CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

482 vulnerabilities with CWE-116
CVE-2024-50349 MEDIUM
Git < 2.40.4 - Terminal Credential Prompt Spoofing via ANSI Escape Sequences
CVSS 4.7
CVE-2024-52891 MEDIUM
IBM Concert Software <1.0.4 - Info Disclosure
CVSS 5.4
CVE-2024-9427 MEDIUM
Koji 1.35.0 - Reflected Cross-Site Scripting via Unsanitized Input
CVSS 5.4
CVE-2024-55663 CRITICAL
XWiki Platform <13.10.5-14.3-rc-1 - SQL Injection
CVSS 9.8
CVE-2024-46547 HIGH
Romain Bourdon Wampserver - Info Disclosure
CVSS 7.5
CVE-2024-46901 LOW
Apache Subversion <1.14.4 - Info Disclosure
CVSS 3.1
CVE-2024-42332 LOW
Zabbix 6.0.0-6.0.35 - SNMP Trap Log Forgery via Malformed Trap Data
CVSS 3.7
CVE-2024-10006 HIGH
Consul 1.4.1-1.20.0 and 1.9.0-1.15.14 - HTTP Header Bypass via L7 Traffic Intentions
CVSS 8.3
CVE-2024-47549 HIGH
Sharp/Toshiba Tec MFPs - XSS
CVSS 7.4
CVE-2024-47224 MEDIUM
Mitel MiCollab <9.8.1.201 - CRLF Injection
CVSS 6.5
CVE-2024-40088 MEDIUM
Vilo 5 Mesh WiFi System <= 5.16.1.33 - Path Traversal
CVSS 5.3
CVE-2024-9348 HIGH
Docker Desktop < 4.34.3 - Remote Code Execution via GitHub Source Link in Build View
CVE-2024-45219 HIGH
Apache CloudStack <4.18.2.3-4.19.1.1 - Info Disclosure
CVSS 8.5
CVE-2024-47845 HIGH
The Wikimedia Foundation Mediawiki - CSS Extension <1.39.9-1.41.3-1...
CVSS 8.2
CVE-2024-47528 MEDIUM
LibreNMS < 24.9.0 - Stored Cross-Site Scripting via Custom Map Background SVG Upload
CVSS 4.8
CVE-2024-47531 MEDIUM
Scout < 4.89 - Unauthenticated Arbitrary File Download via Filename Sanitization Bypass
CVSS 4.6
CVE-2024-4099 LOW
GitLab EE <17.2.8-17.3.4-17.4.1 - Info Disclosure
CVSS 3.1
CVE-2024-45808 MEDIUM
Envoy <1.31.2-1.28.7 - Code Injection
CVSS 6.5
CVE-2024-7873 CRITICAL
Veribilim Software Veribase Order <4.010.3 - XSS
CVE-2024-45498 HIGH
Apache Airflow <2.10.0 - Command Injection
CVSS 8.8
CVE-2024-45299 MEDIUM
alf < 2.0-m5 - Cross-Site Scripting via Preloaded Data JSON
CVSS 6.5
CVE-2024-8297 MEDIUM
Kitsada8621 Digital Library Management System <1.0 - Info Disclosure
CVSS 5.3
CVE-2024-34739 HIGH
Android - Local Privilege Escalation via UsbProfileGroupSettingsManager Logic Error
CVSS 7.8
CVE-2024-38177 HIGH
Windows App Installer - Path Traversal
CVSS 7.8
CVE-2024-6329 MEDIUM
GitLab CE/EE <17.0.6-17.2.2 - Info Disclosure
CVSS 5.7
Details
Vulnerabilities 482
Exploit Likelihood High