← Back
CWE-74

4,976 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

JSON object

Loading...

CVEs (4,976)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
8.1 HIGH· v3
6.5 MEDIUM· v2
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
7.3 HIGH· v3
4.9 MEDIUM· v2
In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).
1Inveniosoftware
1Invenio App
Jun 17, 2026
Jul 29, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
invenio-app before 1.1.1 allows host header injection.
4Debian
MozillaNovell+1 more
6Debian Linux
FirefoxFirefox Esr+3 more
Jun 17, 2026
Jul 23, 2019
N/A· v4
8.3 HIGH· v3
5.1 MEDIUM· v2
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects...Show more
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.Show less
2Mozilla
Opensuse
2Firefox
Leap
Jun 17, 2026
Jul 23, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information...Show more
Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stream, such as browsing history, if the Snipper Service were compromised. This vulnerability affects Firefox < 68.Show less
1B3log
1Wide
Jun 17, 2026
Jul 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in the editor, and compile and run it approximately three times to read an arbitrary file. Second, the a...Show more
b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in the editor, and compile and run it approximately three times to read an arbitrary file. Second, the attacker can create a symlink, and then place the symlink into a ZIP archive. An unzip operation leads to read access, and write access (depending on file permissions), to the symlink target. Third, the attacker can import a Git repository that contains a symlink, similarly leading to read and write access.Show less
1Glpi Project
1Glpi
Jun 17, 2026
Jul 12, 2019
N/A· v4
3.5 LOW· v3
3.5 LOW· v2
GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / c...Show more
GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The component is: Tools > Reminder > Description .. Set the description to any iframe/form tags and apply. The attack vector is: The attacker puts a login form, the user fills it and clicks on submit .. the request is sent to the attacker domain saving the data. The fixed version is: 9.4.1.Show less
1Sap
2Gateway
Ui5
Jun 17, 2026
Jul 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form of an error message. An attacker could thus mislead a user to believe this information is from the l...Show more
The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form of an error message. An attacker could thus mislead a user to believe this information is from the legitimate service when it's not.Show less
1Field Test Project
1Field Test
Jun 17, 2026
Jul 9, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input, which can be dangerous depending on how applications...Show more
The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input, which can be dangerous depending on how applications use it. If an application treats arbitrary variants as trusted, this can lead to a variety of potential vulnerabilities like SQL injection or cross-site scripting (XSS).Show less
1Logitech
5K360 Firmware
K400r FirmwareK750 Firmware+2 more
Nov 21, 2024
Jun 29, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.
1Fehelper Project
1Fehelper
Jun 17, 2026
Jun 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FeHelper through 2019-06-19 allows arbitrary code execution during a JSON format operation, as demonstrated by the {"a":(function(){confirm(1)})()} input.
3Debian
OpensuseRubygems
3Debian Linux
LeapRubygems
Jun 17, 2026
Jun 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence inj...Show more
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.Show less
3Debian
OpensuseRubygems
3Debian Linux
LeapRubygems
Jun 17, 2026
Jun 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occ...Show more
An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.Show less
3Debian
OpensuseRubygems
3Debian Linux
LeapRubygems
Jun 17, 2026
Jun 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)
1Sap
5Advanced Business Application Programming Platform Kernel
Advanced Business Application Programming Platform Krnl32nucAdvanced Business Application Programming Platform Krnl32uc+2 more
Jun 17, 2026
Jun 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT...Show more
FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.45, 7.49, 7.53, 7.73, allows an attacker to inject code or specifically manipulated command that can be executed by the application. An attacker could thereby control the behaviour of the application.Show less
4Canonical
FedoraprojectOracle+1 more
5Fedora
SolarisTwisted+2 more
Jun 17, 2026
Jun 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.