CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,808 vulnerabilities with CWE-74
CVE-2023-51446
MEDIUM
GLPI 0.70-10.0.11 - LDAP Injection via Authentication Form
CVSS 5.9
CVE-2023-51939
HIGH
Relic relic-toolkit <0.6.0 - Info Disclosure/Privilege Escalation
CVSS 8.8
CVE-2023-36260
HIGH
Feed Me plugin 4.6.1 for Craft CMS - Denial of Service via Crafted Feed-Me Name and URL Fields
CVSS 7.5
CVE-2023-22527
CRITICAL
KEV
Atlassian Confluence SSTI Injection
CVSS 9.8
CVE-2023-4818
HIGH
PAX PayDroid - Bootloader Downgrade via Version Check Bypass
CVSS 7.6
CVE-2023-42136
HIGH
PAX PayDroid < 8.1.0_sagittarius_11.1.50_20230614 - Authenticated OS Command Injection via Shell
CVSS 7.8
CVE-2023-42135
MEDIUM
PAX PayDroid < 8.1.0_sagittarius_11.1.50_20230614 - Local Code Execution via Partition Flashing Parameter Injection
CVSS 6.8
CVE-2023-31025
MEDIUM
NVIDIA DGX A100 BMC - Info Disclosure
CVSS 6.5
CVE-2023-29050
HIGH
LDAP contacts provider - Info Disclosure
CVSS 7.6
CVE-2023-6004
MEDIUM
libssh >=0.8.0 <0.9.8 - OS Command Injection via ProxyCommand or ProxyJump Hostname Parameter
CVSS 4.8
CVE-2023-50093
MEDIUM
APIIDA API Gateway Manager 2023.2.2 - Host Header Injection
CVSS 6.1
CVE-2023-39655
CRITICAL
@perfood/couch-auth <= 0.20.0 - Host Header Injection via Forgot Password Request
CVSS 9.6
CVE-2023-7114
HIGH
Mattermost < 2.10.1 - Cross-Site Request Forgery via Deeplink Path
CVSS 7.1
CVE-2023-52081
MEDIUM
ewen-lbh/firefox_css < 0.2.0 - Input Validation Bypass via Unicode Normalization
CVSS 5.3
CVE-2023-51664
HIGH
tj-actions/changed-files <41.0.0 - Command Injection
CVSS 7.3
CVE-2023-49328
HIGH
Wolters Kluwer B.POINT <23.70.00 - Command Injection
CVSS 7.2
CVE-2023-7100
MEDIUM
PHPGurukul Restaurant Table Booking System 1.0 - SQL Injection via fdate/tdate Parameters
CVSS 6.3
CVE-2023-7096
MEDIUM
Faculty Management System 1.0 - SQL Injection via crud.php fieldname/tablename Parameter
CVSS 4.7
CVE-2023-7039
MEDIUM
Byzoro S210 Firmware < 2023-12-10 - SQL Injection via /importexport.php sql Parameter
CVSS 6.3
CVE-2023-35895
MEDIUM
IBM Informix JDBC Driver <4.10,4.50 - RCE
CVSS 6.3
CVE-2023-46726
HIGH
GLPI 10.0.0-10.0.10 - Remote Code Execution via LDAP Server Configuration Form
CVSS 7.2
CVE-2023-43364
CRITICAL
searchor < 2.4.2 - Remote Code Execution via CLI Input
CVSS 9.8
CVE-2023-46456
CRITICAL
GL.iNET GL-AR300M <3.216 - Command Injection
CVSS 9.8
CVE-2023-49964
HIGH
Hyland Alfresco Content Services < 7.2.0 - Server-Side Template Injection via folder.get.html.ftl
CVSS 8.8
CVE-2023-6648
HIGH
PHPGurukul Nipah Virus Testing Management System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities
4,808
Exploit Likelihood
High