CWE-116
522 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
CVEs (522)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netapp 1Oncommand System Manager May 13, 2026 Feb 7, 2017 N/A· v4 7.5 HIGH· v3 4.4 MEDIUM· v2 Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users to execute arbitrary API calls via unspecified vectors. |
3F5 OpensuseSuse5Lifecycle Management Server NginxOpensuse+2 moreApr 29, 2026 Nov 23, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI. |