CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,818 vulnerabilities with CWE-74
CVE-2023-26261
CRITICAL
UBIKA WAAP Gateway/Cloud <6.10 - Auth Bypass
CVSS 9.8
CVE-2023-27479
CRITICAL
XWiki 6.3-13.10.10 - Authenticated Remote Code Execution via UIX Parameter Injection
CVSS 9.9
CVE-2023-27635
HIGH
debmany - OS Command Injection via Crafted .deb File
CVSS 7.8
CVE-2023-1061
MEDIUM
Doctors Appointment System 1.0 - SQL Injection via Email Parameter in Edit Doctor Endpoint
CVSS 6.3
CVE-2023-1059
MEDIUM
Doctors Appointment System 1.0 - SQL Injection via search/id Parameter
CVSS 6.3
CVE-2023-20858
HIGH
VMware Carbon Black App Control 8.7.0-8.7.7, 8.8.0-8.8.5, 8.9.0-8.9.3 - Authenticated OS Command Injection
CVSS 7.2
CVE-2023-25613
CRITICAL
Apache Kerby LDAP Backend < 2.0.3 - LDAP Injection
CVSS 9.8
CVE-2023-23936
MEDIUM
Undici <5.19.1 - CRLF Injection
CVSS 6.5
CVE-2023-25141
HIGH
Apache Sling JCR Base < 3.1.12 - Remote Code Execution via JDNI and RMI in RepositoryAccessor
CVSS 7.5
CVE-2023-25719
HIGH
ConnectWise Control < 22.9.10032 - Code Injection via Unvalidated h Parameter
CVSS 8.8
CVE-2023-0493
MEDIUM
BTCPay Server < 1.7.5 - HTML Injection
CVSS 5.3
CVE-2023-0476
MEDIUM
Tenable.sc < 5.23.1 - Authenticated LDAP Injection
CVSS 6.5
CVE-2023-24040
HIGH
Common Desktop Environment 1.6 - Info Disclosure
CVSS 7.1
CVE-2023-20057
NONE
Cisco AsyncOS Software - Auth Bypass
CVE-2023-0040
HIGH
Async HTTP Client <1.13.2 - CRLF Injection
CVSS 7.5
CVE-2023-23749
HIGH
LDAP Integration with Active Directory and OpenLDAP - LDAP Injection via Username Parameter
CVSS 7.5
CVE-2023-0302
HIGH
radare2 < 5.8.2 - Command Injection via Unsanitized Special Elements
CVSS 7.8
CVE-2022-31631
CRITICAL
PHP <8.0.27, <8.1.15, <8.2.2 - SQL Injection
CVSS 9.1
CVE-2022-46337
CRITICAL
Apache Derby 10.1.1.0-10.14.3.0 - LDAP Authentication Bypass via Username Injection
CVSS 9.8
CVE-2022-47583
CRITICAL
mintty < 3.6.3 - Remote Code Execution via Terminal Character Injection
CVSS 9.8
CVE-2022-4145
MEDIUM
OpenShift Container Platform - Unauthenticated Content Spoofing in OAuth Endpoint
CVSS 4.3
CVE-2022-3962
MEDIUM
Kiali < 1.57.4 - Content Spoofing via Error Page Text Injection
CVSS 4.3
CVE-2022-24989
CRITICAL
TerraMaster TOS < 4.2.31 - Unauthenticated Remote Code Execution via api.php Raid Creation
CVSS 9.8
CVE-2022-47028
MEDIUM
Action Launcher for Android <50.5 - DoS
CVSS 5.5
CVE-2022-45048
HIGH
Apache Ranger 2.3.0 - Authenticated Remote Code Execution via Policy Expression Injection
CVSS 8.4
Details
Vulnerabilities
4,818
Exploit Likelihood
High