CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

482 vulnerabilities with CWE-116
CVE-2020-25646 HIGH
Ansible Collection community.crypto - Info Disclosure
CVSS 7.5
CVE-2020-27604 MEDIUM
BigBlueButton <2.3 - Info Disclosure
CVSS 6.5
CVE-2020-9862 HIGH
iCloud < 7.20 - Command Injection via Web Inspector URL Copy
CVSS 7.8
CVE-2020-24592 MEDIUM
Mitel MiCloud Management Portal <6.1 SP5 - Info Disclosure
CVSS 5.3
CVE-2020-6313 MEDIUM
SAP NetWeaver Application Server JAVA/XML Forms <7.50 - XSS
CVSS 6.5
CVE-2020-24972 HIGH
Kleopatra <3.1.12 - Code Execution via openpgp4fpr URL Handling
CVSS 8.8
CVE-2020-16281 HIGH
RangeeOS 8.0.4 - Authenticated Arbitrary Code Execution via Kommbox Context Menu
CVSS 7.8
CVE-2020-7694 LOW
uvicorn < 0.11.7 - ANSI Escape Sequence Injection via Request Logger
CVSS 3.7
CVE-2020-6261 MEDIUM
SAP Solution Manager <7.20 - Info Disclosure
CVSS 5.3
CVE-2020-5304 HIGH
WhiteSource AVM <20.4.1 - Log Injection
CVSS 7.5
CVE-2020-13625 HIGH
PHPMailer < 6.1.6 - Improper Output Escaping in File Attachment Name
CVSS 7.5
CVE-2020-6227 HIGH
SAP BusinessObjects <4.2 - Code Injection
CVSS 7.5
CVE-2020-4282 MEDIUM
IBM Security Information Queue <1.0.6 - Auth Bypass
CVSS 4.3
CVE-2020-10235 HIGH
Froxlor < 0.10.14 - Remote Code Execution via Database Configuration Options
CVSS 8.8
CVE-2019-4326 HIGH
HCL AppScan Enterprise - Info Disclosure
CVSS 7.5
CVE-2019-19714 MEDIUM
Contao 4.8.4-4.8.5 - Insert Tag Injection in Login Module
CVSS 5.3
CVE-2019-11325 CRITICAL
Symfony <4.2.12 & <4.3.8 - Code Injection
CVSS 9.8
CVE-2019-12675 HIGH
Cisco Firepower Threat Defense - Privilege Escalation
CVSS 8.8
CVE-2019-12674 HIGH
Cisco Firepower Threat Defense - Privilege Escalation
CVSS 8.2
CVE-2019-9853 HIGH
LibreOffice 6.2.0-6.2.6 - Macro Execution Bypass via URL Decoding Flaw
CVSS 7.8
CVE-2019-10074 CRITICAL
Apache OFBiz 16.11.01-16.11.04 - Remote Code Execution via Freemarker Markup in Form Widget Textarea
CVSS 9.8
CVE-2019-11547 MEDIUM
GitLab < 11.8.9, 11.9.x < 11.9.10, 11.10.x < 11.10.2 - Cross-Site Scripting via Merge Request Notification Email
CVSS 6.1
CVE-2019-12463 HIGH
LibreNMS 1.50.1-1.53 - Authenticated RRDtool Injection via Graph Parameter
CVSS 8.8
CVE-2019-15944 MEDIUM
Counter-Strike: Global Offensive <8/29/2019 - XSS
CVSS 5.3
CVE-2019-1968 HIGH
Cisco NX-OS - Unauthenticated Denial of Service via NX-API HTTP Header
CVSS 7.5
Details
Vulnerabilities 482
Exploit Likelihood High