CWE-74
5,001 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (5,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields. This vulnerability allows attackers to execute arbitrary code via injection of a crafted p...Show more |
3Debian FedoraprojectFishshell3Debian Linux FedoraFishJun 17, 2026 Mar 14, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including runni...Show more |
1Ibm 1Spectrum Copy Data Management Jun 17, 2026 Mar 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks again...Show more |
1Parseplatform 1Parse Server Jun 17, 2026 Mar 12, 2022 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects Parse Server in the default configurati...Show more |
diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then...Show more |
A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior to 2.60. This vulnerability could be remotely exploited to allow an at...Show more |
An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159). |
Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before rendering. An authenticated user with the permissions to create, modify and d...Show more |
1Ibexa 1Ez Platform Kernel Jun 17, 2026 Feb 18, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames. |
4Fedoraproject NetappOracle+1 more10Active Iq Unified Manager FedoraHci+7 moreJun 17, 2026 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input...Show more |
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for an unprivileged user to perform a remote code execution by injecting a groov...Show more |
1Synology 1Diskstation Manager Jun 17, 2026 Feb 7, 2022 N/A· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work flow management in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote authentica...Show more |
3Debian FedoraprojectSymfony3Debian Linux FedoraTwigJun 17, 2026 Feb 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions th...Show more |
1Amd 63Athlon 3050ge Firmware Athlon 3150g FirmwareAthlon 3150ge Firmware+60 moreJun 17, 2026 Feb 4, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits potentially resulting in data leakage. |
1Dell 1Integrated Dell Remote Access Controller 9 Firmware Jun 17, 2026 Jan 25, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial...Show more |
1Ibm 1Websphere Application Server Jun 17, 2026 Jan 25, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerab...Show more |
2Fedoraproject Owncloud2Fedora Owncloud Desktop ClientJun 17, 2026 Jan 15, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution. |
1Ui 1Unifi Network Controller Jun 17, 2026 Jan 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a malicious actor to control the application. |
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with access to the backend is able to execute PHP code by using t...Show more |
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with "create, modify and delete website pages" privileges in the...Show more |