CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

414 vulnerabilities with CWE-116
CVE-2022-42948 CRITICAL KEV
Cobalt Strike 4.7.1 - XSS
CVSS 9.8
CVE-2022-48339 HIGH
GNU Emacs < 28.2 - Command Injection
CVSS 7.8
CVE-2022-45102 MEDIUM
Dell EMC Data Protection Central <19.7 - Host Header Injection
CVSS 5.4
CVE-2022-45143 HIGH
Apache Tomcat <10.1.1 - Info Disclosure
CVSS 7.5
CVE-2022-28284 HIGH
Firefox < 99 - Info Disclosure
CVSS 8.8
CVE-2022-22744 HIGH
Mozilla Firefox < 96.0 - Command Injection
CVSS 8.8
CVE-2022-43543 MEDIUM
+Message App - XSS
CVSS 5.4
CVE-2022-43883 MEDIUM
IBM Cognos Analytics <11.2.1 - Log Injection
CVSS 6.5
CVE-2022-41934 CRITICAL
XWiki Platform - RCE
CVSS 9.9
CVE-2022-40870 HIGH
Parallels Remote Application Server <18.0 - Command Injection
CVSS 8.1
CVE-2022-0421 MEDIUM
Five Star Restaurant Reservations WP <2.4.12 - XSS
CVSS 6.1
CVE-2022-4011 MEDIUM
Simple History Plugin - Info Disclosure
CVSS 6.5
CVE-2022-34316 LOW
IBM CICS TX 11.1 - XSS
CVSS 3.7
CVE-2022-3941 MEDIUM
Activity Log Plugin - Info Disclosure
CVSS 5.3
CVE-2022-41443 CRITICAL
phpipam <1.5.0 - Header Injection
CVSS 9.8
CVE-2022-41322 HIGH
Kitty <0.26.2 - RCE
CVSS 7.8
CVE-2022-39958 HIGH
Owasp Modsecurity Core Rule Set < 3.2.2 - Incorrect Authorization
CVSS 7.5
CVE-2022-39957 HIGH
OWASP ModSecurity Core Rule Set - Auth Bypass
CVSS 7.3
CVE-2022-39956 HIGH
Owasp Modsecurity Core Rule Set < 3.2.2 - Incorrect Authorization
CVSS 7.3
CVE-2022-36100 CRITICAL
XWiki Platform <14.4 - Code Injection
CVSS 9.9
CVE-2022-36099 CRITICAL
XWiki Platform Wiki UI Main Wiki <13.10.6-14.4 - Code Injection
CVSS 9.9
CVE-2022-35153 CRITICAL
Fusionpbx - Command Injection
CVSS 9.8
CVE-2022-2619 MEDIUM
Google Chrome <104.0.5112.79 - XSS
CVSS 4.3
CVE-2022-2241 MEDIUM
Fifu Featured Image From Url < 4.0.0 - XSS
CVSS 6.1
CVE-2022-36446 CRITICAL
Webmin <1.997 - XSS
CVSS 9.8
Details
Vulnerabilities 414
Exploit Likelihood High