CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

482 vulnerabilities with CWE-116
CVE-2021-4041 HIGH
ansible-runner < 2.1.0 - Command Injection via Improper Shell Command Escaping
CVSS 7.8
CVE-2021-23266 MEDIUM
Crafter CMS 3.1-3.1.17 - Unauthenticated Log Injection via URL Parameter
CVSS 4.3
CVE-2021-39027 MEDIUM
IBM Guardium Data Encryption <5.0.0 - Info Disclosure
CVSS 5.0
CVE-2021-29854 HIGH
IBM Maximo Asset Management 7.6.1.1-7.6.1.2 - HTTP Header Injection via HOST Header
CVSS 7.2
CVE-2021-45848 HIGH
nicotine+ 3.0.3-3.2.1 - Denial of Service via File Path Null Character
CVSS 7.5
CVE-2021-43106 MEDIUM
Compass Plus TranzWare Online FIMI Web Interface <5.3.33.3 F38 & FI...
CVSS 6.1
CVE-2021-45226 MEDIUM
COINS Construction Cloud <11.12 - Open Redirect
CVSS 6.5
CVE-2021-29872 MEDIUM
IBM Cloud Pak for Automation 21.0.1-21.0.2 - HTTP Header Injection via HOST Header
CVSS 5.4
CVE-2021-4068 MEDIUM
Google Chrome < 96.0.4664.93 - Cross-Origin Data Leak via New Tab Page
CVSS 6.5
CVE-2021-0933 HIGH
Android - Remote Escalation of Privilege via Bluetooth Pairing Dialog HTML Injection
CVSS 8.0
CVE-2021-44042 CRITICAL
UiPath Assistant - Stored Cross-Site Scripting via URI Handler Error Message
CVSS 9.8
CVE-2021-38182 HIGH
Kyma < 1.24.7 - Authenticated Privilege Escalation via Header Injection
CVSS 8.8
CVE-2021-40007 MEDIUM
Huawei eCNS280_TD V100R005C10SPC650 - Information Disclosure via Improper Log Output Management
CVSS 6.5
CVE-2021-43410 MEDIUM
Apache Airavata Django Portal <3c5d8c7 - Log Injection
CVSS 5.3
CVE-2021-20844 MEDIUM
Yamaha RTX830, NVR510, NVR700W, RTX1210 Firmware - Authenticated Information Disclosure via HTTP Header Injection
CVSS 5.7
CVE-2021-42250 MEDIUM
Apache Superset < 1.3.2 - Authenticated Log Forgery via HTTP Endpoint
CVSS 6.5
CVE-2021-41232 HIGH
Thunderdome <1.16.3 - Command Injection
CVSS 8.1
CVE-2021-41191 HIGH
Roblox-Purchasing-Hub <1.0.2 - Info Disclosure
CVSS 7.5
CVE-2021-41132 CRITICAL
OMERO.web < 5.11.0 - Cross-Site Scripting via Improper HTML Escaping
CVSS 9.8
CVE-2021-21684 MEDIUM
Jenkins Git Plugin < 4.8.2 - Stored Cross-Site Scripting via Git SHA-1 Checksum Parameter
CVSS 6.1
CVE-2021-33672 CRITICAL
SAP Contact Center 700 - Stored Cross-Site Scripting and Remote Code Execution via Chat Message
CVSS 9.6
CVE-2021-39170 HIGH
pimcore < 10.1.2 - Authenticated Stored Cross-Site Scripting via Custom Metadata
CVSS 8.0
CVE-2021-39367 MEDIUM
Canon Oce Print Exec Workgroup 1.3.2 - Open Redirect
CVSS 5.3
CVE-2021-22254 LOW
GitLab <14.1.2-14.0.7-13.12.9 - Privilege Escalation
CVSS 3.1
CVE-2021-38751 MEDIUM
ExponentCMS < 2.6 - HTTP Host Header Injection in exponent_constants.php
CVSS 4.3
Details
Vulnerabilities 482
Exploit Likelihood High