CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
4,606 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 7 of 93
- CVE-2020-11441MEDIUMCVSS 6.1EG 6.12020-03-31
phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.
- CVE-2020-11546CRITICALCVSS 9.8EG 9.82020-07-14
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Inject…
- CVE-2020-11593HIGHCVSS 7.5EG 7.52020-04-06
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is later leveraged to send emails from a customer trusted email address.
- CVE-2020-11647HIGHCVSS 7.5EG 7.52020-04-10
In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.
- CVE-2020-11703HIGHCVSS 7.5EG 7.52020-04-12
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response Splitting via the language parameter.
- CVE-2020-11709HIGHCVSS 7.5EG 7.52020-04-12
cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP response splitting in some specific contexts.
- CVE-2020-11733MEDIUMCVSS 6.7EG 6.72020-08-13
An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restricted shell, can achieve root access via shell metacharacters. The attacker can then, for ex…
- CVE-2020-11766HIGHCVSS 8.8EG 8.82020-05-19
sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.
- CVE-2020-11770HIGHCVSS 8.8EG 8.82020-04-15
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000v2 before 1.0.0.53, D8500 before 1.0.3.44, R6220 before 1.1.0.80, R6250 before 1.0.4.34, R6…
- CVE-2020-11789CRITICALCVSS 9.8EG 9.82020-04-15
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.
- CVE-2020-11814MEDIUMCVSS 5.4EG 5.42020-04-16
A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious websites.
- CVE-2020-11852HIGHCVSS 8.8EG 8.82020-08-07
DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG). Affecting all SMG Appliance running releases prior to July 2020. The vulnerability could allow a logged in user with rights to generate DKIM key informat…
- CVE-2020-11928CRITICALCVSS 9.8EG 9.82020-04-20
In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin.
- CVE-2020-11994HIGHCVSS 7.5EG 7.52020-07-08
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
- CVE-2020-12074HIGHCVSS 8.8EG 8.82020-04-23
The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
- CVE-2020-12078HIGHCVSS 8.8EG 8.82020-04-28
An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker can exploit this by adding an excluded IP address to the global discovery settings (interna…
- CVE-2020-12108MEDIUMCVSS 6.5EG 6.52020-05-06
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
- CVE-2020-12393HIGHCVSS 7.8EG 7.82020-05-26
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could ha…
- CVE-2020-12408MEDIUMCVSS 6.5EG 6.52020-07-09
When browsing a document hosted on an IP address, an attacker could insert certain characters to flip domain and path information in the address bar. This vulnerability affects Firefox < 77.
- CVE-2020-12736HIGHCVSS 7.2EG 7.22020-07-07
Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an administrator creates a local (non-SSO) user via a Code42-generated email, the administrator has the option to modify …
- CVE-2020-12753CRITICALCVSS 9.8EG 9.82020-05-11
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Arbitrary code execution can occur via the bootloader because of an EL1/EL3 coldboot vulnerability involving raw_resources. The LG ID is LVE-SM…
- CVE-2020-12782CRITICALCVSS 9.8EG 9.82020-06-23
Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be triggered and gain unauthorized access to system files.
- CVE-2020-12790HIGHCVSS 7.5EG 7.52020-05-11
In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side Template Injection and credentials disclosure via a crafted Twig template after a semicolon.
- CVE-2020-12817HIGHCVSS 8.8EG 8.82020-09-24
An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Connectors.
- CVE-2020-12835CRITICALCVSS 9.8EG 9.82020-05-20
An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote cod…
- CVE-2020-12855HIGHCVSS 8.8EG 8.82020-08-26
A Host header injection vulnerability has been discovered in SecZetta NEProfile 3.3.11. Authenticated remote adversaries can poison this header resulting in an adversary controlling the execution flow for the 302 HTTP status.
- CVE-2020-12873HIGHCVSS 8.8EG 8.82021-02-19
An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same p…
- CVE-2020-12965HIGHCVSS 7.5EG 7.52022-02-04
When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits potentially resulting in data leakage.
- CVE-2020-13146HIGHCVSS 8.8EG 8.82020-05-18
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature.
- CVE-2020-13167CRITICALCVSS 9.8EG 9.82020-05-19
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.
- CVE-2020-13247HIGHCVSS 7.3EG 7.32020-06-24
BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area.
- CVE-2020-13262MEDIUMCVSS 6.1EG 6.12020-06-19
Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link
- CVE-2020-1327MEDIUMCVSS 6.1EG 6.12020-06-09
A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.
- CVE-2020-13279HIGHCVSS 8.6EG 8.62020-06-22
Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system
- CVE-2020-13311MEDIUMCVSS 4.3EG 4.32020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface.
- CVE-2020-13445HIGHCVSS 8.8EG 8.82020-06-10
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which allows remote authenticated users to execu…
- CVE-2020-13448HIGHCVSS 8.8EG 8.82020-06-01
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.
- CVE-2020-13480MEDIUMCVSS 5.4EG 5.42020-06-22
Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature.
- CVE-2020-13651HIGHCVSS 7.8EG 7.82020-06-15
An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200421, and 2019R2 before p20200430. It allows a user to provide data that will be used to generate the JNLP file used by a client to obtain the right Java applic…
- CVE-2020-13826HIGHCVSS 8.8EG 8.82020-08-20
A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled in a CSV export.
- CVE-2020-13851HIGHCVSS 8.8EG 9.02020-06-11
Artica Pandora FMS 7.44 allows remote command execution via the events feature.
- CVE-2020-13863HIGHCVSS 8.1EG 8.12020-08-26
The SAS portal of Mitel MiCollab before 9.1.3 could allow an attacker to access user data by performing a header injection in HTTP responses, due to the improper handling of input parameters. A successful exploit could allow an attacker to…
- CVE-2020-13942CRITICALCVSS 9.8EG 9.82020-11-24
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the…
- CVE-2020-13977MEDIUMCVSS 4.9EG 4.92020-06-09
Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and …
- CVE-2020-14094CRITICALCVSS 9.8EG 9.82020-06-24
In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow or remote code execution.
- CVE-2020-14095CRITICALCVSS 9.8EG 9.82020-06-24
In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to a stack overflow or remote code execution.
- CVE-2020-14172CRITICALCVSS 9.8EG 9.82020-07-03
This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server and Data Center in af…
- CVE-2020-14193MEDIUMCVSS 5.4EG 5.42020-11-30
Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF/classes & <jira-installation>/jira/bin directories via a template injection vulnerability…
- CVE-2020-1443MEDIUMCVSS 5.4EG 5.42020-07-14
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.
- CVE-2020-14433MEDIUMCVSS 6.8EG 6.82020-06-18
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBK842 before 3.2.15.25, RBR850 before 3.2.15.25, RBS850 before 3.2.15.25, RBR840 before 3.2…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →