CWE-116
433 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
CVEs (433)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a m...Show more |
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES. This issue affects...Show more |
1Ibm 2App Connect Enterprise Integration BusJan 28, 2025 Mar 26, 2024 N/A· v4 4.9 MEDIUM· v3 N/A· v2 IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 through 10.1.0.2store potentially sensitive information in log or trace files that could be read by a...Show more |
KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\includegraphics` that runs arbitrary JavaScript, or gener...Show more |
In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive servi...Show more |
Postal is an open source SMTP server. Postal versions less than 3.0.0 are vulnerable to SMTP Smuggling attacks which may allow incoming e-mails to be spoofed. This, in conjunction with a cooperative outgoing SMTP service...Show more |
IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system...Show more |
All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability could lead...Show more |
2Fedoraproject Redhat6Ansible Ansible Automation PlatformAnsible Developer+3 moreNov 4, 2025 Feb 6, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. D...Show more |
A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header |
1Ibm 1Tivoli Application Dependency Discovery Manager Nov 21, 2024 Feb 2, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct va...Show more |
A vulnerability classified as critical has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected is an unknown function of the file /runtime/log. The manipulation leads to improper output neutralization for...Show more |
1Dell 3Unity Operating Environment Unity Xt Operating EnvironmentUnityvsa Operating EnvironmentNov 21, 2024 Jan 24, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and in...Show more |
1Intel 6Nuc 7 Essential Nuc7cjysamn Firmware Nuc Kit Nuc7cjyh FirmwareNuc Kit Nuc7cjyhn Firmware+3 moreNov 21, 2024 Jan 19, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation for some Intel NUC BIOS firmware before version JY0070 may allow a privileged user to potentially enable escalation of privilege via local access. |
1Integrationobjects 1Opc Ua Server Toolkit Nov 21, 2024 Jan 16, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2
OPCUAServerToolkit will write a log message once an OPC UA client has successfully connected containing the client's self-defined description field.
|
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, leading to a Reflected Cross-Site Scripting which could...Show more |
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Script...Show more |
Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality. |
Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability. |
This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability specifically impacts web applications that render user-supplied data thr...Show more |