CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,843 vulnerabilities with CWE-74
CVE-2018-21051
CRITICAL
Android N(7.x) and O(8.x) - Arbitrary Code Execution via Fingerprint Trustlet Invalid Free
CVSS 9.8
CVE-2018-20914
HIGH
cPanel < 70.0.23 - Session File Injection via OpenID Provider
CVSS 7.3
CVE-2018-20898
MEDIUM
cPanel 61.9999.55-71.9980.37 - Email Injection via cPAddons Moderation
CVSS 4.3
CVE-2018-20885
MEDIUM
cPanel < 74.0.0 - Apache HTTP Server Configuration Injection via DocumentRoot Variable Interpolation
CVSS 5.3
CVE-2018-1943
MEDIUM
IBM Cloud Private <3.1.2 - HTTP HOST header injection
CVSS 5.4
CVE-2018-4153
MEDIUM
macOS < 10.14 - Injection via Improved Validation
CVSS 5.9
CVE-2018-18996
CRITICAL
LCDS Laquis SCADA < 4.1.0.4150 - Remote Code Execution
CVSS 9.8
CVE-2018-18992
HIGH
LCDS Laquis SCADA < 4.1.0.4150 - Remote Code Execution
CVSS 8.8
CVE-2018-16492
CRITICAL
extend <2.0.2, 3.0.0-3.0.2 - Prototype Pollution
CVSS 9.8
CVE-2018-16491
CRITICAL
node.extend <1.1.7 - Prototype Pollution
CVSS 9.8
CVE-2018-16490
HIGH
mpath < 0.5.1 - Prototype Pollution
CVSS 7.5
CVE-2018-16489
CRITICAL
just-extend < 4.0.0 - Prototype Pollution via Function Property Injection
CVSS 9.8
CVE-2018-16486
CRITICAL
defaults-deep <=0.2.4 - Prototype Pollution
CVSS 9.8
CVE-2018-16627
MEDIUM
Kirby 2.5.12 - Host Header Injection via Forget Password Feature
CVSS 6.1
CVE-2018-1000854
CRITICAL
esigate < 5.2 - Remote Code Execution via ESI Directive with User-Specified XSLT
CVSS 9.8
CVE-2018-18250
HIGH
Icinga Web 2 < 2.6.2 - Cross-Site Scripting via Navigation Dashlet Name Parameter
CVSS 7.5
CVE-2018-20167
HIGH
Terminology < 1.3.1 - Remote Code Execution via Popmedia Control Sequence
CVSS 7.8
CVE-2018-1474
MEDIUM
IBM BigFix Platform <9.2.14, <9.5.9 - HTTP Response Splitting
CVSS 6.1
CVE-2018-1896
MEDIUM
IBM Connections 5.0, 5.5, and 6.0 - Host Header Injection
CVSS 4.6
CVE-2018-18207
MEDIUM
Virtualmin 6.03 - Frame Injection via Settings Editor File Parameter
CVSS 6.1
CVE-2018-16763
CRITICAL
FUEL CMS < 1.4.2 - Unauthenticated Remote Code Execution via Pages Filter or Preview Data Parameter
CVSS 9.8
CVE-2018-9062
MEDIUM
Lenovo ThinkPad and V Series Firmware - Arbitrary Code Execution via Improper BIOS Region Check
CVSS 6.8
CVE-2018-1549
MEDIUM
IBM Rational Quality Manager 5.0-5.0.2 and 6.0-6.0.5 - HTTP Response Splitting via Crafted URL
CVSS 5.4
CVE-2018-4995
CRITICAL
Adobe Acrobat and Reader DC < 15.006.30417, 15.008.20082-18.011.20038 - Security Bypass via XFA Newline Injection
CVSS 9.8
CVE-2018-0313
HIGH
Cisco NX-OS - Authenticated Remote Code Execution via NX-API HTTP/HTTPS Packet
CVSS 8.8
Details
Vulnerabilities
4,843
Exploit Likelihood
High