CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

482 vulnerabilities with CWE-116
CVE-2024-39682 MEDIUM
Cooked < 1.8.0 - Authenticated HTML Injection via Insufficient Input Sanitization
CVSS 6.4
CVE-2024-39736 MEDIUM
IBM Datacap Navigator 9.1.5-9.1.9 - HTTP Header Injection via HOST Header
CVSS 6.5
CVE-2024-39929 MEDIUM
Exim < 4.97.1 - Improper Encoding or Escaping of Output via Multiline RFC 2231 Header Filename
CVSS 5.4
CVE-2024-38475 CRITICAL KEV
Apache HTTP Server < 2.4.60 - Remote Code Execution via mod_rewrite Unsafe Substitution
CVSS 9.1
CVE-2024-38474 CRITICAL
Apache HTTP Server < 2.4.60 - Script Execution via mod_rewrite Substitution Encoding Issue
CVSS 9.8
CVE-2024-38473 HIGH
Apache HTTP Server <2.4.60 - Open Redirect
CVSS 8.1
CVE-2024-27629 HIGH
dcm2niix < 1.0.20240202 - OS Command Injection via Filename Escaping
CVSS 7.8
CVE-2024-35225 CRITICAL
Jupyter Server Proxy 3.0.0-3.2.3 and 4.0.0-4.1.9 - Reflected Cross-Site Scripting via Host Path Segment
CVSS 9.6
CVE-2024-5585 HIGH
PHP <8.1.29, 8.2.*<8.2.20, 8.3.*<8.3.8 - Command Injection
CVSS 7.7
CVE-2024-4177 HIGH
Bitdefender GravityZone < 6.38.1-2 - Server-Side Request Forgery via Host Whitelist Parser
CVSS 8.1
CVE-2024-34715 LOW
Fides < 2.37.0 - Sensitive Information Exposure in Database Password Logs
CVSS 2.3
CVE-2024-4420 HIGH
Tink-cc < 2.1.3 - Denial of Service via Malformed JSON Input
CVSS 7.5
CVE-2024-34355 LOW
TYPO3 13.0.0-13.1.0 - Authenticated HTML Injection in History Backend Module
CVSS 3.5
CVE-2024-29894 MEDIUM
Cacti < 1.2.27 - Stored Cross-Site Scripting via Unescaped PHP Variables
CVSS 5.4
CVE-2024-34510 HIGH
Gradio < 4.20.0 - Credential Leakage on Windows
CVSS 7.5
CVE-2024-1874 CRITICAL
PHP <8.1.28, 8.2.*<8.2.18, 8.3.*<8.3.5 - Command Injection
CVSS 9.4
CVE-2024-31866 CRITICAL
Apache Zeppelin 0.8.2-0.11.0 - Remote Code Execution via Configuration Override
CVSS 9.8
CVE-2024-22356 MEDIUM
IBM App Connect Enterprise <12.0.9.0 - Info Disclosure
CVSS 4.9
CVE-2024-28245 MEDIUM
KaTeX 0.11.0-0.16.9 - Cross-Site Scripting via \\includegraphics
CVSS 6.3
CVE-2024-29156 MEDIUM
OpenStack Murano <16.0.0 - Info Disclosure
CVSS 6.5
CVE-2024-27938 MEDIUM
Postal < 3.0.0 - SMTP Smuggling via Non-Compliant End of DATA Sequence
CVSS 5.3
CVE-2024-21499 MEDIUM
github.com/greenpau/caddy-security - HTTP Header Injection
CVSS 4.3
CVE-2024-0690 MEDIUM
ansible-core < 2.14.14 - Information Disclosure via ANSIBLE_NO_LOG Bypass
CVSS 5.0
CVE-2024-1064 HIGH
Crafty Controller 4.0.0-4.2.2 - Unauthenticated Denial of Service via Host Header Injection
CVSS 7.5
CVE-2024-0987 MEDIUM
Sichuan Yougou Technology KuERP <1.0.4 - Info Disclosure
CVSS 6.3
Details
Vulnerabilities 482
Exploit Likelihood High