CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,808 vulnerabilities with CWE-74
CVE-2024-7219 HIGH
School Log Management System 1.0 - SQL Injection via Username Parameter in /admin/ajax.php
CVSS 7.3
CVE-2024-40324 MEDIUM
E-Staff <5.1 - HTTP Response Splitting
CVSS 5.4
CVE-2024-0231 LOW
GitLab 12.0-17.0.4 17.1-17.1.2 17.2 - Resource Misdirection via Repository Import
CVSS 2.7
CVE-2024-40137 MEDIUM
Dolibarr ERP CRM <19.0.2-php8.2 - RCE
CVSS 5.5
CVE-2024-26020 CRITICAL
Anki < 24.06 - Arbitrary Script Execution via MPV Flashcard Rendering
CVSS 9.6
CVE-2024-6933 MEDIUM
LimeSurvey 6.5.14-6.6.2 - SQL Injection via Survey General Settings Language Parameter
CVSS 6.3
CVE-2024-41122 HIGH
Woodpecker < 2.7.0 - Unauthenticated Pipeline Workflow Injection
CVSS 7.5
CVE-2024-41121 HIGH
Woodpecker < 2.7.0 - Unauthenticated Pipeline Workflow Injection
CVSS 8.8
CVE-2024-39906 HIGH
Haven < c52f07c - Authenticated Remote Code Execution via IndieAuth Link Injection
CVSS 8.3
CVE-2024-41111 HIGH
BishopFox Sliver 1.6.0-dev - Authenticated Remote Code Execution via Teamserver Operator Privilege Escalation
CVSS 7.2
CVE-2024-20429 MEDIUM
Cisco AsyncOS for Secure Email Gateway - Authenticated Remote Code Execution via Web Interface
CVSS 6.5
CVE-2024-40637 MEDIUM
dbt_core < 1.6.14 - Code Injection via Malicious Package Override
CVSS 4.2
CVE-2024-38700 MEDIUM
realmag777 WPCS <1.2.0.3 - Code Injection
CVSS 6.5
CVE-2024-36522 CRITICAL
Apache Wicket XSLTResourceStream - XSLT Injection Remote Code Execution
CVSS 9.8
CVE-2024-37442 LOW
Photo Gallery by Ays < 5.7.1 - Code Injection
CVSS 3.8
CVE-2024-37253 LOW
WP Directory Kit <= 1.3.6 - Code Injection
CVSS 2.7
CVE-2024-35777 LOW
WooCommerce <8.9.2 - Code Injection
CVSS 3.5
CVE-2024-6470 LOW
playSMS 1.4.3 - Server-Side Template Injection via Receiver Number Parameter
CVSS 2.7
CVE-2024-6469 LOW
playSMS 1.4.3 - Injection via IP Address Argument in Template Handler
CVSS 2.7
CVE-2024-38366 CRITICAL
trunk.cocoapods.org - Command Injection
CVSS 10.0
CVE-2024-36420 HIGH
Flowise 1.4.3 - Arbitrary File Read via OpenAI Assistants File Endpoint
CVSS 7.5
CVE-2024-39704 CRITICAL
Melty Blood: Actress Again: Current Code <= 1.07 - Remote Code Execution via Crafted TCP Packet
CVSS 9.8
CVE-2024-39243 CRITICAL
skycaiji 2.8 - Remote Code Execution via /index.php?s=/admin/develop/editor_save
CVSS 9.8
CVE-2024-37759 CRITICAL
DataGear < 5.0.0 - SpEL Expression Injection via Data Viewing Interface
CVSS 9.8
CVE-2024-35728 MEDIUM
Themeisle PPOM for WooCommerce < 32.0.20 - Code Inclusion
CVSS 5.3
Details
Vulnerabilities 4,808
Exploit Likelihood High