CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,818 vulnerabilities with CWE-74
CVE-2022-46169 CRITICAL KEV
Cacti 1.2.22 unauthenticated command injection
CVSS 9.8
CVE-2022-35507 HIGH
Proxmox Virtual Environment and Proxmox Mail Gateway - Response Header Injection via CRLF
CVSS 7.1
CVE-2022-46162 HIGH
Discourse BBCode <91478f5 - Code Injection
CVSS 8.8
CVE-2022-4188 MEDIUM
Google Chrome < 108.0.5359.71 - Same Origin Policy Bypass via CORS Input Validation
CVSS 4.3
CVE-2022-41934 CRITICAL
XWiki Platform < 13.10.8 - Authenticated Remote Code Execution via Menu Macro Injection
CVSS 9.9
CVE-2022-33012 HIGH
Microweber v1.2.15 - Host Header Injection
CVSS 8.8
CVE-2022-4064 LOW
dalli < 3.2.3 - Injection via Meta Protocol Handler cas/ttl Argument
CVSS 3.7
CVE-2022-41878 HIGH
Parse Server <5.3.2, <4.10.19 - Auth Bypass
CVSS 7.2
CVE-2022-43562 LOW
Splunk Enterprise <8.1.12-9.0.2 - XSS
CVSS 3.0
CVE-2022-20772 MEDIUM
Cisco ESA/Secure Email and Web Manager - HTTP Response Splitting
CVSS 4.7
CVE-2022-39382 CRITICAL
Keystone 3.0.0-3.0.1 - Environment Variable Injection via NODE_ENV Inlining
CVSS 9.8
CVE-2022-31777 MEDIUM
Apache Spark < 3.2.2 - Stored Cross-Site Scripting via Log Rendering
CVSS 5.4
CVE-2022-39016 HIGH
M-Files Hubshare < 3.3.10.9 - Authenticated Account Takeover via PDF JavaScript Injection
CVSS 8.2
CVE-2022-42468 CRITICAL
Apache Flume 1.4.0-1.10.1 - Remote Code Execution via JMS Source ProviderURL
CVSS 9.8
CVE-2022-3607 MEDIUM
octoprint/octoprint <1.8.3 - Special Element Injection
CVSS 6.0
CVE-2022-2992 CRITICAL
GitLab GitHub Repo Import Deserialization RCE
CVSS 9.9
CVE-2022-40257 MEDIUM
CERT/CC VINCE < 1.50.4 - Authenticated HTML Injection via Email Subject Field
CVSS 5.4
CVE-2022-40248 MEDIUM
CERT/CC VINCE < 1.50.4 - Authenticated HTML Injection via Product Affected Field
CVSS 5.4
CVE-2022-39265 HIGH
MyBB < 1.8.31 - Authenticated Remote Code Execution via Mail Settings Parameter Injection
CVSS 7.2
CVE-2022-3215 HIGH
SwiftNIO < 2.29.1 and 2.41.0-2.42.0 - HTTP Response Injection via CRLF in HTTP Headers
CVSS 7.5
CVE-2022-35914 CRITICAL KEV
GLPI htmLawed php command injection
CVSS 9.8
CVE-2022-39217 MEDIUM
ghas-to-csv < 1 - CSV Injection via Unsanitized API Output
CVSS 5.8
CVE-2022-38796 MEDIUM
Feehi CMS 2.1.1 - Host Header Injection via Password Reset Email
CVSS 6.1
CVE-2022-34165 MEDIUM
IBM WebSphere Application Server <22.0.0.9 - HTTP Header Injection
CVSS 5.4
CVE-2022-36084 CRITICAL
cruddl <2.7.0-3.0.2 - Code Injection
CVSS 9.9
Details
Vulnerabilities 4,818
Exploit Likelihood High