CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,818 vulnerabilities with CWE-74
CVE-2022-37108
HIGH
Securonix Snypr 6.4 - Authenticated Remote Code Execution via Syslog-ng Configuration Wizard
CVSS 8.7
CVE-2022-37242
CRITICAL
SecurityGateway for Email Servers 8.5.2 - HTTP Response Splitting via DATA Parameter
CVSS 9.8
CVE-2022-37240
CRITICAL
SecurityGateway for Email Servers 8.5.2 - HTTP Response Splitting via Format Parameter
CVSS 9.8
CVE-2022-34773
MEDIUM
tabit < 3.27.0 - HTTP Method Manipulation via Addresses Query Endpoint
CVSS 4.9
CVE-2022-32453
MEDIUM
Cybozu Office 10.0.0-10.8.5 - HTTP Header Injection
CVSS 6.5
CVE-2022-38357
HIGH
Eyes of Network Web - iFrame Injection via URL Parameter
CVSS 8.8
CVE-2022-38191
MEDIUM
Esri Portal for ArcGIS <10.9.0 - Code Injection
CVSS 6.1
CVE-2022-35954
MEDIUM
GitHub Actions ToolKit <v1.9.1 - Code Injection
CVSS 5.0
CVE-2022-35948
MEDIUM
undici < 5.8.1 - CRLF Injection via Content-Type Header
CVSS 5.3
CVE-2022-36323
CRITICAL
Affected Device - Command Injection
CVSS 9.1
CVE-2022-31665
HIGH
VMware Identity Manager - Remote Code Execution
CVSS 7.2
CVE-2022-31658
HIGH
VMware Workspace ONE Access and Identity Manager - Remote Code Execution
CVSS 7.2
CVE-2022-35735
HIGH
BIG-IP <16.1.3.1, 15.1.x <15.1.6.1, 14.1.x <14.1.5.1, 13.1.x - Priv...
CVSS 7.2
CVE-2022-31181
CRITICAL
PrestaShop <1.7.8.7 - SQL Injection
CVSS 9.8
CVE-2022-31180
CRITICAL
shescape 1.4.0-1.5.7 - Command Injection via Interpolation Option
CVSS 9.8
CVE-2022-31179
HIGH
shescape < 1.5.8 - Command Injection via Line Feed Character
CVSS 8.1
CVE-2022-36302
HIGH
Bosch BF-OS 3.00-3.83 - Path Traversal
CVSS 8.8
CVE-2022-22360
HIGH
IBM Sterling Partner Engagement Manager - LDAP Injection
CVSS 8.8
CVE-2022-31593
HIGH
SAP Business One client <10.0 - Code Injection
CVSS 8.8
CVE-2022-34466
MEDIUM
Mendix 9 >=V9.11<V9.15,Mendix 9 V9.12 <V9.12.3 - Info Disclosure
CVSS 6.5
CVE-2022-34914
CRITICAL
Webswing < 20.1.16 - Argument Injection via X-Forwarded-For Header
CVSS 9.8
CVE-2022-33011
HIGH
Known <1.3.1+2020120201 - Host Header Injection
CVSS 8.8
CVE-2022-31126
CRITICAL
Roxy-wi < 6.1.1.0 - Unauthenticated Remote Code Execution via /app/options.py
CVSS 10.0
CVE-2022-31014
MEDIUM
Nextcloud Server < 19.0.13.7, < 22.2.8 - SMTP Command Injection via CRLF Injection
CVSS 5.4
CVE-2022-34903
MEDIUM
GnuPG < 2.3.6 - Signature Forgery via Status Line Injection
CVSS 6.5
Details
Vulnerabilities
4,818
Exploit Likelihood
High