CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
482 vulnerabilities with CWE-116
CVE-2021-32072
MEDIUM
Mitel MiCollab <9.3 - Info Disclosure
CVSS 6.5
CVE-2021-32067
MEDIUM
Mitel MiCollab <9.3 - Info Disclosure
CVSS 6.5
CVE-2021-30589
MEDIUM
Google Chrome <92.0.4515.107 - CSRF
CVSS 4.3
CVE-2021-32812
MEDIUM
monkshu <= 2.90 - Reflected Cross-Site Scripting via Error Response
CVSS 4.6
CVE-2021-34630
MEDIUM
GTranslate < 2.8.65 - Reflected Cross-Site Scripting via REQUEST_URI Output
CVSS 5.0
CVE-2021-32796
MEDIUM
xmldom < 0.7.0 - XML Injection via Improper Character Escaping
CVSS 6.5
CVE-2021-20333
MEDIUM
MongoDB <3.6.20, <4.0.21, <4.2.10 - Info Disclosure
CVSS 5.3
CVE-2021-30640
MEDIUM
Apache Tomcat <10.0.6, <9.0.46, <8.5.66 - Auth Bypass
CVSS 6.5
CVE-2021-32679
LOW
Nextcloud Server <19.0.13, 20.0.11, 21.0.3 - Info Disclosure
CVSS 3.5
CVE-2021-23205
HIGH
Gallagher Command Centre <8.40.1888-8.30.1359-8.20.1259-8.10 - Priv...
CVSS 8.1
CVE-2021-20195
CRITICAL
Keycloak < 13.0.0 - Stored Cross-Site Scripting via User-Supplied Data Fields
CVSS 9.6
CVE-2021-31806
MEDIUM
Squid < 4.15 and 5.x < 5.0.6 - Denial of Service via HTTP Range Request Processing
CVSS 6.5
CVE-2021-28662
MEDIUM
Squid 4.0.1-4.14 and 5.0-5.0.5 - Denial of Service via HTTP Response Header
CVSS 6.5
CVE-2021-28940
CRITICAL
MagpieRSS 0.72 - OS Command Injection via RSS URL Parameter
CVSS 9.8
CVE-2021-20405
HIGH
IBM Security Verify Information Queue <1.0.8 - Info Disclosure
CVSS 7.5
CVE-2020-36567
HIGH
gin-gonic/gin < 1.6.0 - Log Injection via Default Logger
CVSS 7.5
CVE-2020-36599
CRITICAL
OmniAuth <1.9.2, <2.0 - Info Disclosure
CVSS 9.8
CVE-2020-27958
MEDIUM
Ohio Supercomputer Center Open OnDemand <1.7.19, <1.8.18 - Command ...
CVSS 4.3
CVE-2020-4850
HIGH
IBM Spectrum Scale <1.1.8.4 - Info Disclosure
CVSS 7.5
CVE-2020-26283
MEDIUM
go-ipfs < 0.8.0 - Console Output Injection via Unescaped Control Characters
CVSS 6.8
CVE-2020-29023
LOW
Secomea GateManager <9.3 - Code Injection
CVSS 3.5
CVE-2020-36173
MEDIUM
Ninja Forms <3.4.28 - Info Disclosure
CVSS 5.3
CVE-2020-13654
HIGH
XWiki Platform <12.8 - Info Disclosure
CVSS 7.5
CVE-2020-28954
MEDIUM
BigBlueButton <2.2.29 - Info Disclosure
CVSS 5.3
CVE-2020-26226
HIGH
semantic-release <17.2.3 - Info Disclosure
CVSS 8.1
Details
Vulnerabilities
482
Exploit Likelihood
High