CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 9 of 105
- CVE-2020-12835CRITICALCVSS 9.8EG 9.82020-05-20
An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote cod…
- CVE-2020-12855HIGHCVSS 8.8EG 8.82020-08-26
A Host header injection vulnerability has been discovered in SecZetta NEProfile 3.3.11. Authenticated remote adversaries can poison this header resulting in an adversary controlling the execution flow for the 302 HTTP status.
- CVE-2020-12873HIGHCVSS 8.8EG 8.82021-02-19
An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same p…
- CVE-2020-12965HIGHCVSS 7.5EG 7.52022-02-04
When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits potentially resulting in data leakage.
- CVE-2020-13146HIGHCVSS 8.8EG 8.82020-05-18
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature.
- CVE-2020-13167CRITICALCVSS 9.8EG 9.82020-05-19
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.
- CVE-2020-13247HIGHCVSS 7.3EG 7.32020-06-24
BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area.
- CVE-2020-13262MEDIUMCVSS 6.1EG 6.12020-06-19
Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link
- CVE-2020-1327MEDIUMCVSS 6.1EG 6.12020-06-09
A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.
- CVE-2020-13279HIGHCVSS 8.6EG 8.62020-06-22
Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system
- CVE-2020-13311MEDIUMCVSS 4.3EG 4.32020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface.
- CVE-2020-13445HIGHCVSS 8.8EG 8.82020-06-10
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which allows remote authenticated users to execu…
- CVE-2020-13448HIGHCVSS 8.8EG 8.82020-06-01
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.
- CVE-2020-13480MEDIUMCVSS 5.4EG 5.42020-06-22
Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature.
- CVE-2020-13651HIGHCVSS 7.8EG 7.82020-06-15
An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200421, and 2019R2 before p20200430. It allows a user to provide data that will be used to generate the JNLP file used by a client to obtain the right Java applic…
- CVE-2020-13826HIGHCVSS 8.8EG 8.82020-08-20
A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title parameter that is mishandled in a CSV export.
- CVE-2020-13851CRITICALCVSS 8.8EG 9.02020-06-11
Artica Pandora FMS 7.44 allows remote command execution via the events feature.
- CVE-2020-13863HIGHCVSS 8.1EG 8.12020-08-26
The SAS portal of Mitel MiCollab before 9.1.3 could allow an attacker to access user data by performing a header injection in HTTP responses, due to the improper handling of input parameters. A successful exploit could allow an attacker to…
- CVE-2020-13942CRITICALCVSS 9.8EG 9.82020-11-24
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the…
- CVE-2020-13977MEDIUMCVSS 4.9EG 4.92020-06-09
Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and …
- CVE-2020-14094CRITICALCVSS 9.8EG 9.82020-06-24
In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow or remote code execution.
- CVE-2020-14095CRITICALCVSS 9.8EG 9.82020-06-24
In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to a stack overflow or remote code execution.
- CVE-2020-14172CRITICALCVSS 9.8EG 9.82020-07-03
This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server and Data Center in af…
- CVE-2020-14193MEDIUMCVSS 5.4EG 5.42020-11-30
Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF/classes & <jira-installation>/jira/bin directories via a template injection vulnerability…
- CVE-2020-1443MEDIUMCVSS 5.4EG 5.42020-07-14
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.
