CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
446 vulnerabilities with CWE-116
CVE-2020-6227
HIGH
SAP BusinessObjects <4.2 - Code Injection
CVSS 7.5
CVE-2020-4282
MEDIUM
IBM Security Information Queue <1.0.6 - Auth Bypass
CVSS 4.3
CVE-2020-10235
HIGH
Froxlor < 0.10.14 - Remote Code Execution via Database Configuration Options
CVSS 8.8
CVE-2019-4326
HIGH
HCL AppScan Enterprise - Info Disclosure
CVSS 7.5
CVE-2019-19714
MEDIUM
Contao 4.8.4-4.8.5 - Insert Tag Injection in Login Module
CVSS 5.3
CVE-2019-11325
CRITICAL
Symfony <4.2.12 & <4.3.8 - Code Injection
CVSS 9.8
CVE-2019-12675
HIGH
Cisco Firepower Threat Defense - Privilege Escalation
CVSS 8.8
CVE-2019-12674
HIGH
Cisco Firepower Threat Defense - Privilege Escalation
CVSS 8.2
CVE-2019-9853
HIGH
LibreOffice 6.2.0-6.2.6 - Macro Execution Bypass via URL Decoding Flaw
CVSS 7.8
CVE-2019-10074
CRITICAL
Apache OFBiz 16.11.01-16.11.04 - Remote Code Execution via Freemarker Markup in Form Widget Textarea
CVSS 9.8
CVE-2019-11547
MEDIUM
GitLab < 11.8.9, 11.9.x < 11.9.10, 11.10.x < 11.10.2 - Cross-Site Scripting via Merge Request Notification Email
CVSS 6.1
CVE-2019-12463
HIGH
LibreNMS 1.50.1-1.53 - Authenticated RRDtool Injection via Graph Parameter
CVSS 8.8
CVE-2019-15944
MEDIUM
Counter-Strike: Global Offensive <8/29/2019 - XSS
CVSS 5.3
CVE-2019-1968
HIGH
Cisco NX-OS - Unauthenticated Denial of Service via NX-API HTTP Header
CVSS 7.5
CVE-2019-9852
HIGH
LibreOffice - Code Injection
CVSS 7.8
CVE-2019-10362
MEDIUM
Jenkins Configuration as Code Plugin <1.24 - Info Disclosure
CVSS 5.4
CVE-2019-11717
MEDIUM
Firefox ESR <60.8-Firefox <68-Thunderbird <60.8 - SSRF
CVSS 5.3
CVE-2019-3571
MEDIUM
WhatsApp Desktop <0.3.3793 - Info Disclosure
CVSS 5.3
CVE-2019-11268
MEDIUM
Cloud Foundry UAA < 73.3.0 - Authenticated Information Disclosure via Improper Escaping
CVSS 4.3
CVE-2019-0971
MEDIUM
Azure DevOps Server - Info Disclosure
CVSS 6.5
CVE-2019-0956
MEDIUM
Microsoft SharePoint Server - Info Disclosure
CVSS 6.5
CVE-2019-10249
HIGH
Xtext & Xtend <2.18.0 - Info Disclosure
CVSS 8.1
CVE-2019-0857
MEDIUM
Azure DevOps Server - Info Disclosure
CVSS 6.5
CVE-2019-6109
MEDIUM
OpenSSH < 7.9 - Terminal Output Manipulation via ANSI Control Codes in Progress Display
CVSS 6.8
CVE-2018-9433
HIGH
Android - Remote Code Execution via ArrayConcatVisitor Type Confusion
CVSS 8.8
Details
Vulnerabilities
446
Exploit Likelihood
High