CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,818 vulnerabilities with CWE-74
CVE-2022-45801
MEDIUM
Apache StreamPark 1.0.0-2.0.0 - LDAP Injection
CVSS 5.4
CVE-2022-23721
LOW
PingID Integration for Windows Login < 2.9 - Username Collision Vulnerability
CVSS 3.8
CVE-2022-43769
HIGH
KEV
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
CVSS 8.8
CVE-2022-42797
HIGH
Xcode < 14.1 - Privilege Escalation via Injection
CVSS 7.8
CVE-2022-36775
MEDIUM
IBM Security Verify Access 10.0.0.0-10.0.4.0 - HTTP Header Injection via HOST Header
CVSS 6.5
CVE-2022-42472
MEDIUM
FortiOS/FortiProxy HTTP Request Splitting (Auth Required)
CVSS 4.2
CVE-2022-43756
MEDIUM
SUSE Rancher <0.7.3, <0.8.4, <1.0.0 - DoS
CVSS 5.9
CVE-2022-47052
MEDIUM
Nighthawk R6220 AC1200 - CRLF Injection
CVSS 6.1
CVE-2022-3918
HIGH
swift_foundation < 5.7.3 - CRLF Injection in URLRequest Headers
CVSS 8.8
CVE-2022-43720
MEDIUM
Apache Superset < 1.5.2 and 2.0.0 - Authenticated Cross-Site Scripting via Toast Message
CVSS 5.4
CVE-2022-42268
HIGH
Omniverse Kit Create, Audio2Face, Isaac Sim, View, Code, Machinima - Remote Code Execution via USD File Python Code
CVSS 7.8
CVE-2022-37933
HIGH
HPE Superdome Flex and Superdome Flex 280 Firmware - Local Unauthorized Data Injection
CVSS 7.3
CVE-2022-46180
MEDIUM
Discourse Mermaid <1.0.0 - Code Injection
CVSS 5.0
CVE-2022-42471
MEDIUM
FortiWeb 6.3.6-6.3.20, 6.4.0-6.4.2, 7.0.0-7.0.2 - Authenticated HTTP Response Splitting
CVSS 5.4
CVE-2022-4864
MEDIUM
froxlor/froxlor <2.0.0-beta1 - Command Injection
CVSS 5.4
CVE-2022-4768
MEDIUM
Dropbox merou < 2022-03-28 - Injection in SSH Public Key Handler
CVSS 6.3
CVE-2022-46873
HIGH
Firefox < 108.0 - Cross-Site Scripting via CSP unsafe-hashes Directive Bypass
CVSS 8.8
CVE-2022-40958
MEDIUM
Firefox ESR < 102.3, Thunderbird < 102.3, Firefox < 105 - SSRF
CVSS 6.5
CVE-2022-40145
CRITICAL
Apache Karaf < 4.3.8 - Remote Code Execution via JNDI LDAP Data Source URI
CVSS 9.8
CVE-2022-42544
HIGH
Android - Local Privilege Escalation via Network Add Request Input Validation
CVSS 7.8
CVE-2022-46265
MEDIUM
Polarion ALM <V2304.0 - Host Header Injection
CVSS 5.4
CVE-2022-4170
CRITICAL
rxvt-unicode - Remote Code Execution in Perl Background Extension
CVSS 9.8
CVE-2022-4364
HIGH
Teledyne FLIR AX8 <1.46.16 - Command Injection
CVSS 7.3
CVE-2022-45910
MEDIUM
Apache ManifoldCF < 2.23 - LDAP Injection in ActiveDirectory and Sharepoint Authority Connectors
CVSS 5.3
CVE-2022-3643
MEDIUM
Linux Kernel 3.19-4.9.335 - Denial of Service via Malicious Network Packet Headers
CVSS 6.5
Details
Vulnerabilities
4,818
Exploit Likelihood
High