CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 23 of 105
- CVE-2023-3922LOWCVSS 3.0EG 3.02023-09-29
An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons …
- CVE-2023-39424CRITICALCVSS 9.9EG 9.92023-09-07
A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. Th…
- CVE-2023-39655CRITICALCVSS 9.6EG 9.62024-01-03
A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, …
- CVE-2023-39659CRITICALCVSS 9.8EG 9.82023-08-15
An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component.
- CVE-2023-39661CRITICALCVSS 9.8EG 9.82023-08-15
An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.
- CVE-2023-39662CRITICALCVSS 9.8EG 9.82023-08-15
An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.
- CVE-2023-3997HIGHCVSS 8.6EG 8.62023-07-31
Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to c…
- CVE-2023-40035HIGHCVSS 7.2EG 7.22023-08-23
Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code execution. This vulnerability can lead to malicious control of vulnerable systems and data …
- CVE-2023-41039HIGHCVSS 7.7EG 7.72023-08-30
RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality allows someone controlling the format string to "read" all objects accessible through recursive attribute lookup and s…
- CVE-2023-4157MEDIUMCVSS 4.8EG 4.82023-08-04
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in GitHub repository omeka/omeka-s prior to version 4.0.3.
- CVE-2023-41580HIGHCVSS 7.5EG 7.52023-10-02
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitiv…
- CVE-2023-41834MEDIUMCVSS 6.1EG 6.12023-09-19
Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted HTTP reque…
- CVE-2023-4197HIGHCVSS 8.8EG 8.82023-11-01
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
- CVE-2023-4212MEDIUMCVSS 6.8EG 6.82023-08-22
A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to …
- CVE-2023-42135MEDIUMCVSS 6.8EG 6.82024-01-15
PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection by bypassing the input validation when flashing a specific partition. The attacker must have …
- CVE-2023-42136HIGHCVSS 7.8EG 7.82024-01-15
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system account privilege by shell injection starting with a specific word. The attacker must …
- CVE-2023-43364CRITICALCVSS 9.8EG 9.82023-12-12
main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.
- CVE-2023-43655HIGHCVSS 8.8EG 8.82023-09-29
Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability if PHP also has `reg…
- CVE-2023-43656CRITICALCVSS 9.0EG 9.02023-09-27
matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. Instances that have enabled transformation functions (those that have `generic.allowJsTransformationFunctions` in their config), may b…
- CVE-2023-43661HIGHCVSS 8.8EG 8.92023-10-11
Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Commit 6fb04…
- CVE-2023-43667HIGHCVSS 7.5EG 7.52023-10-16
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create misleading or false log r…
- CVE-2023-43835HIGHCVSS 8.8EG 8.82023-10-02
Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote Code Execution when settings overwrite config.inc.php content.
- CVE-2023-4393MEDIUMCVSS 6.1EG 6.12023-10-30
HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attacks against an organization.
- CVE-2023-44109HIGHCVSS 7.5EG 7.52023-10-11
Clone vulnerability in the huks ta module.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-44270MEDIUMCVSS 5.3EG 5.32023-09-29
An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. Af…
- CVE-2023-44373CRITICALCVSS 9.1EG 9.12023-11-14
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. Follow-up of CVE-2022-36323.
- CVE-2023-4450CRITICALCVSS 9.8EG 9.82023-08-21
A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack …
- CVE-2023-4478HIGHCVSS 8.2EG 8.22023-08-25
Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their …
- CVE-2023-45303HIGHCVSS 8.8EG 8.82023-10-06
ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).
- CVE-2023-45540MEDIUMCVSS 6.5EG 6.52023-10-16
An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of the List of Leave requests page.
- CVE-2023-4571HIGHCVSS 8.6EG 8.62023-08-30
In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3, 4.15.3, or 4.17.1, a malicious actor can inject American National Standards Institute (ANSI) escape codes into Splunk ITSI log files that, when a vulnerable terminal app…
- CVE-2023-46304HIGHCVSS 8.1EG 8.12024-04-30
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).
- CVE-2023-46456CRITICALCVSS 9.8EG 9.82023-12-12
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.
- CVE-2023-46468HIGHCVSS 7.8EG 7.82023-10-28
An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the custom plugin function.
- CVE-2023-46726CRITICALCVSS 9.8EG 9.82023-12-13
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server configuration form can be used to execute arbitrary code previously uploaded as a GLPI docum…
- CVE-2023-47119MEDIUMCVSS 6.1EG 6.12023-11-10
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some links can inject arbitrary HTML tags when rendered through…
- CVE-2023-4767MEDIUMCVSS 6.1EG 6.12023-11-03
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fi…
- CVE-2023-4818HIGHCVSS 7.6EG 7.62024-01-15
PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by PAX can be used. The attacker must have physical USB access to the device in order to …
- CVE-2023-48199HIGHCVSS 7.8EG 7.82023-11-15
HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script execution. This occurs when user-supplied data is not appropriately sanitized, enabling the in…
- CVE-2023-48205MEDIUMCVSS 5.3EG 5.32023-12-07
Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails.
- CVE-2023-4843MEDIUMCVSS 4.8EG 4.82023-09-08
Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.
- CVE-2023-48709HIGHCVSS 8.0EG 8.02024-04-15
iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas that may be imported into Excel. As Excel 2016 does **not** prevent Remote Code E…
- CVE-2023-48826HIGHCVSS 8.8EG 8.82023-12-07
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
- CVE-2023-48830HIGHCVSS 8.8EG 8.82023-12-07
Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.
- CVE-2023-48835HIGHCVSS 8.8EG 8.82023-12-07
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
- CVE-2023-48841HIGHCVSS 8.8EG 8.82023-12-07
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
- CVE-2023-49214CRITICALCVSS 9.8EG 9.82023-11-23
Usedesk before 1.7.57 allows chat template injection.
- CVE-2023-49328HIGHCVSS 7.2EG 7.22023-12-25
On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote code execution via Argument Injection in the server-to-server module.
- CVE-2023-49964HIGHCVSS 8.8EG 8.82023-12-11
An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarke…
- CVE-2023-50093MEDIUMCVSS 6.1EG 6.12024-01-03
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →