CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,829 vulnerabilities with CWE-74
CVE-2021-21372 HIGH
Nim < 1.2.10 - Remote Code Execution via Nimble doCmd Command Injection
CVSS 8.3
CVE-2021-21333 MEDIUM
Synapse < 1.27.0 - HTML Injection in Notification Emails
CVSS 6.1
CVE-2021-3027 MEDIUM
LibrIT PaSSHport <2.5 - Info Disclosure
CVSS 6.5
CVE-2021-29156 HIGH
ForgeRock OpenAM < 13.5.1 - Unauthenticated LDAP Injection via Webfinger Protocol
CVSS 7.5
CVE-2021-1432 HIGH
Cisco IOS XE SD-WAN - Authenticated Command Injection via CLI
CVSS 7.3
CVE-2021-27908 MEDIUM
Mautic < 3.3.2 - Authenticated Information Disclosure via Symfony Parameter Injection
CVSS 5.8
CVE-2021-28963 MEDIUM
Shibboleth Service Provider < 3.2.1 - Content Injection via Template Parameter
CVSS 5.3
CVE-2021-26069 MEDIUM
Atlassian Jira Server/Data Center <8.5.11, 8.6.0-8.13.2, 8.14.0-8.14.9 - Unauthenticated Info Disclosure via API
CVSS 5.3
CVE-2021-24144 HIGH
Contact Form 7 Database Addon <1.2.5.6 - Code Injection
CVSS 7.8
CVE-2021-22191 MEDIUM
Wireshark 3.2.0-3.2.11 and 3.4.0-3.4.3 - Remote Code Execution via Packet Injection or Crafted Capture File
CVSS 6.3
CVE-2021-21381 HIGH
Flatpak 0.9.4-1.10.1 - Unauthenticated Arbitrary File Access via Desktop File Token Injection
CVSS 7.1
CVE-2021-21510 MEDIUM
Dell iDRAC8 < 2.75.100.75 - Unauthenticated Host Header Injection
CVSS 6.1
CVE-2021-21313 MEDIUM
GLPI < 9.5.4 - Cross-Site Scripting via _target Parameter in common.tabs.php
CVSS 4.9
CVE-2021-21353 MEDIUM
pug < 3.0.1 - Remote Code Execution via Pretty Option Injection
CVSS 6.8
CVE-2021-27730 CRITICAL
Accellion FTA <9_12_444 - Command Injection
CVSS 9.8
CVE-2021-27132 CRITICAL
SerComm AG Combo VD625 AGSOT_2.1.0 - HTTP Header Injection via Content-Disposition Header
CVSS 9.8
CVE-2021-3197 CRITICAL
Salt < 2015.8.10 - Injection
CVSS 9.8
CVE-2021-26068 HIGH
Atlassian Jira Server for Slack 0.0.3-2.0.14 - Remote Code Execution via Template Injection
CVSS 8.8
CVE-2021-21316 MEDIUM
less-openui5 < 0.10.0 - Remote Code Execution via Inline JavaScript in Less Files
CVSS 6.3
CVE-2021-20644 MEDIUM
ELECOM WRC-1467GHBK-A Firmware - Stored Cross-Site Scripting via SSID Display
CVSS 6.1
CVE-2021-23335 HIGH
Package is-user-valid - LDAP Injection
CVSS 7.5
CVE-2021-21479 CRITICAL
SAP SCIMono < 0.0.19 - Remote Code Execution via Java Expression Injection
CVSS 9.1
CVE-2021-21141 MEDIUM
Google Chrome <88.0.4324.96 - Info Disclosure
CVSS 6.5
CVE-2021-21137 MEDIUM
Google Chrome <88.0.4324.96 - Info Disclosure
CVSS 6.5
CVE-2021-21305 HIGH
CarrierWave <2.1.1 - Code Injection
CVSS 7.4
Details
Vulnerabilities 4,829
Exploit Likelihood High