← Back
CWE-74

4,976 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

JSON object

Loading...

CVEs (4,976)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Status
1Statusnet
Nov 21, 2024
Feb 7, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.
1Zabbix
1Zabbix
Nov 21, 2024
Feb 7, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.
1Cisco
1Linksys E4200 Firmware
Nov 21, 2024
Feb 4, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the a...Show more
Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type parameter.Show less
1Apereo
1Opencast
Jun 17, 2026
Jan 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be problematic for operation and security since such identifiers are sometimes used for file system ope...Show more
Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be problematic for operation and security since such identifiers are sometimes used for file system operations which may lead to an attacker being able to escape working directories and write files to other locations. In addition, Opencast's Id.toString(…) vs Id.compact(…) behavior, the latter trying to mitigate some of the file system problems, can cause errors due to identifier mismatch since an identifier may unintentionally change. This issue is fixed in Opencast 7.6 and 8.1.Show less
1Bitdefender
1Antivirus
Jun 17, 2026
Jan 30, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A vulnerability in the AntivirusforMac binary as used in Bitdefender Antivirus for Mac allows an attacker to inject a library using DYLD environment variable to cause third-party code execution
1Vtiger
1Vtiger Crm
Nov 21, 2024
Jan 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
1Vtiger
1Vtiger Crm
Nov 21, 2024
Jan 28, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.
2Fedoraproject
Module Metadata Project
2Fedora
Module Metadata
Nov 21, 2024
Jan 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.
1Zend
1Zend Framework
Nov 21, 2024
Jan 27, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splittin...Show more
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.Show less
1Webcalendar Project
1Webcalendar
Nov 21, 2024
Jan 27, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Local file inclusion in WebCalendar before 1.2.5.
1Webcalendar Project
1Webcalendar
Nov 21, 2024
Jan 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.
1Tiki
1Tiki
Nov 21, 2024
Jan 27, 2020
N/A· v4
7.2 HIGH· v3
6.0 MEDIUM· v2
Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.
3Apereo
DebianFedoraproject
5.net Cas Client
Debian LinuxFedora+2 more
Nov 21, 2024
Jan 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow rem...Show more
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.Show less
1Peerigon
1Angular Expressions
Jun 17, 2026
Jan 24, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Angular Expressions before version 1.0.1 has a remote code execution vulnerability if you call expressions.compile(userControlledInput) where userControlledInput is text that comes from user input. If running angular-exp...Show more
Angular Expressions before version 1.0.1 has a remote code execution vulnerability if you call expressions.compile(userControlledInput) where userControlledInput is text that comes from user input. If running angular-expressions in the browser, an attacker could run any browser script when the application code calls expressions.compile(userControlledInput). If running angular-expressions on the server, an attacker could run any Javascript expression, thus gaining Remote Code Execution.Show less
1Twitter
1Secure Headers
Jun 17, 2026
Jan 23, 2020
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1.0, and 6.2.0. If user-supplied input was passed into append/override_content_security_policy_direct...Show more
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1.0, and 6.2.0. If user-supplied input was passed into append/override_content_security_policy_directives, a semicolon could be injected leading to directive injection. This could be used to e.g. override a script-src directive. Duplicate directives are ignored and the first one wins. The directives in secure_headers are sorted alphabetically so they pretty much all come before script-src. A previously undefined directive would receive a value even if SecureHeaders::OPT_OUT was supplied. The fixed versions will silently convert the semicolons to spaces and emit a deprecation warning when this happens. This will result in innocuous browser console messages if being exploited/accidentally used. In future releases, we will raise application errors resulting in 500s. Depending on what major version you are using, the fixed versions are 6.2.0, 5.1.0, 3.8.0.Show less
1Twitter
1Secure Headers
Jun 17, 2026
Jan 23, 2020
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0. If user-supplied input was passed into append/override_content_security_policy_direct...Show more
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0. If user-supplied input was passed into append/override_content_security_policy_directives, a newline could be injected leading to limited header injection. Upon seeing a newline in the header, rails will silently create a new Content-Security-Policy header with the remaining value of the original string. It will continue to create new headers for each newline. This has been fixed in 6.3.0, 5.2.0, and 3.9.0.Show less
1Adobe
1Experience Manager
Jun 17, 2026
Jan 15, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
1Spamdyke
1Spamdyke
Nov 21, 2024
Jan 15, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
spamdyke prior to 4.2.1: STARTTLS reveals plaintext
3Bsd Mailx Project
DebianRedhat
8Bsd Mailx
Debian LinuxEnterprise Linux Desktop+5 more
Nov 21, 2024
Jan 14, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.