CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
446 vulnerabilities with CWE-116
CVE-2024-4420
HIGH
Tink-cc < 2.1.3 - Denial of Service via Malformed JSON Input
CVSS 7.5
CVE-2024-34355
LOW
TYPO3 13.0.0-13.1.0 - Authenticated HTML Injection in History Backend Module
CVSS 3.5
CVE-2024-29894
MEDIUM
Cacti < 1.2.27 - Stored Cross-Site Scripting via Unescaped PHP Variables
CVSS 5.4
CVE-2024-34510
HIGH
Gradio < 4.20.0 - Credential Leakage on Windows
CVSS 7.5
CVE-2024-1874
CRITICAL
PHP <8.1.28, 8.2.*<8.2.18, 8.3.*<8.3.5 - Command Injection
CVSS 9.4
CVE-2024-31866
CRITICAL
Apache Zeppelin 0.8.2-0.11.0 - Remote Code Execution via Configuration Override
CVSS 9.8
CVE-2024-22356
MEDIUM
IBM App Connect Enterprise <12.0.9.0 - Info Disclosure
CVSS 4.9
CVE-2024-28245
MEDIUM
KaTeX 0.11.0-0.16.9 - Cross-Site Scripting via \\includegraphics
CVSS 6.3
CVE-2024-29156
MEDIUM
OpenStack Murano <16.0.0 - Info Disclosure
CVSS 6.5
CVE-2024-27938
MEDIUM
Postal < 3.0.0 - SMTP Smuggling via Non-Compliant End of DATA Sequence
CVSS 5.3
CVE-2024-21499
MEDIUM
github.com/greenpau/caddy-security - HTTP Header Injection
CVSS 4.3
CVE-2024-0690
MEDIUM
ansible-core < 2.14.14 - Information Disclosure via ANSIBLE_NO_LOG Bypass
CVSS 5.0
CVE-2024-1064
HIGH
Crafty Controller 4.0.0-4.2.2 - Unauthenticated Denial of Service via Host Header Injection
CVSS 7.5
CVE-2024-0987
MEDIUM
Sichuan Yougou Technology KuERP <1.0.4 - Info Disclosure
CVSS 6.3
CVE-2024-22229
LOW
Dell Unity Operating Environment - Authenticated Log Spoofing via Improper Output Encoding
CVSS 3.1
CVE-2024-0233
MEDIUM
EventON WordPress plugin < 2.2.7 - Reflected Cross-Site Scripting
CVSS 6.1
CVE-2024-22199
CRITICAL
gofiber/template < 3.1.9 - Cross-Site Scripting via Autoescape Bypass
CVSS 9.3
CVE-2023-35894
MEDIUM
IBM Sterling Control Center 6.2.1-6.3.1 - HTTP Header Injection via HOST Header
CVSS 5.4
CVE-2023-28362
MEDIUM
Rails - Open Redirect
CVSS 4.0
CVE-2023-45359
MEDIUM
MediaWiki Vector Skin < 1.39.5 and 1.40.0 - Cross-Site Scripting in Table of Contents Toggle Button
CVSS 6.5
CVE-2023-26289
MEDIUM
IBM Aspera Orchestrator 4.0.1 - HTTP Header Injection
CVSS 5.4
CVE-2023-28952
MEDIUM
IBM Cognos Controller <11.0.0 - Command Injection
CVSS 5.3
CVE-2023-47143
CRITICAL
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0-7.3.0.10 - HTTP Header Injection via HOST Header
CVSS 10.0
CVE-2023-28738
HIGH
Intel NUC BIOS <JY0070 - Privilege Escalation
CVSS 7.5
CVE-2023-7234
MEDIUM
OPCUAServerToolkit - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
446
Exploit Likelihood
High