CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,818 vulnerabilities with CWE-74
CVE-2022-45801 MEDIUM
Apache StreamPark 1.0.0-2.0.0 - LDAP Injection
CVSS 5.4
CVE-2022-23721 LOW
PingID Integration for Windows Login < 2.9 - Username Collision Vulnerability
CVSS 3.8
CVE-2022-43769 HIGH KEV
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
CVSS 8.8
CVE-2022-42797 HIGH
Xcode < 14.1 - Privilege Escalation via Injection
CVSS 7.8
CVE-2022-36775 MEDIUM
IBM Security Verify Access 10.0.0.0-10.0.4.0 - HTTP Header Injection via HOST Header
CVSS 6.5
CVE-2022-42472 MEDIUM
FortiOS/FortiProxy HTTP Request Splitting (Auth Required)
CVSS 4.2
CVE-2022-43756 MEDIUM
SUSE Rancher <0.7.3, <0.8.4, <1.0.0 - DoS
CVSS 5.9
CVE-2022-47052 MEDIUM
Nighthawk R6220 AC1200 - CRLF Injection
CVSS 6.1
CVE-2022-3918 HIGH
swift_foundation < 5.7.3 - CRLF Injection in URLRequest Headers
CVSS 8.8
CVE-2022-43720 MEDIUM
Apache Superset < 1.5.2 and 2.0.0 - Authenticated Cross-Site Scripting via Toast Message
CVSS 5.4
CVE-2022-42268 HIGH
Omniverse Kit Create, Audio2Face, Isaac Sim, View, Code, Machinima - Remote Code Execution via USD File Python Code
CVSS 7.8
CVE-2022-37933 HIGH
HPE Superdome Flex and Superdome Flex 280 Firmware - Local Unauthorized Data Injection
CVSS 7.3
CVE-2022-46180 MEDIUM
Discourse Mermaid <1.0.0 - Code Injection
CVSS 5.0
CVE-2022-42471 MEDIUM
FortiWeb 6.3.6-6.3.20, 6.4.0-6.4.2, 7.0.0-7.0.2 - Authenticated HTTP Response Splitting
CVSS 5.4
CVE-2022-4864 MEDIUM
froxlor/froxlor <2.0.0-beta1 - Command Injection
CVSS 5.4
CVE-2022-4768 MEDIUM
Dropbox merou < 2022-03-28 - Injection in SSH Public Key Handler
CVSS 6.3
CVE-2022-46873 HIGH
Firefox < 108.0 - Cross-Site Scripting via CSP unsafe-hashes Directive Bypass
CVSS 8.8
CVE-2022-40958 MEDIUM
Firefox ESR < 102.3, Thunderbird < 102.3, Firefox < 105 - SSRF
CVSS 6.5
CVE-2022-40145 CRITICAL
Apache Karaf < 4.3.8 - Remote Code Execution via JNDI LDAP Data Source URI
CVSS 9.8
CVE-2022-42544 HIGH
Android - Local Privilege Escalation via Network Add Request Input Validation
CVSS 7.8
CVE-2022-46265 MEDIUM
Polarion ALM <V2304.0 - Host Header Injection
CVSS 5.4
CVE-2022-4170 CRITICAL
rxvt-unicode - Remote Code Execution in Perl Background Extension
CVSS 9.8
CVE-2022-4364 HIGH
Teledyne FLIR AX8 <1.46.16 - Command Injection
CVSS 7.3
CVE-2022-45910 MEDIUM
Apache ManifoldCF < 2.23 - LDAP Injection in ActiveDirectory and Sharepoint Authority Connectors
CVSS 5.3
CVE-2022-3643 MEDIUM
Linux Kernel 3.19-4.9.335 - Denial of Service via Malicious Network Packet Headers
CVSS 6.5
Details
Vulnerabilities 4,818
Exploit Likelihood High