CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
446 vulnerabilities with CWE-116
CVE-2023-39527
HIGH
PrestaShop < 1.7.8.10, 8.0.5, 8.1.1 - Cross-Site Scripting via isCleanHTML Method
CVSS 8.3
CVE-2023-3997
HIGH
Splunk SOAR <6.1.0 - Code Injection
CVSS 8.6
CVE-2023-35941
HIGH
Envoy <1.27.0-1.23.12 - Auth Bypass
CVSS 8.6
CVE-2023-34036
MEDIUM
Reactive web apps using Spring HATEOAS - SSRF
CVSS 5.3
CVE-2023-3668
HIGH
GitHub froxlor/froxlor <2.0.21 - XSS
CVSS 7.2
CVE-2023-24480
CRITICAL
Honeywell C300 Firmware 501.1-501.6hf8 - Denial of Service via Message Decoding Stack Overflow
CVSS 9.8
CVE-2023-2200
MEDIUM
GitLab CE/EE <15.11.10, <16.0.6, <16.1.1 - XSS
CVSS 4.1
CVE-2023-36921
HIGH
SAP Solution Manager (Diagnostics agent) -7.20 - SSRF
CVSS 7.2
CVE-2023-36919
MEDIUM
SAP Enable Now - Unauthenticated Exposure of Sensitive Information via Missing Referrer-Policy Header
CVSS 5.3
CVE-2023-3552
MEDIUM
nilsteampassnet/teampass <3.0.10 - Info Disclosure
CVSS 5.4
CVE-2023-32301
LOW
Discourse <3.0.4-3.1.0.beta5 - Info Disclosure
CVSS 3.1
CVE-2023-3190
MEDIUM
nilsteampassnet/teampass <3.0.9 - Info Disclosure
CVSS 4.6
CVE-2023-29543
HIGH
Firefox and Focus for Android < 112.0 - Use-After-Free in Debugger Vector
CVSS 8.8
CVE-2023-29541
HIGH
Firefox < 112.0 - Arbitrary Command Execution via .desktop File Download
CVSS 8.8
CVE-2023-23599
MEDIUM
Firefox < 109, Firefox ESR < 102.7, Thunderbird < 102.7 - Command I...
CVSS 6.5
CVE-2023-32712
HIGH
Splunk Enterprise <9.1.0.2, <9.0.5.1, <8.2.11.2 - Code Injection
CVSS 8.6
CVE-2023-1711
MEDIUM
HitachiEnergy FOXMAN-UN and UNEM - Information Disclosure in Logging Component
CVSS 4.0
CVE-2023-31669
MEDIUM
WebAssembly wat2wasm <1.0.32 - Code Injection
CVSS 5.5
CVE-2023-32071
CRITICAL
XWiki Platform <2.2-14.4.8, <14.10.4, <15.0-rc-1 - XSS
CVSS 9.0
CVE-2023-30844
LOW
Mutagen <0.16.6-0.17.1 - Info Disclosure
CVSS 3.0
CVE-2023-28733
HIGH
AnyMailing Joomla Plugin <8.3.0 - XSS
CVSS 7.2
CVE-2023-28101
MEDIUM
Flatpak <1.10.8, <1.12.8, <1.14.4, <1.15.4 - Privilege Escalation
CVSS 5.0
CVE-2023-28487
MEDIUM
sudo < 1.9.13 - Improper Output Escaping in sudoreplay
CVSS 5.3
CVE-2023-28486
MEDIUM
sudo < 1.9.13 - Log Injection via Unescaped Control Characters
CVSS 5.3
CVE-2023-26472
CRITICAL
XWiki 6.2.1-13.10.9 - Unauthenticated Remote Code Execution via Icon Theme Sheet Injection
CVSS 9.9
Details
Vulnerabilities
446
Exploit Likelihood
High