CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 7 of 105
- CVE-2019-14760MEDIUMCVSS 4.4EG 4.42020-09-14
An issue was discovered in KaiOS 2.5. The pre-installed Recorder application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Recorder application. At a bare minimum, this allows a…
- CVE-2019-14761MEDIUMCVSS 4.4EG 4.42020-09-14
An issue was discovered in KaiOS 2.5. The pre-installed Note application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Note application. At a bare minimum, this allows an attack…
- CVE-2019-1490MEDIUMCVSS 5.4EG 5.42019-12-10
A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Server Spoofing Vulnerability'.
- CVE-2019-15259MEDIUMCVSS 6.1EG 6.12019-10-02
A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some paramet…
- CVE-2019-15616MEDIUMCVSS 4.3EG 4.32020-02-04
Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.
- CVE-2019-16254MEDIUMCVSS 5.3EG 5.32019-11-26
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input into the response header, an attacker can exploit it to insert a newline character to split…
- CVE-2019-16268MEDIUMCVSS 4.8EG 4.82021-02-03
Zoho ManageEngine Remote Access Plus 10.0.259 allows HTML injection via the Description field on the Admin - User Administration userMgmt.do?actionToCall=ShowUser screen.
- CVE-2019-16385MEDIUMCVSS 6.1EG 6.12020-06-04
Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an example.pdf?mimetype= substring. The victim user must load an application request to view a P…
- CVE-2019-16468HIGHCVSS 7.5EG 7.52020-01-15
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
- CVE-2019-16532MEDIUMCVSS 6.1EG 6.12019-09-26
An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.
- CVE-2019-16771MEDIUMCVSS 4.8EG 4.82019-12-06
Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized data is used to populate the headers of a…
- CVE-2019-1680MEDIUMCVSS 4.3EG 4.32019-02-07
A vulnerability in Cisco Webex Business Suite could allow an unauthenticated, remote attacker to inject arbitrary text into a user's browser. The vulnerability is due to improper validation of input. An attacker could exploit this vulnerab…
- CVE-2019-16954MEDIUMCVSS 5.4EG 5.42021-01-06
SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.
- CVE-2019-16959MEDIUMCVSS 6.5EG 6.52020-12-21
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
- CVE-2019-16962MEDIUMCVSS 5.4EG 5.42021-01-06
Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.
- CVE-2019-17068HIGHCVSS 7.5EG 7.52019-10-01
PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content.
- CVE-2019-17123HIGHCVSS 7.5EG 7.52019-12-13
The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstrated by fromName header injection with a %0a or %0d character. (Also, the message parameter…
- CVE-2019-17513HIGHCVSS 7.5EG 7.52019-10-18
An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers lack HTTP control characters. Thus, if untrusted data is used to construct HTTP headers wit…
- CVE-2019-17558CRITICALCVSS 7.5EG 9.0⚠ KEV2019-12-30
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A u…
- CVE-2019-18348MEDIUMCVSS 6.1EG 6.12019-10-23
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen wi…
- CVE-2019-18657MEDIUMCVSS 5.3EG 5.32019-10-31
ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.
- CVE-2019-18860MEDIUMCVSS 6.1EG 6.12020-03-20
Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.
- CVE-2019-19330CRITICALCVSS 9.8EG 9.82019-11-27
The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.
- CVE-2019-19389MEDIUMCVSS 5.4EG 5.42019-12-26
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
- CVE-2019-1939HIGHCVSS 8.8EG 8.82019-09-05
A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. This vulnerability is due to improper restrictions on software logging feature…
- CVE-2019-19614HIGHCVSS 7.5EG 7.52020-03-09
An issue was discovered in Halvotec RAQuest 10.23.10801.0. The login page is vulnerable to wildcard injection, allowing an attacker to enumerate the list of users sharing an identical password. Fixed in Release 10.24.11206.1.
- CVE-2019-19872CRITICALCVSS 9.8EG 9.82020-11-27
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintended commands via an unspecified attack scenario, a different vulnerability than CVE-2019-163…
- CVE-2019-19874CRITICALCVSS 9.8EG 9.82020-11-27
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution of arbitrary unintended commands on the web server, a different vulnerability than CVE-2019…
- CVE-2019-20213HIGHCVSS 7.5EG 7.52020-01-02
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.
- CVE-2019-20409CRITICALCVSS 9.8EG 9.82020-06-23
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerabilit…
- CVE-2019-20680HIGHCVSS 8.0EG 8.02020-04-15
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000v2 before 1.0.0.53, R6220 before 1.1.0.80, R6260 before 1.1.0.64, R6700 before 1.0.2.6, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R…
- CVE-2019-20688MEDIUMCVSS 6.8EG 6.82020-04-16
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 before 1.0.0.63, EX2700 before 1.0.1.48, EX6100v2 before 1.0.1.76, EX6150v2 before 1.0.1.7…
- CVE-2019-20689MEDIUMCVSS 6.8EG 6.82020-04-16
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6000 before 1.0.0.75, D6100 before 1.0.0.63, EX2700 before 1.0.1.48, EX6100v2 before 1.0.1.76, EX6150v2 before 1.0.1.76, EX6200v2 before 1.0.…
- CVE-2019-20773HIGHCVSS 7.8EG 7.82020-04-17
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. Unprivileged applications can execute shell commands via the connectivity service. The LG ID is LVE-SMP-190008 (August 2019).
- CVE-2019-25031MEDIUMCVSS 5.9EG 5.92021-04-27
Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound softwar…
- CVE-2019-25150HIGHCVSS 8.8EG 8.82023-06-07
The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This makes it possible for attackers to present phishing forms or conduct cross-site request forgery attacks against site admin…
- CVE-2019-2725CRITICALCVSS 9.8EG 9.8⚠ KEV2019-04-26
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated att…
- CVE-2019-3498MEDIUMCVSS 6.5EG 6.52019-01-09
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to conten…
- CVE-2019-3562MEDIUMCVSS 6.1EG 6.12019-04-29
A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This affects the Oculus Browser starting from version 5.2.7 until 5.7.11.
- CVE-2019-4216MEDIUMCVSS 4.6EG 4.62019-11-22
IBM SmartCloud Analytics 1.3.1 through 1.3.5 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM X-Force ID: 159187.
- CVE-2019-4396MEDIUMCVSS 5.4EG 5.42019-10-25
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitra…
- CVE-2019-4461MEDIUMCVSS 5.4EG 5.42019-10-25
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to perform further attacks, such as Web Cache poisoning, cross…
- CVE-2019-4558HIGHCVSS 7.8EG 7.82019-10-09
A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spectrum Scale V4.2.0.0 through V4.2.3.17 that could allow a local attacker to obtain root privilege by injecting parameters…
- CVE-2019-5314MEDIUMCVSS 6.1EG 6.12019-09-13
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability.
- CVE-2019-5404HIGHCVSS 8.8EG 8.82019-08-09
A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
- CVE-2019-5977MEDIUMCVSS 4.3EG 4.32019-09-12
Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter mail header via the application 'E-Mail'.
- CVE-2019-6034MEDIUMCVSS 6.1EG 6.12019-12-26
a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in the context of the application due to unspecified vectors.
- CVE-2019-6800HIGHCVSS 7.5EG 7.52019-06-05
In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network po…
- CVE-2019-6802MEDIUMCVSS 6.1EG 6.12019-01-25
CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.
- CVE-2019-7351MEDIUMCVSS 6.5EG 6.52019-02-04
Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject a custom Log message provided by the attacker in the 'log' view page, as demonstrated by t…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →