CWE-707

Improper Neutralization

The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.

240 vulnerabilities with CWE-707
CVE-2026-7045 MEDIUM
baomidou dynamic-datasource StandardEvaluationContext/SpelExpressionParser DsSpelExpressionProcessor.java DsSpelExpressionProcessor#doDetermineDatasource injection
CVSS 6.3
CVE-2026-6994 MEDIUM
Envoy Query Parameter header_mutation.cc params.add injection
CVSS 6.3
CVE-2026-6599 MEDIUM
langflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp_config injection
CVSS 6.3
CVE-2026-5561 MEDIUM
Campcodes Complete POS Management and Inventory System Environment Variable SettingsController.php injection
CVSS 6.3
CVE-2026-5002 HIGH
PromtEngineer localGPT LLM Prompt server.py _route_using_overviews injection
CVSS 7.3
CVE-2026-4516 MEDIUM
Foundation Agents MetaGPT DataInterpreter write_analysis_code.py injection
CVSS 6.3
CVE-2026-4511 MEDIUM
vanna-ai vanna legacy exec injection
CVSS 6.3
CVE-2026-4500 MEDIUM
bagofwords1 bagofwords code_execution.py generate_df injection
CVSS 6.3
CVE-2026-3992 MEDIUM
CodeGenieApp serverless-express <4.17.1 - Code Injection
CVSS 6.3
CVE-2026-3813 MEDIUM
opencc JFlow - Code Injection
CVSS 6.3
CVE-2026-2954 MEDIUM
Dromara UJCMS 10.0.2 - Code Injection
CVSS 6.3
CVE-2025-14674 MEDIUM
aizuda snail-job <1.6.0 - Code Injection
CVSS 6.3
CVE-2025-66545 LOW
Nextcloud <14.0.11, <15.3.12, <16.0.15, <17.0.14, <18.1.8, <19.1.8,...
CVSS 3.5
CVE-2025-13268 MEDIUM
Dromara dataCompare <1.0.1 - SQL Injection
CVSS 6.3
CVE-2025-27712 MEDIUM
Intel(R) Neural Compressor <v3.4 - Privilege Escalation
CVSS 5.7
CVE-2025-11445 MEDIUM
Kilo Code <4.86.0 - Code Injection
CVSS 6.3
CVE-2025-9797 LOW
mrvautin expressCart <b31302f4e99c3293bd742c6d076a721e168118b0 - Co...
CVSS 2.4
CVE-2025-24921 MEDIUM
Intel(R) Tiber(TM) Edge Platform <24.11.1 - Info Disclosure
CVSS 6.6
CVE-2025-3805 MEDIUM
sarrionandia tournatrack - Code Injection
CVSS 5.3
CVE-2025-3804 MEDIUM
thautwarm vscode-diana 0.0.1 - Code Injection
CVSS 5.3
CVE-2025-26633 HIGH KEV
Microsoft Management Console - Auth Bypass
CVSS 7.0
CVE-2025-1611 MEDIUM
ShopXO <6.4.0 - Code Injection
CVSS 4.7
CVE-2025-0697 MEDIUM
Telstra Smart Modem Gen 2 <20250115 - Code Injection
CVSS 5.3
CVE-2024-10915 HIGH
Dlink Dns-320 Firmware - Command Injection
CVSS 8.1
CVE-2024-10914 HIGH
Dlink Dns-320 Firmware - Command Injection
CVSS 8.1
Details
Vulnerabilities 240