- CVE-2020-14433MEDIUMCVSS 6.8EG 6.82020-06-18
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.15.25, RBK853 before 3.2.15.25, RBK842 before 3.2.15.25, RBR850 before 3.2.15.25, RBS850 before 3.2.15.25, RBR840 before 3.2…
- CVE-2020-14434MEDIUMCVSS 6.8EG 6.82020-06-18
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.…
- CVE-2020-14435HIGHCVSS 8.8EG 8.82020-06-18
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.2.104, SRS60 before 2.5.2.104, SRR60 before 2.5.2.104, SRK60B03 before 2.5.2.104, SRK60B04 before 2.5.2.104, SRK60B05 b…
- CVE-2020-14436HIGHCVSS 8.8EG 8.82020-06-18
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 bef…
- CVE-2020-14505CRITICALCVSS 9.8EG 9.82020-07-15
Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET o…
- CVE-2020-14571HIGHCVSS 7.2EG 7.22020-07-15
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Service). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticat…
- CVE-2020-1481HIGHCVSS 8.8EG 8.82020-07-14
A remote code execution vulnerability exists in the ESLint extension for Visual Studio Code when it validates source code after opening a project, aka 'Visual Studio Code ESLint Extention Remote Code Execution Vulnerability'.
- CVE-2020-14928MEDIUMCVSS 5.9EG 5.92020-07-17
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."
- CVE-2020-14954MEDIUMCVSS 5.9EG 5.92020-06-21
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and …
- CVE-2020-14965MEDIUMCVSS 4.8EG 4.82020-06-23
On TP-Link TL-WR740N v4 and TL-WR740ND v4 devices, an attacker with access to the admin panel can inject HTML code and change the HTML context of the target pages and stations in the access-control settings via targets_lists_name or hosts_…
- CVE-2020-14987HIGHCVSS 7.2EG 7.22021-03-11
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the capability for administrators to write and run Groovy scripts …
- CVE-2020-15011MEDIUMCVSS 4.3EG 4.32020-06-24
GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.
- CVE-2020-15070HIGHCVSS 8.8EG 8.82020-08-21
Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value.
- CVE-2020-15111MEDIUMCVSS 4.2EG 4.22020-07-20
In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is not escaped, and therefore vulnerable for a CRLF injection attack. I.e. an attacker could upload a custom filename and…
- CVE-2020-15140HIGHCVSS 8.2EG 8.22020-08-21
In Red Discord Bot before version 3.3.11, a RCE exploit has been discovered in the Trivia module: this exploit allows Discord users with specifically crafted usernames to inject code into the Trivia module's leaderboard command. By abusing…
- CVE-2020-15143HIGHCVSS 7.7EG 7.72020-08-20
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized properly. This allows the attacker to acces…
- CVE-2020-15146CRITICALCVSS 9.6EG 9.62020-08-20
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized properly. This allows the attacker to access…
- CVE-2020-15147HIGHCVSS 8.5EG 8.52020-08-21
Red Discord Bot before versions 3.3.12 and 3.4 has a Remote Code Execution vulnerability in the Streams module. This exploit allows Discord users with specifically crafted "going live" messages to inject code into the Streams module's goin…
- CVE-2020-15164CRITICALCVSS 10.0EG 10.02020-08-28
in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username with leading, trailing, or repeated underscore(s), since those are treated as whitespace and trimmed by MediaWiki. This af…
- CVE-2020-15171MEDIUMCVSS 6.6EG 6.62020-09-10
In XWiki before versions 11.10.5 or 12.2.1, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet context which contains tools allowing to instantiate arbitrary Java objects and invoke m…
- CVE-2020-15184LOWCVSS 3.7EG 3.72020-09-17
In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3…
- CVE-2020-15185LOWCVSS 2.2EG 2.22020-09-17
In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers the level of access that an attacker needs to inject a bad ch…
- CVE-2020-15186LOWCVSS 3.4EG 3.42020-09-17
In Helm before versions 2.16.11 and 3.3.2 plugin names are not sanitized properly. As a result, a malicious plugin author could use characters in a plugin name that would result in unexpected behavior, such as duplicating the name of anoth…
- CVE-2020-15187LOWCVSS 3.0EG 3.02020-09-17
In Helm before versions 2.16.11 and 3.3.2, a Helm plugin can contain duplicates of the same entry, with the last one always used. If a plugin is compromised, this lowers the level of access that an attacker needs to modify a plugin's insta…
- CVE-2020-15227HIGHCVSS 8.7EG 8.72020-10-01
Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →