CWE-74
5,001 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (5,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric,...Show more |
The dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. |
An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an attacker to perform any action with the pr...Show more |
2Fedoraproject Nextcloud2Desktop FedoraJun 17, 2026 Apr 14, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation. |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Apr 6, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries. |
A stored HTML injection vulnerability exists in Knowage Suite version 7.1. An attacker can inject arbitrary HTML in "/restful-services/2.0/analyticalDrivers" via the 'LABEL' and 'NAME' parameters. |
vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted source-code repository containing malicious settings. An attacker who suc...Show more |
Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in different places and can be leveraged to execute arbitrary commands. An attac...Show more |
In FreeBSD 12.2-STABLE before r365730, 11.4-STABLE before r365738, 12.1-RELEASE before p10, 11.4-RELEASE before p4, and 11.3-RELEASE before p14, a programming error in the ure(4) device driver caused some Realtek USB Eth...Show more |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Mar 26, 2021 N/A· v4 6.1 MEDIUM· v3 2.6 LOW· v2 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the notification emails se...Show more |
app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets...Show more |
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a...Show more |
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticate...Show more |
In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in Ma...Show more |
2Debian Shibboleth2Debian Linux Service ProviderJun 17, 2026 Mar 22, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters. |
1Atlassian 4Data Center JiraJira Data Center+1 moreJun 17, 2026 Mar 22, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project keys via an Information Disclosure vulnerability in the /rest/api/1.0/is...Show more |
Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization. |
1Ciphercoin 1Contact Form 7 Database Addon Jun 17, 2026 Mar 18, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files. |
IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which could impact support and development efforts. IBM X-Force ID: 190450. |
3Debian OracleWireshark3Debian Linux WiresharkZfs Storage ApplianceJun 17, 2026 Mar 15, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file. |