CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
482 vulnerabilities with CWE-116
CVE-2025-61912
MEDIUM
python-ldap < 3.4.5 - Denial of Service via Incorrect Null Byte Escaping in ldap.dn.escape_dn_chars()
CVSS 5.3
CVE-2025-55903
HIGH
Perfex CRM 3.3.1 - HTML Injection in Estimate Module Bill To Address Field
CVSS 8.3
CVE-2025-61773
HIGH
pyload-ng < 0.5.0b3.dev91 - Cross-Site Scripting via Captcha Script Endpoint and Click'N'Load Blueprint
CVSS 8.1
CVE-2025-0607
MEDIUM
Logo Cloud < 2.57 - Phishing via Improper Output Encoding
CVSS 4.3
CVE-2025-60787
HIGH
MotionEye <= 0.43.1b4 - Authenticated Configuration Command Injection
CVSS 7.2
CVE-2025-59936
CRITICAL
get-jwks < 11.0.2 - JWKS Cache Poisoning via Issuer Validation Bypass
CVSS 9.4
CVE-2025-57880
MEDIUM
BlueSpice 5.0-5.1.1 - Cross-Site Scripting in BlueSpiceWhoIsOnline Extension
CVSS 5.4
CVE-2025-48007
MEDIUM
BlueSpice 5.0-5.1.1 - Cross-Site Scripting in BlueSpiceAvatars Extension
CVSS 6.4
CVE-2025-46703
MEDIUM
BlueSpice 5.0-5.1.1 - Cross-Site Scripting in AtMentions Extension
CVSS 6.4
CVE-2025-8276
MEDIUM
Patika Global Technologies HumanSuite <53.21.0 - XSS
CVSS 4.3
CVE-2025-55730
CRITICAL
xwiki-pro-macros 1.0-1.26.4 - Remote Code Execution via Confluence Paste Code Macro Title
CVSS 10.0
CVE-2025-55729
CRITICAL
xwiki-pro-macros 1.0-1.26.4 - Remote Code Execution via ConfluenceLayoutSection Macro
CVSS 10.0
CVE-2025-56266
CRITICAL
Avigilon Access Control Manager 7.10.0.20 - Remote Code Execution via Host Header Injection
CVSS 9.8
CVE-2025-0083
MEDIUM
Multiple Locations - Info Disclosure
CVSS 4.0
CVE-2025-34141
MEDIUM
ETQ Reliance CG (legacy) < SE.2025.1 - Reflected Cross-Site Scripting in SQLConverterServlet
CVE-2025-6429
MEDIUM
Firefox < 140.0 and 128.12-128.* - URL Parsing Bypass via Embed Tag
CVSS 6.5
CVE-2025-49013
CRITICAL
WilderForge - Remote Code Execution via GitHub Actions Workflow Injection
CVSS 9.9
CVE-2025-48062
HIGH
Discourse <3.4.4, <3.5.0.beta5, <3.5.0.beta6-dev - XSS
CVSS 7.1
CVE-2025-25029
MEDIUM
IBM Security Guardium 12.0 - Info Disclosure
CVSS 4.9
CVE-2025-5271
MEDIUM
Firefox < 139.0 - Content Injection via Devtools Response Preview
CVSS 6.5
CVE-2025-3942
MEDIUM
Tridium Niagara <4.14.2-4.15.1-4.10.11 - Input Data Manipulation
CVSS 4.3
CVE-2025-1308
HIGH
Pure Storage PX Backup 1.0.0-2.5.9, 2.7.0-2.7.2, 2.8.0 - Information Exposure via Logging
CVE-2025-47280
MEDIUM
Umbraco Forms <13.4.2-15.1.2 - Info Disclosure
CVSS 6.1
CVE-2025-46340
HIGH
Misskey 12.0.0-2025.4.1 - CSS Injection via UrlPreviewService and MkUrlPreview
CVSS 7.2
CVE-2025-32974
CRITICAL
XWiki 15.9-15.10.7 and 16.0.0-16.1.0 - Privilege Escalation via TextArea Default Content Type
CVSS 9.0
Details
Vulnerabilities
482
Exploit Likelihood
High