CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
414 vulnerabilities with CWE-116
CVE-2022-42948
CRITICAL
KEV
Cobalt Strike 4.7.1 - XSS
CVSS 9.8
CVE-2022-48339
HIGH
GNU Emacs < 28.2 - Command Injection
CVSS 7.8
CVE-2022-45102
MEDIUM
Dell EMC Data Protection Central <19.7 - Host Header Injection
CVSS 5.4
CVE-2022-45143
HIGH
Apache Tomcat <10.1.1 - Info Disclosure
CVSS 7.5
CVE-2022-28284
HIGH
Firefox < 99 - Info Disclosure
CVSS 8.8
CVE-2022-22744
HIGH
Mozilla Firefox < 96.0 - Command Injection
CVSS 8.8
CVE-2022-43543
MEDIUM
+Message App - XSS
CVSS 5.4
CVE-2022-43883
MEDIUM
IBM Cognos Analytics <11.2.1 - Log Injection
CVSS 6.5
CVE-2022-41934
CRITICAL
XWiki Platform - RCE
CVSS 9.9
CVE-2022-40870
HIGH
Parallels Remote Application Server <18.0 - Command Injection
CVSS 8.1
CVE-2022-0421
MEDIUM
Five Star Restaurant Reservations WP <2.4.12 - XSS
CVSS 6.1
CVE-2022-4011
MEDIUM
Simple History Plugin - Info Disclosure
CVSS 6.5
CVE-2022-34316
LOW
IBM CICS TX 11.1 - XSS
CVSS 3.7
CVE-2022-3941
MEDIUM
Activity Log Plugin - Info Disclosure
CVSS 5.3
CVE-2022-41443
CRITICAL
phpipam <1.5.0 - Header Injection
CVSS 9.8
CVE-2022-41322
HIGH
Kitty <0.26.2 - RCE
CVSS 7.8
CVE-2022-39958
HIGH
Owasp Modsecurity Core Rule Set < 3.2.2 - Incorrect Authorization
CVSS 7.5
CVE-2022-39957
HIGH
OWASP ModSecurity Core Rule Set - Auth Bypass
CVSS 7.3
CVE-2022-39956
HIGH
Owasp Modsecurity Core Rule Set < 3.2.2 - Incorrect Authorization
CVSS 7.3
CVE-2022-36100
CRITICAL
XWiki Platform <14.4 - Code Injection
CVSS 9.9
CVE-2022-36099
CRITICAL
XWiki Platform Wiki UI Main Wiki <13.10.6-14.4 - Code Injection
CVSS 9.9
CVE-2022-35153
CRITICAL
Fusionpbx - Command Injection
CVSS 9.8
CVE-2022-2619
MEDIUM
Google Chrome <104.0.5112.79 - XSS
CVSS 4.3
CVE-2022-2241
MEDIUM
Fifu Featured Image From Url < 4.0.0 - XSS
CVSS 6.1
CVE-2022-36446
CRITICAL
Webmin <1.997 - XSS
CVSS 9.8
Details
Vulnerabilities
414
Exploit Likelihood
High