← Back
CWE-116

522 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Encoding or Escaping of Output

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

JSON object

Loading...

CVEs (522)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netapp
1Oncommand System Manager
May 13, 2026
Feb 7, 2017
N/A· v4
7.5 HIGH· v3
4.4 MEDIUM· v2
Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users to execute arbitrary API calls via unspecified vectors.
3F5
OpensuseSuse
5Lifecycle Management Server
NginxOpensuse+2 more
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.