CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,818 vulnerabilities with CWE-74
CVE-2022-37108 HIGH
Securonix Snypr 6.4 - Authenticated Remote Code Execution via Syslog-ng Configuration Wizard
CVSS 8.7
CVE-2022-37242 CRITICAL
SecurityGateway for Email Servers 8.5.2 - HTTP Response Splitting via DATA Parameter
CVSS 9.8
CVE-2022-37240 CRITICAL
SecurityGateway for Email Servers 8.5.2 - HTTP Response Splitting via Format Parameter
CVSS 9.8
CVE-2022-34773 MEDIUM
tabit < 3.27.0 - HTTP Method Manipulation via Addresses Query Endpoint
CVSS 4.9
CVE-2022-32453 MEDIUM
Cybozu Office 10.0.0-10.8.5 - HTTP Header Injection
CVSS 6.5
CVE-2022-38357 HIGH
Eyes of Network Web - iFrame Injection via URL Parameter
CVSS 8.8
CVE-2022-38191 MEDIUM
Esri Portal for ArcGIS <10.9.0 - Code Injection
CVSS 6.1
CVE-2022-35954 MEDIUM
GitHub Actions ToolKit <v1.9.1 - Code Injection
CVSS 5.0
CVE-2022-35948 MEDIUM
undici < 5.8.1 - CRLF Injection via Content-Type Header
CVSS 5.3
CVE-2022-36323 CRITICAL
Affected Device - Command Injection
CVSS 9.1
CVE-2022-31665 HIGH
VMware Identity Manager - Remote Code Execution
CVSS 7.2
CVE-2022-31658 HIGH
VMware Workspace ONE Access and Identity Manager - Remote Code Execution
CVSS 7.2
CVE-2022-35735 HIGH
BIG-IP <16.1.3.1, 15.1.x <15.1.6.1, 14.1.x <14.1.5.1, 13.1.x - Priv...
CVSS 7.2
CVE-2022-31181 CRITICAL
PrestaShop <1.7.8.7 - SQL Injection
CVSS 9.8
CVE-2022-31180 CRITICAL
shescape 1.4.0-1.5.7 - Command Injection via Interpolation Option
CVSS 9.8
CVE-2022-31179 HIGH
shescape < 1.5.8 - Command Injection via Line Feed Character
CVSS 8.1
CVE-2022-36302 HIGH
Bosch BF-OS 3.00-3.83 - Path Traversal
CVSS 8.8
CVE-2022-22360 HIGH
IBM Sterling Partner Engagement Manager - LDAP Injection
CVSS 8.8
CVE-2022-31593 HIGH
SAP Business One client <10.0 - Code Injection
CVSS 8.8
CVE-2022-34466 MEDIUM
Mendix 9 >=V9.11<V9.15,Mendix 9 V9.12 <V9.12.3 - Info Disclosure
CVSS 6.5
CVE-2022-34914 CRITICAL
Webswing < 20.1.16 - Argument Injection via X-Forwarded-For Header
CVSS 9.8
CVE-2022-33011 HIGH
Known <1.3.1+2020120201 - Host Header Injection
CVSS 8.8
CVE-2022-31126 CRITICAL
Roxy-wi < 6.1.1.0 - Unauthenticated Remote Code Execution via /app/options.py
CVSS 10.0
CVE-2022-31014 MEDIUM
Nextcloud Server < 19.0.13.7, < 22.2.8 - SMTP Command Injection via CRLF Injection
CVSS 5.4
CVE-2022-34903 MEDIUM
GnuPG < 2.3.6 - Signature Forgery via Status Line Injection
CVSS 6.5
Details
Vulnerabilities 4,818
Exploit Likelihood High