CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

446 vulnerabilities with CWE-116
CVE-2022-39956 HIGH
OWASP ModSecurity Core Rule Set 3.0.0-3.2.1 & 3.3.2 - Bypass via Character Encoding in MIME Headers
CVSS 7.3
CVE-2022-36100 CRITICAL
XWiki Platform <14.4 - Code Injection
CVSS 9.9
CVE-2022-36099 CRITICAL
XWiki Platform Wiki UI Main Wiki <13.10.6-14.4 - Code Injection
CVSS 9.9
CVE-2022-35153 CRITICAL
FusionPBX 5.0.1 - OS Command Injection via Fax Send Endpoint
CVSS 9.8
CVE-2022-2619 MEDIUM
Google Chrome < 104.0.5112.79 - Script Injection via Malicious Extension
CVSS 4.3
CVE-2022-2241 MEDIUM
Featured Image from URL (FIFU) < 4.0.1 - Cross-Site Request Forgery and Stored Cross-Site Scripting
CVSS 6.1
CVE-2022-36446 CRITICAL
Webmin < 1.997 - Remote Code Execution via Unescaped UI Command
CVSS 9.8
CVE-2022-2099 MEDIUM
WooCommerce < 6.6.0 - Stored Cross-Site Scripting in Payment Gateway Titles
CVSS 4.8
CVE-2022-20230 MEDIUM
Android - Local Information Disclosure via KeyChain choosePrivateKeyAlias
CVSS 5.5
CVE-2022-34820 HIGH
SIMATIC and SIPLUS CP Firmware - Remote Code Execution via Authentication Field Injection
CVSS 8.4
CVE-2022-32549 MEDIUM
Apache Sling Commons Log <= 5.4.0 & Apache Sling API <= 2.25.0 - Co...
CVSS 5.3
CVE-2022-23079
motor-admin <0.2.56 - Host Header Injection
CVE-2022-29258 HIGH
XWiki Platform <12.10.11-14.0-rc-1-13.4.7-13.10.3 - XSS
CVSS 7.4
CVE-2022-29252 HIGH
XWiki Platform Wiki UI Main Wiki <5.3-milestone-2 - XSS
CVSS 7.4
CVE-2022-29251 HIGH
XWiki Platform Flamingo Theme UI <12.10.11,14.0-rc-1,13.4.7,13.10.3...
CVSS 7.4
CVE-2022-29599 CRITICAL
Apache Maven maven-shared-utils <3.3.3 - Command Injection
CVSS 9.8
CVE-2022-28960 HIGH
SPIP < 3.2.8 - Remote Code Execution via _oups Parameter
CVSS 8.8
CVE-2022-30966 MEDIUM
Jenkins Random String Parameter Plugin <1.0 - XSS
CVSS 5.4
CVE-2022-30781 HIGH
Gitea < 1.16.7 - Remote Code Execution via Git Fetch Remote
CVSS 7.5
CVE-2022-0935 HIGH
livehelperchat/livehelperchat <3.97 - SSRF
CVSS 8.8
CVE-2022-0741 MEDIUM
GitLab 10.0.0-14.6.5 - Environment Variable Exposure via Sendmail Email Address Injection
CVSS 5.8
CVE-2022-0450 MEDIUM
Menu Image Icons made easy <3.0.6 - CSRF
CVSS 5.4
CVE-2022-26174 CRITICAL
Beekeeper Studio < 3.7.10 - Remote Code Execution via Display Field Injection
CVSS 9.8
CVE-2022-22734 MEDIUM
Simple Quotation < 1.3.2 - Cross-Site Scripting via Quote Creation/Editing
CVSS 6.1
CVE-2022-22151 HIGH
Yokogawa Electric - Info Disclosure
CVSS 8.1
Details
Vulnerabilities 446
Exploit Likelihood High