CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
482 vulnerabilities with CWE-116
CVE-2022-43883
MEDIUM
IBM Cognos Analytics <11.2.1 - Log Injection
CVSS 6.5
CVE-2022-41934
CRITICAL
XWiki Platform < 13.10.8 - Authenticated Remote Code Execution via Menu Macro Injection
CVSS 9.9
CVE-2022-40870
HIGH
Parallels Remote Application Server <18.0 - Command Injection
CVSS 8.1
CVE-2022-0421
MEDIUM
Five Star Restaurant Reservations WP <2.4.12 - XSS
CVSS 6.1
CVE-2022-4011
MEDIUM
Simple History Plugin - Info Disclosure
CVSS 6.5
CVE-2022-34316
LOW
IBM CICS TX 11.1 - Cross-Site Scripting via HTTP Headers
CVSS 3.7
CVE-2022-3941
MEDIUM
Activity Log Plugin - Info Disclosure
CVSS 5.3
CVE-2022-41443
CRITICAL
phpipam 1.5.0 - Header Injection via ripe-query.php Component
CVSS 9.8
CVE-2022-41322
HIGH
kitty < 0.26.2 - Remote Code Execution via Desktop Notification Escape Sequence
CVSS 7.8
CVE-2022-39958
HIGH
OWASP ModSecurity Core Rule Set 3.0.0-3.2.1 and 3.3.2 - Response Body Exfiltration via HTTP Range Header Bypass
CVSS 7.5
CVE-2022-39957
HIGH
OWASP ModSecurity Core Rule Set - Auth Bypass
CVSS 7.3
CVE-2022-39956
HIGH
OWASP ModSecurity Core Rule Set 3.0.0-3.2.1 & 3.3.2 - Bypass via Character Encoding in MIME Headers
CVSS 7.3
CVE-2022-36100
CRITICAL
XWiki Platform <14.4 - Code Injection
CVSS 9.9
CVE-2022-36099
CRITICAL
XWiki Platform Wiki UI Main Wiki <13.10.6-14.4 - Code Injection
CVSS 9.9
CVE-2022-35153
CRITICAL
FusionPBX 5.0.1 - OS Command Injection via Fax Send Endpoint
CVSS 9.8
CVE-2022-2619
MEDIUM
Google Chrome < 104.0.5112.79 - Script Injection via Malicious Extension
CVSS 4.3
CVE-2022-2241
MEDIUM
Featured Image from URL (FIFU) < 4.0.1 - Cross-Site Request Forgery and Stored Cross-Site Scripting
CVSS 6.1
CVE-2022-36446
CRITICAL
Webmin < 1.997 - Remote Code Execution via Unescaped UI Command
CVSS 9.8
CVE-2022-2099
MEDIUM
WooCommerce < 6.6.0 - Stored Cross-Site Scripting in Payment Gateway Titles
CVSS 4.8
CVE-2022-20230
MEDIUM
Android - Local Information Disclosure via KeyChain choosePrivateKeyAlias
CVSS 5.5
CVE-2022-34820
HIGH
SIMATIC and SIPLUS CP Firmware - Remote Code Execution via Authentication Field Injection
CVSS 8.4
CVE-2022-32549
MEDIUM
Apache Sling Commons Log <= 5.4.0 & Apache Sling API <= 2.25.0 - Co...
CVSS 5.3
CVE-2022-23079
motor-admin <0.2.56 - Host Header Injection
CVE-2022-29258
HIGH
XWiki Platform <12.10.11-14.0-rc-1-13.4.7-13.10.3 - XSS
CVSS 7.4
CVE-2022-29252
HIGH
XWiki Platform Wiki UI Main Wiki <5.3-milestone-2 - XSS
CVSS 7.4
Details
Vulnerabilities
482
Exploit Likelihood
High