CWE-116
475 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
CVEs (475)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is r...Show more |
1Cisco 9Firepower 4110 Firmware Firepower 4115 FirmwareFirepower 4120 Firmware+6 moreJun 17, 2026 Oct 2, 2019 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands wit...Show more |
1Cisco 9Firepower 4110 Firmware Firepower 4115 FirmwareFirepower 4120 Firmware+6 moreJun 17, 2026 Oct 2, 2019 N/A· v4 8.2 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands wit...Show more |
LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings, typically execution of macros are blocked by default. A URL decoding flaw existed in how the urls t...Show more |
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manage...Show more |
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request no...Show more |
An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of...Show more |
1Valvesoftware 1Counter Strike Jun 17, 2026 Sep 5, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Counter-Strike: Global Offensive before 8/29/2019, community game servers can display unsafe HTML in a disconnection message. |
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Aug 15, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the sha...Show more |
1Jenkins 1Configuration As Code Jun 17, 2026 Jul 31, 2019 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when exporting, allowing attackers with permission to change Jenkins system conf...Show more |
4Debian MozillaNovell+1 more5Debian Linux FirefoxLeap+2 moreJun 17, 2026 Jul 23, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Fir...Show more |
An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension. |
1Pivotal Software 1Cloud Foundry Uaa Release Jun 17, 2026 Jul 11, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all ot...Show more |
An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be achieved via the PATH_INFO to swp/login/EJBRemoteService/, related to com.swift.ejbgwt.j2ee.client.EjB...Show more |
An issue was discovered in Netdata 1.10.0. Log Injection (or Log Forgery) exists via a %0a sequence in the url parameter to api/v1/registry. |
1Microsoft 2Azure Devops Server Team Foundation ServerJun 17, 2026 May 16, 2019 N/A· v4 6.5 MEDIUM· v3 9.0 HIGH· v2 An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to an affected server, aka 'Azure DevOps Se...Show more |
1Microsoft 2Sharepoint Enterprise Server Sharepoint FoundationJun 17, 2026 May 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Server Information Di...Show more |
All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised. |
1Microsoft 1Azure Devops Server Jun 17, 2026 Apr 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Spoofing Vulnerability'. |