CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

482 vulnerabilities with CWE-116
CVE-2024-22229 LOW
Dell Unity Operating Environment - Authenticated Log Spoofing via Improper Output Encoding
CVSS 3.1
CVE-2024-0233 MEDIUM
EventON WordPress plugin < 2.2.7 - Reflected Cross-Site Scripting
CVSS 6.1
CVE-2024-22199 CRITICAL
gofiber/template < 3.1.9 - Cross-Site Scripting via Autoescape Bypass
CVSS 9.3
CVE-2023-35894 MEDIUM
IBM Sterling Control Center 6.2.1-6.3.1 - HTTP Header Injection via HOST Header
CVSS 5.4
CVE-2023-28362 MEDIUM
Rails - Open Redirect
CVSS 4.0
CVE-2023-45359 MEDIUM
MediaWiki Vector Skin < 1.39.5 and 1.40.0 - Cross-Site Scripting in Table of Contents Toggle Button
CVSS 6.5
CVE-2023-26289 MEDIUM
IBM Aspera Orchestrator 4.0.1 - HTTP Header Injection
CVSS 5.4
CVE-2023-28952 MEDIUM
IBM Cognos Controller <11.0.0 - Command Injection
CVSS 5.3
CVE-2023-47143 CRITICAL
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0-7.3.0.10 - HTTP Header Injection via HOST Header
CVSS 10.0
CVE-2023-28738 HIGH
Intel NUC BIOS <JY0070 - Privilege Escalation
CVSS 7.5
CVE-2023-7234 MEDIUM
OPCUAServerToolkit - Info Disclosure
CVSS 5.3
CVE-2023-6005 MEDIUM
EventON WordPress plugin <4.5.5-2.2.7 - XSS
CVSS 4.8
CVE-2023-52102 HIGH
Huawei EMUI and HarmonyOS - Information Disclosure via WMS Module Parameter Verification
CVSS 7.5
CVE-2023-52098 HIGH
Huawei DMS Module - Denial of Service
CVSS 7.5
CVE-2023-42183 MEDIUM
lockss-daemon <1.77.3 - Auth Bypass
CVSS 5.3
CVE-2023-45539 HIGH
HAProxy < 2.8.2 - Improper URI Component Handling via Fragment Identifier
CVSS 8.2
CVE-2023-26279 LOW
IBM QRadar WinCollect Agent <10.1.7 - Privilege Escalation
CVSS 3.3
CVE-2023-38316 CRITICAL
OpenNDS Captive Portal <10.1.2 - Command Injection
CVSS 9.8
CVE-2023-48655 CRITICAL
MISP < 2.4.176 - SQL Injection via Improper Filtering of Query Parameters
CVSS 9.8
CVE-2023-40453 MEDIUM
Docker Machine < 0.16.2 - Escape Sequence Injection and Denial of Service via Crafted Version Data
CVSS 6.5
CVE-2023-5968 MEDIUM
Mattermost - Exposure of Sensitive Information via User Object Sanitization Failure
CVSS 4.9
CVE-2023-4393 MEDIUM
LiquidFiles <3.7.13 - Command Injection
CVSS 5.4
CVE-2023-45135 CRITICAL
XWiki Platform 7.2-milestone-2-14.10.12 - Remote Code Execution via Page Creation Title Parameter
CVSS 9.0
CVE-2023-46301 CRITICAL
iTerm2 < 3.4.20 - Remote Code Execution via Escape Sequence Mishandling
CVSS 9.8
CVE-2023-46300 CRITICAL
iTerm2 < 3.4.20 - Remote Code Execution via tmux Escape Sequence Mishandling
CVSS 9.8
Details
Vulnerabilities 482
Exploit Likelihood High