CWE-74
5,001 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (5,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vmware 3Cloud Foundation Vrealize Log InsightVrealize Suite Lifecycle ManagerJun 17, 2026 Oct 13, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges m...Show more |
1Cybozu 1Remote Service Manager Jun 17, 2026 Oct 13, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product. |
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries. |
Hygeia is an application for collecting and processing personal and case data in connection with communicable diseases. In affected versions all CSV Exports (Statistics & BAG MED) contain a CSV Injection Vulnerability. U...Show more |
1Axis 4Axis Os Axis Os 2016Axis Os 2018+1 moreJun 17, 2026 Oct 5, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the ge...Show more |
Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary. |
Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary. |
1Aviatorscript Project 1Aviatorscript Jun 17, 2026 Oct 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (BCEL). |
http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request-splitting attacks when untrusted user input is used to create any of the following fields: Hea...Show more |
IBM PowerVM Hypervisor FW860, FW930, FW940, and FW950 could allow a local user to create a specially crafted sequence of hypervisor calls from a partition that could crash the system. IBM X-Force ID: 203557. |
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openE...Show more |
1Ericsson 1Enterprise Content Management Jun 17, 2026 Sep 17, 2021 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection. |
1Netgear 20Gc108p Firmware Gc108pp FirmwareGs108t Firmware+17 moreJun 17, 2026 Sep 16, 2021 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the authentication scheme - allows the attacker to create (or overwrite) a file with...Show more |
GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in ver...Show more |
An injection issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. A malicious application may be able to gain root p...Show more |
1Sonatype 1Nexus Repository Manager 3 Jun 17, 2026 Sep 7, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vuln...Show more |
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version 4.10.3, Parse Server crashes when if a query request contains an invalid value for the `explain` op...Show more |
HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject arbitrary JavaScript into the speaker-notes of the slide-mode feature by embedding an iframe hosting...Show more |
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files. |
2Mock Server Oracle2Communications Cloud Native Core Policy MockserverJun 17, 2026 Aug 16, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim into visiting a malicious site while running MockServer locally, will...Show more |