CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,818 vulnerabilities with CWE-74
CVE-2022-46169
CRITICAL
KEV
Cacti 1.2.22 unauthenticated command injection
CVSS 9.8
CVE-2022-35507
HIGH
Proxmox Virtual Environment and Proxmox Mail Gateway - Response Header Injection via CRLF
CVSS 7.1
CVE-2022-46162
HIGH
Discourse BBCode <91478f5 - Code Injection
CVSS 8.8
CVE-2022-4188
MEDIUM
Google Chrome < 108.0.5359.71 - Same Origin Policy Bypass via CORS Input Validation
CVSS 4.3
CVE-2022-41934
CRITICAL
XWiki Platform < 13.10.8 - Authenticated Remote Code Execution via Menu Macro Injection
CVSS 9.9
CVE-2022-33012
HIGH
Microweber v1.2.15 - Host Header Injection
CVSS 8.8
CVE-2022-4064
LOW
dalli < 3.2.3 - Injection via Meta Protocol Handler cas/ttl Argument
CVSS 3.7
CVE-2022-41878
HIGH
Parse Server <5.3.2, <4.10.19 - Auth Bypass
CVSS 7.2
CVE-2022-43562
LOW
Splunk Enterprise <8.1.12-9.0.2 - XSS
CVSS 3.0
CVE-2022-20772
MEDIUM
Cisco ESA/Secure Email and Web Manager - HTTP Response Splitting
CVSS 4.7
CVE-2022-39382
CRITICAL
Keystone 3.0.0-3.0.1 - Environment Variable Injection via NODE_ENV Inlining
CVSS 9.8
CVE-2022-31777
MEDIUM
Apache Spark < 3.2.2 - Stored Cross-Site Scripting via Log Rendering
CVSS 5.4
CVE-2022-39016
HIGH
M-Files Hubshare < 3.3.10.9 - Authenticated Account Takeover via PDF JavaScript Injection
CVSS 8.2
CVE-2022-42468
CRITICAL
Apache Flume 1.4.0-1.10.1 - Remote Code Execution via JMS Source ProviderURL
CVSS 9.8
CVE-2022-3607
MEDIUM
octoprint/octoprint <1.8.3 - Special Element Injection
CVSS 6.0
CVE-2022-2992
CRITICAL
GitLab GitHub Repo Import Deserialization RCE
CVSS 9.9
CVE-2022-40257
MEDIUM
CERT/CC VINCE < 1.50.4 - Authenticated HTML Injection via Email Subject Field
CVSS 5.4
CVE-2022-40248
MEDIUM
CERT/CC VINCE < 1.50.4 - Authenticated HTML Injection via Product Affected Field
CVSS 5.4
CVE-2022-39265
HIGH
MyBB < 1.8.31 - Authenticated Remote Code Execution via Mail Settings Parameter Injection
CVSS 7.2
CVE-2022-3215
HIGH
SwiftNIO < 2.29.1 and 2.41.0-2.42.0 - HTTP Response Injection via CRLF in HTTP Headers
CVSS 7.5
CVE-2022-35914
CRITICAL
KEV
GLPI htmLawed php command injection
CVSS 9.8
CVE-2022-39217
MEDIUM
ghas-to-csv < 1 - CSV Injection via Unsanitized API Output
CVSS 5.8
CVE-2022-38796
MEDIUM
Feehi CMS 2.1.1 - Host Header Injection via Password Reset Email
CVSS 6.1
CVE-2022-34165
MEDIUM
IBM WebSphere Application Server <22.0.0.9 - HTTP Header Injection
CVSS 5.4
CVE-2022-36084
CRITICAL
cruddl <2.7.0-3.0.2 - Code Injection
CVSS 9.9
Details
Vulnerabilities
4,818
Exploit Likelihood
High