CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,818 vulnerabilities with CWE-74
CVE-2022-31108 MEDIUM
mermaid 8.0.0-9.1.2 - CSS Injection via Crafted CSS Selectors
CVSS 4.1
CVE-2022-31088 MEDIUM
LDAP Account Manager <8.0 - Info Disclosure
CVSS 5.3
CVE-2022-31087 HIGH
LDAP Account Manager <8.0 - Code Injection
CVSS 7.8
CVE-2022-31086 HIGH
LDAP Account Manager < 8.0 - Remote Code Execution via PHP Script Upload to PDF Templates
CVSS 8.8
CVE-2022-25167 CRITICAL
Apache Flume 1.4.0-1.9.0 - Remote Code Execution via JMS Source JNDI LDAP URI
CVSS 9.8
CVE-2022-29631 HIGH
Jodd HTTP 5.0-6.2.0 - Server-Side Request Forgery via CRLF Injection in HttpRequest
CVSS 7.5
CVE-2022-30991 MEDIUM
Acronis Cyber Protect <15 - Info Disclosure
CVSS 6.1
CVE-2022-23068 MEDIUM
ToolJet 0.6.0-1.10.2 - HTML Injection via User Invitation Name Fields
CVSS 5.4
CVE-2022-22975 MEDIUM
Pinniped 0.9.0-0.16.9 - LDAP Query Injection via Common Name Manipulation
CVSS 6.6
CVE-2022-29171 MEDIUM
Sourcegraph < 3.38.0 - Authenticated Remote Code Execution via Gitolite Callsign Command
CVSS 6.6
CVE-2022-29166 HIGH
matrix-appservice-irc <0.33.2 - RCE
CVSS 8.0
CVE-2022-23064 HIGH
Snipe-IT 3.0.0-5.3.7 - Host Header Injection via Password Reset Request
CVSS 8.8
CVE-2022-29816 LOW
JetBrains IntelliJ IDEA < 2022.1 - HTML Injection in IDE Messages
CVSS 2.8
CVE-2022-24888 MEDIUM
Nextcloud Server < 20.0.14.4 - File and Folder Name Injection via Leading/Trailing Whitespace Characters
CVSS 4.3
CVE-2022-27924 HIGH KEV
Zimbra Collaboration Suite 8.8.15 and 9.0 - Unauthenticated Memcache Command Injection
CVSS 7.5
CVE-2022-20693 MEDIUM
Cisco IOS XE - Authenticated OS Command Injection via Web UI API
CVSS 4.7
CVE-2022-28345 HIGH
Signal < 5.34 - URI Spoofing via RTLO Injection
CVSS 7.5
CVE-2022-24838 MEDIUM
Nextcloud Calendar < 3.2.2 - SMTP Command Injection via Newlines in Appointment Emails
CVSS 5.3
CVE-2022-24832 HIGH
GoCD 17.5.0-22.1.0 - LDAP Injection via Username Parameter
CVSS 8.2
CVE-2022-1287 MEDIUM
School Club Application System 1.0 - Unauthenticated Privilege Escalation via Users.php Save User Request
CVSS 6.5
CVE-2022-1074 MEDIUM
TEM FLEX-1085 1.6.0 - HTML Injection via WiFi Settings Dashboard Input
CVSS 4.3
CVE-2022-25420 CRITICAL
goo blog App 1.0 - CLRF Injection via Crafted HTTP Request
CVSS 9.8
CVE-2022-26205 CRITICAL
Marky - Remote Code Execution via Display Text Field Injection
CVSS 9.8
CVE-2022-20001 HIGH
fish 3.1.0-3.3.1 - Arbitrary Code Execution via Git Repository Configuration
CVSS 7.8
CVE-2022-22344 MEDIUM
IBM Spectrum Copy Data Management <2.2.14.3 - HTTP Header Injection
CVSS 6.1
Details
Vulnerabilities 4,818
Exploit Likelihood High