← Back
CWE-74

4,992 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

JSON object

Loading...

CVEs (4,992)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Nov 3, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting...Show more
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Nov 1, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
1Liquidfiles
1Liquidfiles
Jun 17, 2026
Oct 30, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attacks against an organization.
1Juzaweb
1Juzaweb Cms
Jun 17, 2026
Oct 28, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the custom plugin function.
1Kubernetes
1Ingress Nginx
Jun 17, 2026
Oct 25, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Ingress nginx annotation injection causes arbitrary command execution.
1Langchain
1Langchain
Jun 17, 2026
Oct 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
1Mintty Project
1Mintty
Jun 17, 2026
Oct 19, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal.
1Jorani
1Leave Management System
Jun 17, 2026
Oct 16, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of the List of Leave requests page.
1Apache
1Inlong
Jun 17, 2026
Oct 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create mislea...Show more
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create misleading or false log records, making it harder to audit and trace malicious activities. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8628Show less
1All Three
1Cachet
Jun 17, 2026
Oct 11, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig ve...Show more
Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Commit 6fb043e109d2a262ce3974e863c54e9e5f5e0587 of the 2.4 branch contains a patch for this issue.Show less
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Oct 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Clone vulnerability in the huks ta module.Successful exploitation of this vulnerability may affect service confidentiality.
1Thingsboard
1Thingsboard
Jun 17, 2026
Oct 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/se...Show more
ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).Show less
1Redhat
1Openshift Container Platform
Jun 17, 2026
Oct 5, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.
1Trellix
1Endpoint Security
Jun 17, 2026
Oct 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables, leading to denial of service and or the execution of...Show more
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables, leading to denial of service and or the execution of arbitrary code. Show less
1Superstorefinder
1Super Store Finder
Jun 17, 2026
Oct 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote Code Execution when settings overwrite config.inc.php content.
1Phpipam
1Phpipam
Jun 17, 2026
Oct 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server...Show more
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitive data via a crafted POST request.Show less
1Postcss
1Postcss
Jun 17, 2026
Sep 29, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS a...Show more
An issue was discovered in PostCSS before 8.4.31. The vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being included in a comment.Show less
3Debian
FedoraprojectGetcomposer
3Composer
Debian LinuxFedora
Jun 17, 2026
Sep 29, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability i...Show more
Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability if PHP also has `register_argc_argv` enabled in php.ini. Versions 2.6.4, 2.2.22 and 1.10.27 patch this vulnerability. Users are advised to upgrade. Users unable to upgrade should make sure `register_argc_argv` is disabled in php.ini, and avoid publishing composer.phar to the web as this is not best practice.Show less
1Mayurik
1Best Courier Management System
Jun 17, 2026
Sep 29, 2023
5.1 MEDIUM· v4
8.8 HIGH· v3
5.2 MEDIUM· v2
A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as critical. Affected is an unknown function of the file parcel_list.php of the component GET Parameter Handler. The...Show more
A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as critical. Affected is an unknown function of the file parcel_list.php of the component GET Parameter Handler. The manipulation of the argument id/s leads to sql injection. The exploit has been disclosed to the public and may be used.Show less
1Ithewei
1Libhv
Jun 17, 2026
Sep 29, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attacker can add the \r\n (carriage return line feeds) characters and inject additio...Show more
All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent.Show less