CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,818 vulnerabilities with CWE-74
CVE-2023-26261 CRITICAL
UBIKA WAAP Gateway/Cloud <6.10 - Auth Bypass
CVSS 9.8
CVE-2023-27479 CRITICAL
XWiki 6.3-13.10.10 - Authenticated Remote Code Execution via UIX Parameter Injection
CVSS 9.9
CVE-2023-27635 HIGH
debmany - OS Command Injection via Crafted .deb File
CVSS 7.8
CVE-2023-1061 MEDIUM
Doctors Appointment System 1.0 - SQL Injection via Email Parameter in Edit Doctor Endpoint
CVSS 6.3
CVE-2023-1059 MEDIUM
Doctors Appointment System 1.0 - SQL Injection via search/id Parameter
CVSS 6.3
CVE-2023-20858 HIGH
VMware Carbon Black App Control 8.7.0-8.7.7, 8.8.0-8.8.5, 8.9.0-8.9.3 - Authenticated OS Command Injection
CVSS 7.2
CVE-2023-25613 CRITICAL
Apache Kerby LDAP Backend < 2.0.3 - LDAP Injection
CVSS 9.8
CVE-2023-23936 MEDIUM
Undici <5.19.1 - CRLF Injection
CVSS 6.5
CVE-2023-25141 HIGH
Apache Sling JCR Base < 3.1.12 - Remote Code Execution via JDNI and RMI in RepositoryAccessor
CVSS 7.5
CVE-2023-25719 HIGH
ConnectWise Control < 22.9.10032 - Code Injection via Unvalidated h Parameter
CVSS 8.8
CVE-2023-0493 MEDIUM
BTCPay Server < 1.7.5 - HTML Injection
CVSS 5.3
CVE-2023-0476 MEDIUM
Tenable.sc < 5.23.1 - Authenticated LDAP Injection
CVSS 6.5
CVE-2023-24040 HIGH
Common Desktop Environment 1.6 - Info Disclosure
CVSS 7.1
CVE-2023-20057 NONE
Cisco AsyncOS Software - Auth Bypass
CVE-2023-0040 HIGH
Async HTTP Client <1.13.2 - CRLF Injection
CVSS 7.5
CVE-2023-23749 HIGH
LDAP Integration with Active Directory and OpenLDAP - LDAP Injection via Username Parameter
CVSS 7.5
CVE-2023-0302 HIGH
radare2 < 5.8.2 - Command Injection via Unsanitized Special Elements
CVSS 7.8
CVE-2022-31631 CRITICAL
PHP <8.0.27, <8.1.15, <8.2.2 - SQL Injection
CVSS 9.1
CVE-2022-46337 CRITICAL
Apache Derby 10.1.1.0-10.14.3.0 - LDAP Authentication Bypass via Username Injection
CVSS 9.8
CVE-2022-47583 CRITICAL
mintty < 3.6.3 - Remote Code Execution via Terminal Character Injection
CVSS 9.8
CVE-2022-4145 MEDIUM
OpenShift Container Platform - Unauthenticated Content Spoofing in OAuth Endpoint
CVSS 4.3
CVE-2022-3962 MEDIUM
Kiali < 1.57.4 - Content Spoofing via Error Page Text Injection
CVSS 4.3
CVE-2022-24989 CRITICAL
TerraMaster TOS < 4.2.31 - Unauthenticated Remote Code Execution via api.php Raid Creation
CVSS 9.8
CVE-2022-47028 MEDIUM
Action Launcher for Android <50.5 - DoS
CVSS 5.5
CVE-2022-45048 HIGH
Apache Ranger 2.3.0 - Authenticated Remote Code Execution via Policy Expression Injection
CVSS 8.4
Details
Vulnerabilities 4,818
Exploit Likelihood High