CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 6 of 105
- CVE-2018-21119MEDIUMCVSS 6.8EG 6.82020-04-22
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 5.0.5.4 and WAC510 before 5.0.5.4.
- CVE-2018-21123HIGHCVSS 8.8EG 8.82020-04-22
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WC7500 before 6.5.3.9, WC7520 before 6.5.3.9, WC7600v1 before 6.5.3.9, and WC7600v2 before 6.5.3.9.
- CVE-2018-21146MEDIUMCVSS 6.8EG 6.82020-04-21
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, R7800 before 1.0.2.42, R8900 before 1.0.3.10, R9000 before 1.0.3.10, WNDR4300v2 before 1.0.0.54, and WNDR4500v3 before …
- CVE-2018-21208HIGHCVSS 8.8EG 8.82020-04-28
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.57, R6100 before 1.0.1.20, R7500v2 before 1.0.3.24, WNDR4300v2 before 1.0.0.50, and WNDR4500v3 before 1.0.0.50.
- CVE-2018-21227MEDIUMCVSS 6.8EG 6.82020-04-24
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, R6400v2 before 1.0.2.34, R6700 before 1.0.1.30, R6900 before 1.0.1.30, R6900P before 1.0.0.62, R7000 before 1.0.9.12, R…
- CVE-2018-21228MEDIUMCVSS 6.8EG 6.82020-04-24
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34, EX6100v2 before 1.0.1.50, EX6150v2 before 1.0.1.50, EX6200v2 before 1.0.1.44, EX6400 before 1.0.1.60, EX7300 before 1.0…
- CVE-2018-21258HIGHCVSS 7.5EG 7.52020-06-19
An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command.
- CVE-2018-21268CRITICALCVSS 10.0EG 10.02020-06-25
The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular…
- CVE-2018-25016CRITICALCVSS 9.8EG 9.82021-06-21
Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.
- CVE-2018-25106MEDIUMCVSS 6.3EG 6.32024-12-23
A vulnerability, which was classified as critical, has been found in webuidesigning NebulaX Theme up to 5.0 on WordPress. This issue affects the function nebula_send_to_hubspot of the file libs/Legacy/Legacy.php. The manipulation leads to …
- CVE-2018-3963CRITICALCVSS 8.0EG 9.02019-03-21
An exploitable command injection vulnerability exists in the DHCP daemon configuration of the CUJO Smart Firewall. When adding a new static DHCP address, its corresponding hostname is inserted into the dhcpd.conf file without prior sanitiz…
- CVE-2018-4106HIGHCVSS 8.8EG 8.82018-04-03
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the Bracketed Paste Mode of the "Terminal" component. It allows user-assisted attackers to inject arbitrary commands within pasted cont…
- CVE-2018-4153MEDIUMCVSS 5.9EG 5.92019-04-03
An injection issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14.
- CVE-2018-4235MEDIUMCVSS 5.5EG 5.52018-06-08
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "Messages" component. It allows local …
- CVE-2018-4995CRITICALCVSS 9.8EG 9.82018-07-09
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an XFA '\n' POST injection vulnerability. Successful exploitation could lead to a security bypass.
- CVE-2018-6220CRITICALCVSS 9.8EG 9.82018-03-15
An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to gaining code execution on vulnerable systems.
- CVE-2018-6289CRITICALCVSS 9.8EG 9.82018-02-06
Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
- CVE-2018-6519HIGHCVSS 7.5EG 7.52018-02-02
The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.
- CVE-2018-6603MEDIUMCVSS 6.1EG 6.12018-02-07
Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injection attacks via JavaScript code in a PHPSESSID cookie.
- CVE-2018-7032HIGHCVSS 7.5EG 7.52018-02-14
webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for arbitrary code execution, as demonstrated by an "ext::sh -c…
- CVE-2018-9062MEDIUMCVSS 6.8EG 6.82018-07-19
In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.
- CVE-2019-0304CRITICALCVSS 9.8EG 9.82019-06-12
FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNE…
- CVE-2019-0319HIGHCVSS 7.5EG 7.52019-07-10
The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form of an error message. An attacker could thus mislead a user to believe this information is from the legitimate service w…
- CVE-2019-10074CRITICALCVSS 9.8EG 9.82019-09-11
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Enco…
- CVE-2019-1010310LOWCVSS 3.5EG 3.52019-07-12
GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The co…
- CVE-2019-1020006MEDIUMCVSS 6.1EG 6.12019-07-29
invenio-app before 1.1.1 allows host header injection.
- CVE-2019-10665CRITICALCVSS 9.8EG 9.82019-09-09
An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supp…
- CVE-2019-10792MEDIUMCVSS 6.3EG 6.32020-02-18
bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
- CVE-2019-10793MEDIUMCVSS 6.3EG 6.32020-02-18
dot-object before 2.1.3 is vulnerable to Prototype Pollution. The set function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
- CVE-2019-10794MEDIUMCVSS 6.3EG 6.32020-02-18
All versions of component-flatten are vulnerable to Prototype Pollution. The a function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
- CVE-2019-10795MEDIUMCVSS 6.3EG 6.32020-02-18
undefsafe before 2.0.3 is vulnerable to Prototype Pollution. The 'a' function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
- CVE-2019-11045MEDIUMCVSS 3.7EG 5.92019-12-23
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applica…
- CVE-2019-11073HIGHCVSS 7.2EG 7.22020-03-16
A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execute code due to insufficient sanitization when passing arguments to the HttpTransactionSensor.exe binary. In order to exp…
- CVE-2019-11275MEDIUMCVSS 4.3EG 4.32019-10-01
Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability whe…
- CVE-2019-11277HIGHCVSS 8.1EG 8.12019-09-23
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via service instance cr…
- CVE-2019-11282MEDIUMCVSS 4.3EG 4.32019-10-23
Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content which can leak informat…
- CVE-2019-11354HIGHCVSS 7.8EG 7.82019-04-19
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an …
- CVE-2019-11581CRITICALCVSS 9.8EG 9.8⚠ KEV2019-08-09
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Ji…
- CVE-2019-11718MEDIUMCVSS 5.3EG 5.32019-07-23
Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Ac…
- CVE-2019-11853LOWCVSS 3.9EG 3.92020-08-21
Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.
- CVE-2019-12303HIGHCVSS 8.8EG 8.82019-06-06
In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd container.
- CVE-2019-12387MEDIUMCVSS 6.1EG 6.12019-06-10
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
- CVE-2019-12416MEDIUMCVSS 6.1EG 6.12020-03-19
we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrategy which is not the default.
- CVE-2019-12425HIGHCVSS 7.5EG 7.52020-04-30
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
- CVE-2019-12463HIGHCVSS 8.8EG 8.82019-09-09
An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input…
- CVE-2019-12966CRITICALCVSS 9.8EG 9.82019-06-26
FeHelper through 2019-06-19 allows arbitrary code execution during a JSON format operation, as demonstrated by the {"a":(function(){confirm(1)})()} input.
- CVE-2019-13146MEDIUMCVSS 5.3EG 5.32019-07-09
The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input, which can be dangerous depending on how applications use it. If an appl…
- CVE-2019-13285HIGHCVSS 7.5EG 7.52020-05-04
CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.
- CVE-2019-13915HIGHCVSS 7.5EG 7.52019-07-18
b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in the editor, and compile and run it approximately three times to read an arbitrary file. Second, the attacker can create …
- CVE-2019-14759MEDIUMCVSS 4.4EG 4.42020-09-14
An issue was discovered in KaiOS 1.0, 2.5, and 2.5.1. The pre-installed Radio application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Radio application. At a bare minimum, thi…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →