CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,829 vulnerabilities with CWE-74
CVE-2021-21303 MEDIUM
Helm 3.0.0-3.5.1 - Terminal Injection via Unsanitized Chart and Repository Metadata
CVSS 5.9
CVE-2021-1221 MEDIUM
Cisco Webex Meetings <41.1.0 & Webex Meetings Server <3.0 - Authenticated Hyperlink Injection
CVSS 4.1
CVE-2021-21277 HIGH
angular-expressions < 1.1.2 - Remote Code Execution via Constructor Bypass
CVSS 8.5
CVE-2021-21278 HIGH
RSSHub < 2021-01-25 - Remote Code Execution via Unsafe Eval in Route Handlers
CVSS 8.6
CVE-2021-21263 HIGH
Laravel <6.20.11, 7.30.2, 8.22.1 - SQL Injection
CVSS 7.2
CVE-2021-21249 CRITICAL
OneDev < 4.0.3 - Authenticated Remote Code Execution via SnakeYAML Deserialization
CVSS 9.6
CVE-2021-21248 CRITICAL
OneDev < 4.0.3 - Remote Code Execution via Build Endpoint Parameter Injection
CVSS 9.6
CVE-2021-21247 CRITICAL
OneDev < 4.0.3 - Authenticated Remote Code Execution via AJAX Event Listener Deserialization
CVSS 9.6
CVE-2021-21242 CRITICAL
OneDev < 4.0.3 - Unauthenticated Remote Code Execution via Attachment-Support Header Deserialization
CVSS 10.0
CVE-2021-21244 CRITICAL
OneDev <4.0.3 - Server Side Template Injection
CVSS 10.0
CVE-2021-21243 CRITICAL
OneDev <4.0.3 - Pre-Auth Code Injection
CVSS 10.0
CVE-2021-21261 HIGH
flatpak 0.11.4-1.8.4 - Sandbox Escape via Environment Variable Injection in flatpak-portal
CVSS 7.3
CVE-2020-28848 HIGH
ChurchCRM 4.2.0 - CSV Injection via Crafted File
CVSS 8.8
CVE-2020-24275 MEDIUM
Swoole 4.5.2 - HTTP Response Header Injection via Crafted URL
CVSS 6.5
CVE-2020-36618 MEDIUM
Furqan node-whois - Prototype Pollution
CVSS 6.3
CVE-2020-27602 CRITICAL
BigBlueButton <2.2.7 - Command Injection
CVSS 9.8
CVE-2020-36531 MEDIUM
SevOne Network Performance Management 5.7.2.0-5.7.2.22 - Privilege Escalation via Device Manager Page Injection
CVSS 6.3
CVE-2020-28246 CRITICAL
Form.io 2.0.0 - Authenticated Server-Side Template Injection via Email Template Deletion
CVSS 9.8
CVE-2020-12965 HIGH
AMD Ryzen PRO Firmware - Data Leakage via Non-Canonical Address Handling
CVSS 7.5
CVE-2020-35213 HIGH
Atomix 3.1.5 - Denial of Service via False Link Event Messages
CVSS 8.1
CVE-2020-23050 HIGH
TAO Open Source Assessment Platform <3.3.0 RC02 - XSS
CVSS 8.0
CVE-2020-18875 HIGH
dotcms < 5.1.0 - Remote Privilege Escalation via VTL File Client Configuration Injection
CVSS 8.8
CVE-2020-23148 HIGH
rconfig 3.9.5 - LDAP Injection via userLogin Parameter
CVSS 7.5
CVE-2020-24826 MEDIUM
Libelfin v0.3 - Denial of Service via Crafted ELF File in elf::section::as_strtab
CVSS 5.5
CVE-2020-24825 MEDIUM
libelfin v0.3 - Denial of Service via Crafted ELF File
CVSS 5.5
Details
Vulnerabilities 4,829
Exploit Likelihood High