CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 4 of 105
- CVE-2017-18049MEDIUMCVSS 5.5EG 5.52018-01-23
In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (incl…
- CVE-2017-18266HIGHCVSS 8.8EG 8.82018-05-10
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks v…
- CVE-2017-18386HIGHCVSS 7.2EG 7.22019-08-02
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).
- CVE-2017-18387HIGHCVSS 7.2EG 7.22019-08-02
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).
- CVE-2017-18389MEDIUMCVSS 6.3EG 6.32019-08-02
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
- CVE-2017-18437MEDIUMCVSS 4.4EG 4.42019-08-02
cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).
- CVE-2017-18583CRITICALCVSS 9.8EG 9.82019-08-22
The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection.
- CVE-2017-18604HIGHCVSS 7.5EG 7.52019-09-10
The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.
- CVE-2017-18605CRITICALCVSS 9.8EG 9.82019-09-10
The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.
- CVE-2017-18634CRITICALCVSS 9.8EG 9.82019-09-16
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
- CVE-2017-18652CRITICALCVSS 9.8EG 9.82020-04-07
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. SVoice allows arbitrary code execution by changing dynamic libraries. The Samsung ID is SVE-2017-9299 (September 2017).
- CVE-2017-18734HIGHCVSS 8.8EG 8.82020-04-23
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6220 befo…
- CVE-2017-18735HIGHCVSS 8.8EG 8.82020-04-23
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0.1.10, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, and R6900v2 before …
- CVE-2017-18736HIGHCVSS 8.8EG 8.82020-04-23
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0.1.10, R6050 before 1.0.1.10, R6220 before 1.1.0.50, R6700v2 before 1.2.0.4, R6800 before 1.2.0.4, R6900v2 before 1.2.0…
- CVE-2017-18737HIGHCVSS 8.8EG 8.82020-04-23
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.18, R6050 before 1.0.1.10, R6220 befo…
- CVE-2017-18754MEDIUMCVSS 6.8EG 6.82020-04-22
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WNDR3700v4 before 1.0.2.88, WNDR4300v1 before 1.0.2.90, and WNR2000v5 before 1.0.0.58.
- CVE-2017-18762HIGHCVSS 8.8EG 8.82020-04-22
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D3600 before 1.0.0.68, D6000 before 1.0.0.68, D6100 before 1.0.0.57, R6100 before 1.0.1.16, R6900P before 1.2.0.22, R7000 before 1.0.9.1…
- CVE-2017-18764HIGHCVSS 8.8EG 8.82020-04-22
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.55, D7000 before 1.0.1.50, D7800 before 1.0.1.28, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 befor…
- CVE-2017-18767MEDIUMCVSS 6.8EG 6.82020-04-22
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, D8500 before 1.0.3.39, R6400 before 1.0.1.14, R6400v2 before 1.0.2.32, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R7…
- CVE-2017-18773MEDIUMCVSS 6.7EG 6.72020-04-22
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6100 before V1.0.0.55, D7800 before V1.0.1.24, EX6150v2 before 1.0.0.48, R6100 before 1.0.1.14, R7500 before 1.0.0.110, R7500v2 before V1.0.3…
- CVE-2017-18786HIGHCVSS 7.8EG 7.82020-04-22
Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050 before 1.0.1.12, WNR1000v4 before …
- CVE-2017-18787HIGHCVSS 7.8EG 7.82020-04-22
Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050, before 1.0.1.12, WNR1000v4 before…
- CVE-2017-18788MEDIUMCVSS 6.7EG 6.72020-04-22
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D6100 before 1.0.0.56, D6200 before 1.1.00.24, D6220 before 1.0.0.32, D6400 before 1.0.0.66, D70…
- CVE-2017-18792HIGHCVSS 8.4EG 8.42020-04-21
NETGEAR D6100 devices before 1.0.0.50_0.0.50 are affected by command injection.
- CVE-2017-18793MEDIUMCVSS 6.7EG 6.72020-04-21
NETGEAR R7800 devices before 1.0.2.36 are affected by command injection.
- CVE-2017-18794HIGHCVSS 8.4EG 8.42020-04-21
Certain NETGEAR devices are affected by command injection. This affects R6300v2 before 1.0.4.8_10.0.77, R6400 before 1.0.1.24, R6700 before 1.0.1.26, R7000 before 1.0.9.10, R7100LG before 1.0.0.32, R7900 before 1.0.1.18, R8000 before 1.0.3…
- CVE-2017-18795MEDIUMCVSS 6.7EG 6.72020-04-21
Certain NETGEAR devices are affected by command injection. This affects D6220 before 1.0.0.28 and D6100 before 1.0.0.50_0.0.50.
- CVE-2017-18796MEDIUMCVSS 6.7EG 6.72020-04-21
Certain NETGEAR devices are affected by command injection. This affects R6400 before 1.0.1.24, R6700 before 1.0.1.26, R6900 before 1.0.1.28, R7000 before 1.0.9.10, R7000P before 1.0.1.16, R6900P before 1.0.1.16, and R7800 before 1.0.2.36.
- CVE-2017-18801MEDIUMCVSS 6.7EG 6.72020-04-21
Certain NETGEAR devices are affected by command injection. This affects R6220 before 1.1.0.50, R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, WNDR3700v5 before 1.1.0.48, and D7000 before 1.0.1.50.
