CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
446 vulnerabilities with CWE-116
CVE-2023-0595
MEDIUM
EcoStruxure Geo SCADA Expert <October 2022 - Info Disclosure
CVSS 5.3
CVE-2022-22399
MEDIUM
IBM Aspera Faspex <5.0.1 - HTTP Header Injection
CVSS 5.4
CVE-2022-36392
HIGH
Intel(R) AMT & Intel(R) Standard Manageability <11.8.94-16.1.27 - DoS
CVSS 8.6
CVE-2022-43713
HIGH
GX Software XperienCentral <10.35.0 - Info Disclosure
CVSS 7.5
CVE-2022-31458
MEDIUM
RTX TRAP v1.0 - Host Header Injection
CVSS 6.1
CVE-2022-30351
HIGH
PDFZorro Online r20220428 - Info Disclosure
CVSS 7.5
CVE-2022-46387
CRITICAL
Cmder < 1.3.2 and ConEmu < 22.08.07 - Command Injection via Terminal Title Control Characters
CVSS 9.8
CVE-2022-42948
CRITICAL
KEV
Cobalt Strike 4.7.1 - Remote Code Execution via HTML Injection in Swing UI
CVSS 9.8
CVE-2022-48339
HIGH
GNU Emacs < 28.2 - OS Command Injection in htmlfontify.el
CVSS 7.8
CVE-2022-45102
MEDIUM
Dell EMC Data Protection Central <19.7 - Host Header Injection
CVSS 5.4
CVE-2022-45143
HIGH
Apache Tomcat <10.1.1 - Info Disclosure
CVSS 7.5
CVE-2022-28284
HIGH
Firefox < 99.0 - Cross-Site Scripting via SVG Use Element
CVSS 8.8
CVE-2022-22744
HIGH
Firefox < 96.0 and Firefox ESR < 91.5 - Command Injection via DevTools Copy as curl
CVSS 8.8
CVE-2022-43543
MEDIUM
docomo/softbank/kddi +Message < 3.9.4 - URL Spoofing via Unicode Control Character Mishandling
CVSS 5.4
CVE-2022-43883
MEDIUM
IBM Cognos Analytics <11.2.1 - Log Injection
CVSS 6.5
CVE-2022-41934
CRITICAL
XWiki Platform < 13.10.8 - Authenticated Remote Code Execution via Menu Macro Injection
CVSS 9.9
CVE-2022-40870
HIGH
Parallels Remote Application Server <18.0 - Command Injection
CVSS 8.1
CVE-2022-0421
MEDIUM
Five Star Restaurant Reservations WP <2.4.12 - XSS
CVSS 6.1
CVE-2022-4011
MEDIUM
Simple History Plugin - Info Disclosure
CVSS 6.5
CVE-2022-34316
LOW
IBM CICS TX 11.1 - Cross-Site Scripting via HTTP Headers
CVSS 3.7
CVE-2022-3941
MEDIUM
Activity Log Plugin - Info Disclosure
CVSS 5.3
CVE-2022-41443
CRITICAL
phpipam 1.5.0 - Header Injection via ripe-query.php Component
CVSS 9.8
CVE-2022-41322
HIGH
kitty < 0.26.2 - Remote Code Execution via Desktop Notification Escape Sequence
CVSS 7.8
CVE-2022-39958
HIGH
OWASP ModSecurity Core Rule Set 3.0.0-3.2.1 and 3.3.2 - Response Body Exfiltration via HTTP Range Header Bypass
CVSS 7.5
CVE-2022-39957
HIGH
OWASP ModSecurity Core Rule Set - Auth Bypass
CVSS 7.3
Details
Vulnerabilities
446
Exploit Likelihood
High