CWE-74
4,976 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (4,976)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Smartcloud Analytics Log Analysis Jun 17, 2026 Nov 22, 2019 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 IBM SmartCloud Analytics 1.3.1 through 1.3.5 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM X-Force ID: 159187. |
1Redhat 2Edeploy Jboss Enterprise Web ServerNov 21, 2024 Nov 21, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data |
2Debian Freedesktop2Debian Linux PopplerNov 21, 2024 Nov 13, 2019 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack. |
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony framework allows service identifiers to be derived from user cont...Show more |
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secure download feature jumpurl. |
TWiki allows arbitrary shell command execution via the Include function |
ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function. |
1Cisco 1Telepresence Video Communication Server Nov 21, 2024 Oct 29, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to execute arbitrary commands. |
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to perform further attacks, such as Web Cac...Show more |
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerabilit...Show more |
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib...Show more |
2Cloudfoundry Pivotal Software2Cf Deployment Cloud Foundry UaaJun 17, 2026 Oct 23, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content whic...Show more |
An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers lack HTTP control characters. Thus, if untrusted data is used to constru...Show more |
A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by providing malicious output to the terminal. This affects versions of iTerm2...Show more |
A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spectrum Scale V4.2.0.0 through V4.2.3.17 that could allow a local attacker to obtain root privilege by i...Show more |
1Cisco 1Unified Contact Center Express Jun 17, 2026 Oct 2, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validat...Show more |
PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content. |
2Pivotal Pivotal Software2Apps Manager Pivotal Application ServiceJun 17, 2026 Oct 1, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain...Show more |
An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections. |
1Cloudfoundry 2Cf Deployment Nfs Volume ReleaseJun 17, 2026 Sep 23, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via...Show more |