- CVE-2017-18802MEDIUMCVSS 6.7EG 6.72020-04-21
Certain NETGEAR devices are affected by command injection. This affects R6100 before 1.0.1.14, R7500 before 1.0.0.110, R7500v2 before 1.0.3.16, R7800 before 1.0.2.32, EX6200v2 before 1.0.1.50, and D7800 before 1.0.1.22.
- CVE-2017-18804MEDIUMCVSS 6.7EG 6.72020-04-21
Certain NETGEAR devices are affected by command injection. This affects R7800 before 1.0.2.16 and R9000 before 1.0.2.4.
- CVE-2017-18805MEDIUMCVSS 6.7EG 6.72020-04-21
Certain NETGEAR devices are affected by command injection. This affects WAC510 before 1.3.0.10, WAC120 before 2.1.4, WNDAP620 before 2.1.3, WND930 before 2.1.2, WN604 before 3.3.7, WNDAP660 before 3.7.4.0, WNDAP350 before 3.7.4.0, WNAP320 …
- CVE-2017-18806MEDIUMCVSS 6.7EG 6.72020-04-21
Certain NETGEAR devices are affected by command injection. This affects WAC510 before 1.3.0.10, WAC120 before 2.1.4, WNDAP620 before 2.1.3, WND930 before 2.1.2, WN604 before 3.3.7, WNDAP660 before 3.7.4.0, WNDAP350 before 3.7.4.0, WNAP320 …
- CVE-2017-18841MEDIUMCVSS 6.7EG 6.72020-04-20
Certain NETGEAR devices are affected by command injection. This affects R6220 before 1.1.0.46, R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, WNDR3700v5 before 1.1.0.46, and D7000 before 1.0.1.50.
- CVE-2017-18849HIGHCVSS 7.8EG 7.82020-04-20
Certain NETGEAR devices are affected by command injection. This affects D6220 before 1.0.0.26, D6400 before 1.0.0.60, D8500 before 1.0.3.29, R6250 before 1.0.4.12, R6400 before 1.01.24, R6400v2 before 1.0.2.30, R6700 before 1.0.1.22, R6900…
- CVE-2017-18851MEDIUMCVSS 6.7EG 6.72020-04-20
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D8500 through 1.0.3.28, R6400 through 1.0.1.22, R6400v2 through 1.0.2.18, R8300 through 1.0.2.94, R8500 through 1.0.2.94, and R6100 through 1.…
- CVE-2017-18854MEDIUMCVSS 6.7EG 6.72020-04-29
NETGEAR ReadyNAS 6.6.1 and earlier is affected by command injection.
- CVE-2017-18855HIGHCVSS 8.8EG 8.82020-04-29
NETGEAR WNR854T devices before 1.5.2 are affected by command execution.
- CVE-2017-18856MEDIUMCVSS 6.7EG 6.72020-04-29
NETGEAR ReadyNAS devices before 6.6.1 are affected by command injection.
- CVE-2017-18860HIGHCVSS 7.7EG 7.72020-04-29
Certain NETGEAR devices are affected by debugging command execution. This affects FS752TP 5.4.2.19 and earlier, GS108Tv2 5.4.2.29 and earlier, GS110TP 5.4.2.29 and earlier, GS418TPP 6.6.2.6 and earlier, GS510TLP 6.6.2.6 and earlier, GS510T…
- CVE-2017-18863HIGHCVSS 7.1EG 7.12020-04-28
Certain NETGEAR devices are affected by command execution via a PHP form. This affects WN604 3.3.3 and earlier, WNAP210v2 3.5.20.0 and earlier, WNAP320 3.5.20.0 and earlier, WNDAP350 3.5.20.0 and earlier, WNDAP360 3.5.20.0 and earlier, WND…
- CVE-2017-18900CRITICALCVSS 9.8EG 9.82020-06-19
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report.
- CVE-2017-18923HIGHCVSS 7.5EG 7.52020-07-29
beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with credentials.
- CVE-2017-20161HIGHCVSS 4.6EG 7.82023-01-02
A vulnerability classified as problematic has been found in rofl0r MacGeiger. Affected is the function dump_wlan_at of the file macgeiger.c of the component ESSID Handler. The manipulation leads to injection. Access to the local network is…
- CVE-2017-20174CRITICALCVSS 5.6EG 9.82023-01-19
A vulnerability was found in bastianallgeier Kirby Webmentions Plugin and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to injection. The attack may be launched remotely. The comple…
- CVE-2017-20187LOWCVSS 3.5EG 3.52023-11-05
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file src/Magnesium/Message/Base.php. The manipulation of the a…
- CVE-2017-20196MEDIUMCVSS 6.3EG 6.32025-01-26
A vulnerability was found in Itechscripts School Management Software 2.75. It has been classified as critical. This affects an unknown part of the file /notice-edit.php. The manipulation of the argument aid leads to sql injection. It is po…
- CVE-2017-20197HIGHCVSS 7.3EG 7.32025-04-09
A vulnerability was found in propanetank Roommate-Bill-Tracking up to 288437f658fc9ee7d4b92a9da12557024d8bc55c. It has been declared as critical. This vulnerability affects unknown code of the file /includes/login.php. The manipulation of …
- CVE-2017-2140HIGHCVSS 8.8EG 8.82017-04-28
Tablacus Explorer 17.3.30 and earlier allows arbitrary scripts to be executed in the context of the application due to specially crafted directory.
- CVE-2017-3547HIGHCVSS 7.4EG 7.42017-04-24
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows unauth…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →