CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

414 vulnerabilities with CWE-116
CVE-2023-48655 CRITICAL
MISP <2.4.176 - Info Disclosure
CVSS 9.8
CVE-2023-40453 MEDIUM
Docker Machine < 0.16.2 - Denial of Service
CVSS 6.5
CVE-2023-5968 MEDIUM
Mattermost < 7.8.11 - Information Disclosure
CVSS 4.9
CVE-2023-4393 MEDIUM
LiquidFiles <3.7.13 - Command Injection
CVSS 5.4
CVE-2023-45135 CRITICAL
Xwiki < 14.10.12 - Remote Code Execution
CVSS 9.0
CVE-2023-46301 CRITICAL
iTerm2 <3.4.20 - RCE
CVSS 9.8
CVE-2023-46300 CRITICAL
iTerm2 <3.4.20 - Code Injection
CVSS 9.8
CVE-2023-5654 MEDIUM
React Developer Tools - SSRF
CVSS 6.5
CVE-2023-43620 HIGH
Croc <9.6.5 - Info Disclosure
CVSS 7.8
CVE-2023-41889 MEDIUM
SHIRASAGI <1.18.0 - Info Disclosure
CVSS 5.3
CVE-2023-37875 LOW
Wftpserver Wing FTP Server < 7.2.0 - XSS
CVSS 3.0
CVE-2023-4571 HIGH
Splunk IT Service Intelligence <4.13.3, 4.15.3, 4.17.1 - Code Injec...
CVSS 8.6
CVE-2023-3481 MEDIUM
Google Critters < 0.0.19 - Basic XSS
CVSS 5.7
CVE-2023-39390 HIGH
Window Management Module - Info Disclosure
CVSS 7.5
CVE-2023-39386 HIGH
PMS - Info Disclosure
CVSS 7.5
CVE-2023-39382 HIGH
Audio Module - DoS
CVSS 7.5
CVE-2023-39381 HIGH
Huawei EMUI and HarmonyOS - Input Verification Vulnerability in Storage Module
CVSS 7.5
CVE-2023-40014 MEDIUM
OpenZeppelin Contracts <4.9.3 - Info Disclosure
CVSS 5.3
CVE-2023-39527 HIGH
Prestashop < 1.7.8.10 - XSS
CVSS 8.3
CVE-2023-3997 HIGH
Splunk SOAR <6.1.0 - Code Injection
CVSS 8.6
CVE-2023-35941 HIGH
Envoy <1.27.0-1.23.12 - Auth Bypass
CVSS 8.6
CVE-2023-34036 MEDIUM
Reactive web apps using Spring HATEOAS - SSRF
CVSS 5.3
CVE-2023-3668 HIGH
GitHub froxlor/froxlor <2.0.21 - XSS
CVSS 7.2
CVE-2023-24480 CRITICAL
Honeywell - DoS
CVSS 9.8
CVE-2023-2200 MEDIUM
GitLab CE/EE <15.11.10, <16.0.6, <16.1.1 - XSS
CVSS 4.1
Details
Vulnerabilities 414
Exploit Likelihood High