CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 5 of 105
- CVE-2017-4028MEDIUMCVSS 5.0EG 5.02018-04-03
Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry param…
- CVE-2017-5246MEDIUMCVSS 4.3EG 4.32017-07-18
Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in double curly-braces ({{ }}). This expression…
- CVE-2017-5585HIGHCVSS 8.8EG 8.82017-02-22
OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row_based config option is false, does not properly restrict DQL hints, which allows remote authentica…
- CVE-2017-5630HIGHCVSS 7.5EG 7.52017-02-01
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .h…
- CVE-2017-5636CRITICALCVSS 9.8EG 9.82017-10-19
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injection attack where a carefully crafted username could impersonate another user and gain their …
- CVE-2017-5799HIGHCVSS 8.8EG 8.82018-02-15
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).
- CVE-2017-6015HIGHCVSS 7.8EG 7.82018-05-11
Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02 remains ambiguous, which may allow an attacker to link to or run a malicious executable. This may allow an authorized, …
- CVE-2017-6031HIGHCVSS 8.8EG 8.82017-05-06
A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. An "improper neutralization of HTTP headers for scripting syntax" issue has been identified, which may allow remote code execution.
- CVE-2017-6748MEDIUMCVSS 6.7EG 6.72017-07-25
A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The attacker must authenticate with valid operator-level …
- CVE-2017-6971HIGHCVSS 8.8EG 8.82017-03-22
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, or launch a reverse shell, via vectors involving the PHP session ID and the NfSen PHP code…
- CVE-2017-7239CRITICALCVSS 9.8EG 9.82017-04-10
Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of service (process hang) via a crafted filename.
- CVE-2017-7459HIGHCVSS 7.5EG 7.52017-06-26
ntopng before 3.0 allows HTTP Response Splitting.
- CVE-2017-7703HIGHCVSS 7.5EG 7.52017-04-12
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-imap.c by calculating a line's end correctly.
- CVE-2017-7788CRITICALCVSS 9.8EG 9.82018-06-11
When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content Security Policy (CSP) as it should unless the sandbox attribute included "allow-same-origin…
- CVE-2017-7846HIGHCVSS 8.8EG 8.82018-06-11
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects …
- CVE-2017-7848MEDIUMCVSS 5.3EG 5.32018-06-11
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.
- CVE-2017-8458MEDIUMCVSS 6.5EG 6.52017-05-03
Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://[email protected]/ is displayed without a clear UI indication that it is not a resource on the safe.example.com web site.
- CVE-2017-8809CRITICALCVSS 9.8EG 9.82017-11-15
api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.
- CVE-2017-9133HIGHCVSS 8.8EG 8.82017-05-21
An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. In the device's web interface, after logging in, there is a page that allows you to ping other hosts from the device and view the results…
- CVE-2017-9135HIGHCVSS 8.8EG 8.82017-05-21
An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4. On the backend of the device's web interface, there are some diagnostic tests available that are not displayed on the webpage; these are …
- CVE-2017-9861CRITICALCVSS 9.8EG 9.82017-08-05
An issue was discovered in SMA Solar Technology products. The SIP implementation does not properly use authentication with encryption: it is vulnerable to replay attacks, packet injection attacks, and man in the middle attacks. An attacker…
- CVE-2018-0313HIGHCVSS 8.8EG 8.82018-06-21
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to send a malicious packet to the management interface on an affected system and execute a command-injection exploit. The vulnerabi…
- CVE-2018-1000130HIGHCVSS 8.1EG 8.82018-03-14
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
- CVE-2018-1000193MEDIUMCVSS 4.3EG 4.32018-06-05
A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can t…
- CVE-2018-1000854CRITICALCVSS 9.8EG 9.82018-12-20
esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in ESI directive with user specified XSLT that can result in Re…
- CVE-2018-1319MEDIUMCVSS 6.1EG 6.12018-03-15
In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial for the victim's browsing session.
- CVE-2018-14009CRITICALCVSS 9.8EG 9.82018-07-12
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
- CVE-2018-1474MEDIUMCVSS 6.1EG 6.12018-12-12
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary H…
- CVE-2018-1549MEDIUMCVSS 5.4EG 5.42018-07-10
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split re…
- CVE-2018-16486CRITICALCVSS 9.8EG 9.82019-02-01
A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype.
- CVE-2018-16489CRITICALCVSS 9.8EG 9.82019-02-01
A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions.
- CVE-2018-16490HIGHCVSS 7.5EG 7.52019-02-01
A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
- CVE-2018-16491CRITICALCVSS 9.8EG 9.82019-02-01
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
- CVE-2018-16492CRITICALCVSS 9.8EG 9.82019-02-01
A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.
- CVE-2018-16627MEDIUMCVSS 6.1EG 6.12018-12-20
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
- CVE-2018-16763CRITICALCVSS 9.8EG 9.82018-09-09
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
- CVE-2018-18207MEDIUMCVSS 6.1EG 6.12018-10-10
Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.
- CVE-2018-18250HIGHCVSS 7.5EG 7.52018-12-17
Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation item.
- CVE-2018-1896MEDIUMCVSS 4.6EG 5.42018-12-07
IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain. IBM X-Force ID: 152456.
- CVE-2018-18992HIGHCVSS 8.8EG 8.82019-02-05
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote code on the server.
- CVE-2018-18996CRITICALCVSS 9.8EG 9.82019-02-05
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the server.
- CVE-2018-1943MEDIUMCVSS 5.4EG 5.42019-04-08
IBM Cloud Private 3.1.0 and 3.1.1 is vulnerable to HTTP HOST header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to inje…
- CVE-2018-20167HIGHCVSS 7.8EG 7.82018-12-17
Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat README.md" command when \e}pn is used. A popmedia control sequence can allow the malicious execution of executable file…
- CVE-2018-20885MEDIUMCVSS 5.3EG 5.32019-08-01
cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).
- CVE-2018-20898MEDIUMCVSS 4.3EG 4.32019-08-01
cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).
- CVE-2018-20914HIGHCVSS 7.3EG 7.32019-08-01
In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).
- CVE-2018-21051CRITICALCVSS 9.8EG 9.82020-04-08
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. There is an invalid free in the fingerprint Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2018-12853 (October 2018).
- CVE-2018-21112MEDIUMCVSS 6.8EG 6.82020-04-22
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.44, R7500v2 before 1.0.3.38, R7800 before 1.0.2.52, R8900 before 1.0.4.12, and R9000 before 1.0.4.12.
- CVE-2018-21113HIGHCVSS 8.8EG 8.82020-04-22
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.58, D7800 before 1.0.1.42, R6100 before 1.0.1.28, R7500 before 1.0.0.130, R7500v2 before 1.0.3.36, R7800 before 1.0.2…
- CVE-2018-21114MEDIUMCVSS 6.8EG 6.82020-04-22
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.44, EX6150v2 before 1.0.1.70, EX6100v2 before 1.0.1.70, EX6200v2 before 1.0.1.64, EX7300 before 1.0.2.136, EX6400 before 1.…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →