CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
482 vulnerabilities with CWE-116
CVE-2022-29251
HIGH
XWiki Platform Flamingo Theme UI <12.10.11,14.0-rc-1,13.4.7,13.10.3...
CVSS 7.4
CVE-2022-29599
CRITICAL
Apache Maven maven-shared-utils <3.3.3 - Command Injection
CVSS 9.8
CVE-2022-28960
HIGH
SPIP < 3.2.8 - Remote Code Execution via _oups Parameter
CVSS 8.8
CVE-2022-30966
MEDIUM
Jenkins Random String Parameter Plugin <1.0 - XSS
CVSS 5.4
CVE-2022-30781
HIGH
Gitea < 1.16.7 - Remote Code Execution via Git Fetch Remote
CVSS 7.5
CVE-2022-0935
HIGH
livehelperchat/livehelperchat <3.97 - SSRF
CVSS 8.8
CVE-2022-0741
MEDIUM
GitLab 10.0.0-14.6.5 - Environment Variable Exposure via Sendmail Email Address Injection
CVSS 5.8
CVE-2022-0450
MEDIUM
Menu Image Icons made easy <3.0.6 - CSRF
CVSS 5.4
CVE-2022-26174
CRITICAL
Beekeeper Studio < 3.7.10 - Remote Code Execution via Display Field Injection
CVSS 9.8
CVE-2022-22734
MEDIUM
Simple Quotation < 1.3.2 - Cross-Site Scripting via Quote Creation/Editing
CVSS 6.1
CVE-2022-22151
HIGH
Yokogawa Electric - Info Disclosure
CVSS 8.1
CVE-2022-25235
CRITICAL
libexpat < 2.4.5 - Improper Encoding or Escaping of Output
CVSS 9.8
CVE-2022-23620
MEDIUM
XWiki < 13.6 - Path Traversal via SSX Document Reference Export
CVSS 6.8
CVE-2022-24682
MEDIUM
KEV
Zimbra Collaboration Suite <8.8.15 patch 30 (update 1) - XSS
CVSS 6.1
CVE-2022-0220
MEDIUM
WordPress GDPR & CCPA < 1.9.26 - Unauthenticated Stored Cross-Site Scripting via check_privacy_settings AJAX Action
CVSS 6.1
CVE-2022-23603
CRITICAL
iTunesRPC-Remastered - Code Injection
CVSS 9.9
CVE-2022-22992
HIGH
Western Digital My Cloud OS < 5.19.117 - Remote Code Execution via Improper Shell Argument Escaping
CVSS 7.8
CVE-2022-0210
MEDIUM
Random Banner WordPress <4.1.4 - XSS
CVSS 4.8
CVE-2022-0124
MEDIUM
GitLab <14.4.5, 14.5.0-14.5.3, 14.6.0-14.6.1 - Open Redirect
CVSS 4.3
CVE-2021-47694
MEDIUM
Nagios XI < 5.8.6 - Reflected Cross-Site Scripting via CCM Test Command
CVSS 6.1
CVE-2021-25262
MEDIUM
Yandex Browser for Android <21.3.0 - Open Redirect
CVSS 5.4
CVE-2021-25254
MEDIUM
Yandex Browser Lite for Android < 21.1.0 - Address Bar Spoofing
CVSS 5.3
CVE-2021-38997
MEDIUM
IBM API Connect <10.0.5.0 - HTTP Header Injection
CVSS 5.4
CVE-2021-42010
CRITICAL
Apache Heron <= 0.20.4-incubating - CRLF Log Injection
CVSS 9.8
CVE-2021-40694
MEDIUM
moodle < 3.9.10 - Unauthenticated Arbitrary File Read via LaTeX Preamble
CVSS 4.9
Details
Vulnerabilities
482
Exploit Likelihood
High