CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,818 vulnerabilities with CWE-74
CVE-2022-31108
MEDIUM
mermaid 8.0.0-9.1.2 - CSS Injection via Crafted CSS Selectors
CVSS 4.1
CVE-2022-31088
MEDIUM
LDAP Account Manager <8.0 - Info Disclosure
CVSS 5.3
CVE-2022-31087
HIGH
LDAP Account Manager <8.0 - Code Injection
CVSS 7.8
CVE-2022-31086
HIGH
LDAP Account Manager < 8.0 - Remote Code Execution via PHP Script Upload to PDF Templates
CVSS 8.8
CVE-2022-25167
CRITICAL
Apache Flume 1.4.0-1.9.0 - Remote Code Execution via JMS Source JNDI LDAP URI
CVSS 9.8
CVE-2022-29631
HIGH
Jodd HTTP 5.0-6.2.0 - Server-Side Request Forgery via CRLF Injection in HttpRequest
CVSS 7.5
CVE-2022-30991
MEDIUM
Acronis Cyber Protect <15 - Info Disclosure
CVSS 6.1
CVE-2022-23068
MEDIUM
ToolJet 0.6.0-1.10.2 - HTML Injection via User Invitation Name Fields
CVSS 5.4
CVE-2022-22975
MEDIUM
Pinniped 0.9.0-0.16.9 - LDAP Query Injection via Common Name Manipulation
CVSS 6.6
CVE-2022-29171
MEDIUM
Sourcegraph < 3.38.0 - Authenticated Remote Code Execution via Gitolite Callsign Command
CVSS 6.6
CVE-2022-29166
HIGH
matrix-appservice-irc <0.33.2 - RCE
CVSS 8.0
CVE-2022-23064
HIGH
Snipe-IT 3.0.0-5.3.7 - Host Header Injection via Password Reset Request
CVSS 8.8
CVE-2022-29816
LOW
JetBrains IntelliJ IDEA < 2022.1 - HTML Injection in IDE Messages
CVSS 2.8
CVE-2022-24888
MEDIUM
Nextcloud Server < 20.0.14.4 - File and Folder Name Injection via Leading/Trailing Whitespace Characters
CVSS 4.3
CVE-2022-27924
HIGH
KEV
Zimbra Collaboration Suite 8.8.15 and 9.0 - Unauthenticated Memcache Command Injection
CVSS 7.5
CVE-2022-20693
MEDIUM
Cisco IOS XE - Authenticated OS Command Injection via Web UI API
CVSS 4.7
CVE-2022-28345
HIGH
Signal < 5.34 - URI Spoofing via RTLO Injection
CVSS 7.5
CVE-2022-24838
MEDIUM
Nextcloud Calendar < 3.2.2 - SMTP Command Injection via Newlines in Appointment Emails
CVSS 5.3
CVE-2022-24832
HIGH
GoCD 17.5.0-22.1.0 - LDAP Injection via Username Parameter
CVSS 8.2
CVE-2022-1287
MEDIUM
School Club Application System 1.0 - Unauthenticated Privilege Escalation via Users.php Save User Request
CVSS 6.5
CVE-2022-1074
MEDIUM
TEM FLEX-1085 1.6.0 - HTML Injection via WiFi Settings Dashboard Input
CVSS 4.3
CVE-2022-25420
CRITICAL
goo blog App 1.0 - CLRF Injection via Crafted HTTP Request
CVSS 9.8
CVE-2022-26205
CRITICAL
Marky - Remote Code Execution via Display Text Field Injection
CVSS 9.8
CVE-2022-20001
HIGH
fish 3.1.0-3.3.1 - Arbitrary Code Execution via Git Repository Configuration
CVSS 7.8
CVE-2022-22344
MEDIUM
IBM Spectrum Copy Data Management <2.2.14.3 - HTTP Header Injection
CVSS 6.1
Details
Vulnerabilities
4,818
Exploit Likelihood
High