← Back
CWE-74

5,001 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

JSON object

Loading...

CVEs (5,001)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sylius
1Syliusresourcebundle
Jun 17, 2026
Aug 20, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized properly. This allows th...Show more
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized properly. This allows the attacker to access any public service by manipulating that request parameter, allowing for Remote Code Execution. This issue has been patched for versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4. Versions prior to 1.3 were not patched.Show less
1Nim Lang
1Nim
Jun 17, 2026
Aug 14, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is possible if the attacker controls any part of the URL provided in a call (such as httpClient.get or http...Show more
In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is possible if the attacker controls any part of the URL provided in a call (such as httpClient.get or httpClient.post), the User-Agent header value, or custom HTTP header names or values.Show less
1Vng
1Zalo Desktop
Jun 17, 2026
Aug 13, 2020
N/A· v4
8.6 HIGH· v3
9.3 HIGH· v2
An issue was discovered in Zalo.exe in VNG Zalo Desktop 19.8.1.0. An attacker can run arbitrary commands on a remote Windows machine running the Zalo client by sending the user of the device a crafted file.
1Vbulletin
1Vbulletin
Jun 17, 2026
Aug 12, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-1675...Show more
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.Show less
1Chartkick Project
1Chartkick
Jun 17, 2026
Aug 5, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute).
1Beronet
1Voice Over Internet Protocol Gateways Firmware
Nov 21, 2024
Jul 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with credentials.
1Encode
1Uvicorn
Jun 17, 2026
Jul 27, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP headers. Attackers can exploit this to add arbitrary headers to HTTP responses, or even return an arbitr...Show more
Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP headers. Attackers can exploit this to add arbitrary headers to HTTP responses, or even return an arbitrary response body, whenever crafted input is used to construct HTTP headers.Show less
4Debian
FedoraprojectLibetpan Project+1 more
4Debian Linux
FedoraLibetpan+1 more
Jun 17, 2026
Jul 27, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional da...Show more
LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."Show less
1Gofiber
1Fiber
Jun 17, 2026
Jul 20, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is not escaped, and therefore vulnerable for a CRLF injection attack. I.e. an attacker could upload a...Show more
In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is not escaped, and therefore vulnerable for a CRLF injection attack. I.e. an attacker could upload a custom filename and then give the link to the victim. With this filename, the attacker can change the name of the downloaded file, redirect to another site, change the authorization header, etc. A possible workaround is to serialize the input before passing it to ctx.Attachment().Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
Evolution Data ServerFedora+1 more
Jun 17, 2026
Jul 17, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response...Show more
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."Show less
1Advantech
1Iview
Jun 17, 2026
Jul 15, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to se...Show more
Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command string without any validation. The attacker may then remotely execute code.Show less
1Traccar
1Traccar
Jun 17, 2026
Jul 14, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerability. It occurs when user input is being used in LDAP search filter. By providing specially crafted input, an attacker can modify the logic of...Show more
Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerability. It occurs when user input is being used in LDAP search filter. By providing specially crafted input, an attacker can modify the logic of the LDAP query and get admin privileges. The issue only impacts instances with LDAP configuration and where users can craft their own names. This has been patched in version 4.9.Show less
1Dlink
1Dir 610 Firmware
Jun 17, 2026
Jul 9, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
2Apache
Oracle
4Camel
Communications Diameter Signaling RouterEnterprise Manager Base Platform+1 more
Jun 17, 2026
Jul 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
1Code42
1Code42
Jun 17, 2026
Jul 7, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an administrator creates a local (non-SSO) user via a Code42-generated email, the administrator has th...Show more
Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an administrator creates a local (non-SSO) user via a Code42-generated email, the administrator has the option to modify content for the email invitation. If the administrator entered template language code in the subject line, that code could be interpreted by the email generation services, potentially resulting in server-side code injection.Show less
1Atlassian
2Confluence
Confluence Server
Jun 17, 2026
Jul 1, 2020
N/A· v4
4.7 MEDIUM· v3
6.5 MEDIUM· v2
Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom...Show more
Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros. The affected versions are before version 7.4.5, and from version 7.5.0 before 7.5.1.Show less
5Canonical
FedoraprojectLinuxfoundation+2 more
6Ceph
Ceph StorageFedora+3 more
Jun 17, 2026
Jun 26, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the...Show more
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.Show less
1Traceroute Project
1Traceroute
Nov 21, 2024
Jun 25, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is...Show more
The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.Show less
3Canonical
DebianGnu
3Debian Linux
MailmanUbuntu Linux
Jun 17, 2026
Jun 24, 2020
N/A· v4
4.3 MEDIUM· v3
2.6 LOW· v2
GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.
1Atlassian
2Jira
Jira Software Data Center
Jun 17, 2026
Jun 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template inj...Show more
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.Show less