← Back
CWE-74

5,001 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

JSON object

Loading...

CVEs (5,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
1Gitlab
Jun 17, 2026
Jul 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE
1Machform
1Machform
Jun 17, 2026
Jun 29, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers. This could cause a victim to receive malformed content.
1Nodemailer
1Nodemailer
Jun 17, 2026
Jun 29, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.
1Ibm
1Security Identity Manager Adapter
Jun 17, 2026
Jun 28, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and takeover...Show more
IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and takeover other accounts. IBM X-Force ID: 199252.Show less
1Ibm
1Security Verify
Jun 17, 2026
Jun 25, 2021
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to co...Show more
IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijackingShow less
1Mozilla
2Firefox
Firefox Esr
Jun 17, 2026
Jun 24, 2021
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. (A related vulnerability, Spec...Show more
A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. (A related vulnerability, Speculative Code Store Bypass (SCSB), did not affect Firefox.). This vulnerability affects Firefox ESR < 78.9 and Firefox < 87.Show less
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Jun 24, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. This vulnerability affe...Show more
When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.Show less
1Synology
2Diskstation Manager
Diskstation Manager Unified Controller
Jun 17, 2026
Jun 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remo...Show more
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file sharing management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors.Show less
1Synology
2Diskstation Manager
Diskstation Manager Unified Controller
Jun 17, 2026
Jun 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3...Show more
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in Security Advisor report management component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to read arbitrary files via unspecified vectors.Show less
1Google
1Android
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. This could lead to local escalation of privilege with User execution privileges needed. User intera...Show more
In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169936038Show less
1Google
1Android
Jun 17, 2026
Jun 22, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation. This could lead to remote denial of service with no additional execution...Show more
In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-180518039Show less
1Google
1Android
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interac...Show more
In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179461812Show less
1Weseek
1Growi
Jun 17, 2026
Jun 22, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors.
1Greenbone
2Greenbone Os
Greenbone Security Assistant
Nov 21, 2024
Jun 21, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.
1Ibm
1Db2
Jun 17, 2026
Jun 16, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID...Show more
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.Show less
1Thalesgroup
1Safenet Keysecure
Jul 9, 2026
Jun 16, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response,...Show more
SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked.Show less
1Canonical
1Apport
Jun 17, 2026
Jun 11, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.
1Sap
1Infrabox
Jun 17, 2026
Jun 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This could partially impact the confidentiality of the application.
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Jun 7, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
1Chiyu Tech
3Bf 430 Firmware
Bf 431 FirmwareBf 450m Firmware
Jun 17, 2026
Jun 4, 2021
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validation on the parameter redirect= available on multiple CGI components.