CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,818 vulnerabilities with CWE-74
CVE-2022-24760 CRITICAL
Parse Server < 4.10.7 - Remote Code Execution via Prototype Pollution in DatabaseController.js
CVSS 10.0
CVE-2022-23701 MEDIUM
HPE Integrated Lights-Out 4 < 2.60 - Remote Host Header Injection
CVSS 5.3
CVE-2022-21705 HIGH
OctoberCMS < 1.0.474 - Authenticated Remote Code Execution via Safe Mode Bypass
CVSS 7.2
CVE-2022-25337 CRITICAL
Ibexa DXP ezsystems/ezpublish-kernel 7.5.0-7.5.25 and 1.3.0-1.3.11 - Injection via Image Filenames
CVSS 9.8
CVE-2022-0391 HIGH
Python <3.10.0b1-3.6.14 - Code Injection
CVSS 7.5
CVE-2022-23616 HIGH
XWiki Platform 3.1.1-13.1 - Unauthenticated Remote Code Execution via Reset Password Feature
CVSS 8.8
CVE-2022-23614 HIGH
Twig 2.0.0-2.14.11 - Remote Code Execution via Sort Filter Arrow Parameter
CVSS 8.8
CVE-2022-21663 MEDIUM
WordPress < 5.8.3 - Authenticated Object Injection via Multisite Super Admin Role
CVSS 6.6
CVE-2021-4227 MEDIUM
WordPress ark-commenteditor <2.15.6 - XSS
CVSS 5.3
CVE-2021-37499 MEDIUM
Reprise License Manager < 17.0 - HTTP Header Injection via Password Parameter in View License Result
CVSS 6.5
CVE-2021-4245 MEDIUM
chbrown rfc6902 - Prototype Pollution
CVSS 5.5
CVE-2021-33621 HIGH
cgi <0.1.0.2, <0.2.x -<0.2.2, <0.3.x -<0.3.5 - XSS
CVSS 8.8
CVE-2021-38395 CRITICAL
Honeywell Experion PKS C200, C200E, C300, and ACE - Remote Code Execution and Denial of Service
CVSS 9.1
CVE-2021-36913 HIGH
Redirection for Contact Form 7 <= 2.4.0 - Unauthenticated Options Change and Content Injection
CVSS 7.5
CVE-2021-41437 MEDIUM
ASUS RT-AX88U Firmware < 3.0.0.4.388.20558 - HTTP Response Splitting via Crafted URL
CVSS 6.5
CVE-2021-40336 MEDIUM
Hitachi Energy MSM <=2.2 - HTTP Response Splitting via Header Validation Failure
CVSS 5.0
CVE-2021-39028 MEDIUM
IBM Engineering Lifecycle Optimization - Publishing HTTP Header Injection via HOST Header
CVSS 5.4
CVE-2021-36668 HIGH
Druva inSync Client < 5.9.3, < 7.0.1 - URL Injection via Port Parameter
CVSS 7.8
CVE-2021-22055 MEDIUM
Vmware photon_os < 2022-02-16 - Log Injection via SchedulerServer Package Parameter
CVSS 5.3
CVE-2021-41282 HIGH
pfSense Diag Routes Web Shell Upload
CVSS 8.8
CVE-2021-44550 CRITICAL
Stanford CoreNLP < 4.4.0 - Incorrect Access Control in NERServlet Classifier
CVSS 9.8
CVE-2021-43929 MEDIUM
Synology DSM <7.0.1-42218-2 - Command Injection
CVSS 6.5
CVE-2021-36348 HIGH
iDRAC9 <5.00.20.00 - Command Injection
CVSS 8.1
CVE-2021-39031 HIGH
IBM WebSphere Application Server Liberty 17.0.0.3-22.0.0.1 - Authenticated LDAP Injection
CVSS 8.8
CVE-2021-44537 HIGH
owncloud_desktop_client < 2.9.2 - Remote Code Execution via URL Resource Injection
CVSS 7.8
Details
Vulnerabilities 4,818
Exploit Likelihood High