm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2 for versions up to and including 3.9.17. It abuses an unexpected creation of a host object based on the specification o…
- CVE-2023-32679HIGHCVSS 7.2EG 7.22023-05-19
Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension may lead to Remote Code Execution. If the name parameter value is not empty string('') in the View.php's doesTemplateEx…
- CVE-2023-32786HIGHCVSS 7.5EG 7.52023-10-20
In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
- CVE-2023-33234HIGHCVSS 7.2EG 7.22023-05-30
Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permiss…
- CVE-2023-33241CRITICALCVSS 9.6EG 9.62023-08-09
Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by injecting a malicious pallier key and cheating in the range proof. Depending on the Beta parameters chosen in the prot…
- CVE-2023-33242CRITICALCVSS 9.6EG 9.62023-08-09
Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by exfiltrating a single bit in every signature attempt (256 in total) because of not adhering to the paper's security pro…
- CVE-2023-3380MEDIUMCVSS 4.7EG 4.72023-06-23
A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi of the component Ping Test. The manipulation of the argument pingIp leads to injection. I…
- CVE-2023-34203HIGHCVSS 8.8EG 8.82023-06-23
In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This a…
- CVE-2023-3444MEDIUMCVSS 5.7EG 5.72023-07-13
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitra…
- CVE-2023-35075LOWCVSS 3.1EG 3.12023-11-27
Mattermost fails to use innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS is possible tho…
- CVE-2023-35810HIGHCVSS 7.2EG 7.22023-06-17
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Second-Order PHP Object Injection vulnerability has been identified in the DocuSign module. By using crafted requests, custom PHP code can be injected a…
- CVE-2023-35895MEDIUMCVSS 6.3EG 6.32023-12-20
IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 259116.
- CVE-2023-36188CRITICALCVSS 9.8EG 9.82023-07-06
An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.
- CVE-2023-36210CRITICALCVSS 9.8EG 9.82023-08-01
MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.
- CVE-2023-36250HIGHCVSS 7.8EG 7.82023-09-14
CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating a new record.
- CVE-2023-36260HIGHCVSS 7.5EG 7.52024-01-30
An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings to Feed-Me Name and Feed-Me URL fields, due to saving a feed using an Asset element type w…
- CVE-2023-36469CRITICALCVSS 9.9EG 9.92023-06-29
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile and notification settings can execute arbitrary script macros including Groovy and Python…
- CVE-2023-36470CRITICALCVSS 9.9EG 9.92023-06-29
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By either creating a new or editing an existing document with an icon set, an attacker can inject XWiki syntax and Velocity code that …
- CVE-2023-36471CRITICALCVSS 9.0EG 9.02023-06-29
Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML tags. In the context of XWiki, this allows an attacker without scrip…
- CVE-2023-3665MEDIUMCVSS 5.5EG 5.52023-10-04
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables, leading to denial of service and or the execution of arbitrary code.
- CVE-2023-36812CRITICALCVSS 9.8EG 9.82023-06-30
OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writing user-controlled input to Gnuplot configuration file and running Gnuplot with the generat…
- CVE-2023-36830MEDIUMCVSS 6.3EG 6.32023-07-06
SQLFluff is a SQL linter. Prior to version 2.1.2, in environments where untrusted users have access to the config files, there is a potential security vulnerability where those users could use the `library_path` config value to allow arbit…
- CVE-2023-3694MEDIUMCVSS 6.3EG 6.32023-07-17
A vulnerability, which was classified as critical, has been found in SourceCodester/projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /index.php. The manipulation of the argument ke…
- CVE-2023-37360MEDIUMCVSS 5.9EG 5.92023-06-30
pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within enterprise security products).
- CVE-2023-37462CRITICALCVSS 9.9EG 9.92023-07-14
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an injection vector from view right on that document to program…
- CVE-2023-37473HIGHCVSS 8.5EG 8.52023-07-14
zenstruck/collections is a set of helpers for iterating/paginating/filtering collections. Passing _callable strings_ (ie `system`) caused the function to be executed. This would result in a limited subset of specific user input being execu…
- CVE-2023-37897HIGHCVSS 7.2EG 7.22023-07-18
Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vulnerability using `|map`, `|filter` and `|reduce` twigs implemented in the commit `71bbed1…
- CVE-2023-38060MEDIUMCVSS 6.3EG 6.32023-07-24
Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic Interface modules allows any authenticated attacker to to perform an host header injectio…
- CVE-2023-38609HIGHCVSS 7.5EG 7.52023-07-28
An injection issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.5. An app may be able to bypass certain Privacy preferences.
- CVE-2023-38896CRITICALCVSS 9.8EG 9.82023-08-15
An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colored_object_prompt functions.
- CVE-2023-39013CRITICALCVSS 9.8EG 9.82023-07-28
Duke v1.2 and below was discovered to contain a code injection vulnerability via the component no.priv.garshol.duke.server.CommonJTimer.init.
- CVE-2023-39213CRITICALCVSS 9.6EG 9.62023-08-08
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privilege via network access.
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →