CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,837 vulnerabilities with CWE-74
CVE-2020-15255
HIGH
Anuko Time Tracker <1.19.23.5325 - Info Disclosure
CVSS 8.7
CVE-2020-15252
HIGH
XWiki < 11.10.6 - Authenticated Remote Code Execution via Servlet Context Access
CVSS 8.5
CVE-2020-25768
MEDIUM
Contao < 4.4.52, 4.9.x < 4.9.6, 4.10.x < 4.10.1 - Insert Tag Injection in Front End Forms
CVSS 5.3
CVE-2020-15227
HIGH
Nette <2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 - Code Injection
CVSS 8.7
CVE-2020-26137
MEDIUM
urllib3 < 1.25.9 - CRLF Injection via HTTP Request Method
CVSS 6.5
CVE-2020-21523
CRITICAL
halo CMS 1.1.3 - Server-Side Freemarker Template Injection via Edit Theme File Function
CVSS 9.8
CVE-2020-26116
HIGH
Python 3.x < 3.5.10, 3.6.x < 3.6.12, 3.7.x < 3.7.9, 3.8.x < 3.8.5 - HTTP Header Injection via HTTPConnection.request
CVSS 7.2
CVE-2020-25596
MEDIUM
Xen 3.2.0-4.14.x - Denial of Service via SYSENTER Instruction Handling
CVSS 5.5
CVE-2020-15187
LOW
Helm <2.16.11, 3.3.2 - Local Execution
CVSS 3.0
CVE-2020-15186
LOW
Helm <2.16.11-3.3.2 - Code Injection
CVSS 3.4
CVE-2020-15185
LOW
Helm <2.16.11, <3.3.2 - Info Disclosure
CVSS 2.2
CVE-2020-15184
LOW
Helm <2.16.11, <3.3.2 - Code Injection
CVSS 3.7
CVE-2020-16875
HIGH
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
CVSS 8.4
CVE-2020-15171
MEDIUM
XWiki < 11.10.5 - Authenticated Remote Code Execution via Servlet Context Access
CVSS 6.6
CVE-2020-15164
CRITICAL
Scratch Login <1.1 - Info Disclosure
CVSS 10.0
CVE-2020-12855
HIGH
SecZetta NEProfile <3.3.11 - Host Header Injection
CVSS 8.8
CVE-2020-13863
HIGH
Mitel MiCollab < 9.1.3 - HTTP Header Injection in SAS Portal
CVSS 8.1
CVE-2020-24364
HIGH
MineTime <1.8.5 - Command Injection
CVSS 8.8
CVE-2020-15147
HIGH
Red Discord Bot < 3.3.12 - Remote Code Execution via Streams Module Going Live Message
CVSS 8.5
CVE-2020-15140
HIGH
Red Discord Bot < 3.3.11 - Remote Code Execution via Trivia Leaderboard Command
CVSS 8.2
CVE-2020-15146
CRITICAL
SyliusResourceBundle <1.3.14-1.6.4 - RCE
CVSS 9.6
CVE-2020-15143
HIGH
SyliusResourceBundle <1.3.14-1.6.4 - RCE
CVSS 7.7
CVE-2020-15693
MEDIUM
Nim < 1.2.6 - CR-LF Injection in httpClient URL and Header Handling
CVSS 6.5
CVE-2020-16087
HIGH
VNG Zalo Desktop 19.8.1.0 - Remote Code Execution via Crafted File
CVSS 8.6
CVE-2020-17496
CRITICAL
KEV
vBulletin 5.5.4-5.6.2 - Remote Command Execution via subWidgets Data in AJAX Widget Renderer
CVSS 9.8
Details
Vulnerabilities
4,837
Exploit Likelihood
High