← Back
CWE-74

4,976 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

JSON object

Loading...

CVEs (4,976)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ep Imageconvert Project
1Ep Imageconvert
Nov 21, 2024
Jan 10, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability
1Tinywebgallery
1Tinywebgallery
Nov 21, 2024
Jan 9, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file.
2Kemptechnologies
Progress
2Loadmaster
Loadmaster
Jul 13, 2026
Jan 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).
1Dlink
14Dir 818lx Firmware
Dir 822 FirmwareDir 823 Firmware+11 more
Jun 17, 2026
Jan 2, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.
1Fibranet
1Monitorix
Nov 21, 2024
Dec 31, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the URI.
2Apache
Oracle
2Primavera Unifier
Solr
Jun 17, 2026
Dec 30, 2019
N/A· v4
7.5 HIGH· v3
4.6 MEDIUM· v2
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or...Show more
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).Show less
1Jetbrains
1Ktor
Jun 17, 2026
Dec 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
1Feature Project
1Feature
Nov 21, 2024
Dec 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
File injection vulnerability in Ruby gem Features 0.3.0 allows remote attackers to inject malicious html in the /tmp directory.
1Appleple
1A Blog Cms
Jun 17, 2026
Dec 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in the context of the application due to unspecified vectors.
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraLeap+3 more
Jun 17, 2026
Dec 23, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabiliti...Show more
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.Show less
1Apple
1Shazam
Jun 17, 2026
Dec 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript c...Show more
An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.Show less
1Egain
1Mail
Jun 17, 2026
Dec 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstrated by fromName header injection with a %0a or %0d character. (Also, th...Show more
The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstrated by fromName header injection with a %0a or %0d character. (Also, the message parameter can have initial HTML comment characters.)Show less
1Microsoft
1Skype For Business
Jun 17, 2026
Dec 10, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Server Spoofing Vulnerability'.
1Openshift Origin Controller Project
1Openshift Origin Controller
Nov 21, 2024
Dec 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection
1Linecorp
1Armeria
Jun 17, 2026
Dec 6, 2019
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized data is used to popula...Show more
Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized data is used to populate the headers of an HTTP response. This vulnerability has been patched in 0.97.0. Potential impacts of this vulnerability include cross-user defacement, cache poisoning, Cross-site scripting (XSS), and page hijacking.Show less
1Redhat
1Zanata
Nov 21, 2024
Dec 3, 2019
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging
2Linux
Redhat
2Dhcp6c
Enterprise Linux
Nov 21, 2024
Nov 27, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.
3Canonical
DebianHaproxy
3Debian Linux
HaproxyUbuntu Linux
Jun 17, 2026
Nov 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulatio...Show more
The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.Show less
2Debian
Ruby Lang
2Debian Linux
Ruby
Jun 17, 2026
Nov 26, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input into the response header, an attacker can exploit it to insert a newline...Show more
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input into the response header, an attacker can exploit it to insert a newline character to split a header, and inject malicious content to deceive clients. NOTE: this issue exists because of an incomplete fix for CVE-2017-17742, which addressed the CRLF vector, but did not address an isolated CR or an isolated LF.Show less
1Ruby Lang
1Ruby
Nov 21, 2024
Nov 26, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Server headers in requests, which might allow remote attackers to inject a...Show more
Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Server headers in requests, which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.Show less