CWE-74
5,001 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (5,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the capability for administrators to write and...Show more |
3Debian FedoraprojectFlatpak3Debian Linux FedoraFlatpakJun 17, 2026 Mar 11, 2021 N/A· v4 8.2 HIGH· v3 5.8 MEDIUM· v2 Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which ca...Show more |
Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison...Show more |
GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is a vulnerability in the /ajax/common....Show more |
Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty` option of the pug compiler, e.g. if you spread a user provided object...Show more |
Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later. |
1Sercomm 1Agcombo Vd625 Firmware Jul 9, 2026 Feb 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header. |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request. |
1Atlassian 1Jira Server For Slack Jun 17, 2026 Feb 22, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via a template injection vulnerability. |
1Atlassian 1Alfresco Enterprise Content Management Jun 17, 2026 Feb 19, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system comma...Show more |
1Less Openui5 Project 1Less Openui5 Jun 17, 2026 Feb 16, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10., when processing theming resources (i.e. `*.less` files) with less-openui5 that originate from an un...Show more |
1Mbconnectline 2Mbconnect24 Mymbconnect24Jun 17, 2026 Feb 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malicious user input of active code. |
CITSmart before 9.1.2.23 allows LDAP Injection. |
1Elecom 1Wrc 1467ghbk A Firmware Jun 17, 2026 Feb 12, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 ELECOM WRC-1467GHBK-A allows arbitrary scripts to be executed on the user's web browser by displaying a specially crafted SSID on the web setup page. |
1Is User Valid Project 1Is User Valid Jun 17, 2026 Feb 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or information exposure. |
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system. |
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy via a crafted HTML page. |
2Google Microsoft2Chrome Edge ChromiumJun 17, 2026 Feb 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page. |
1Carrierwave Project 1Carrierwave Jun 17, 2026 Feb 8, 2021 N/A· v4 8.8 HIGH· v3 7.5 HIGH· v2 CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1, there is a code injection vulnerability. The "#manipu...Show more |
Helm is open-source software which is essentially "The Kubernetes Package Manager". Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. In Helm from version 3.0 and before vers...Show more |