CWE-74
4,976 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (4,976)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype. |
A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype. |
1Just Extend Project 1Just Extend Nov 21, 2024 Feb 1, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions. |
1Defaults Deep Project 1Defaults Deep Nov 21, 2024 Feb 1, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype. |
CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI. |
4Canonical DebianDjangoproject+1 more4Debian Linux DjangoFedora+1 moreJun 17, 2026 Jan 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found()...Show more |
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature. |
esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in ESI directive with user specified XSLT th...Show more |
Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation item. |
Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat README.md" command when \e}pn is used. A popmedia control sequence can allow the malicious execution...Show more |
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to...Show more |
IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain. IBM X-Force ID: 152456. |
Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter. |
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution. |
IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hos...Show more |
1Lenovo 39E42 80 Firmware E42 80 Isk FirmwareE52 80 Firmware+36 moreJun 17, 2026 Jul 19, 2018 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code. |
1Ibm 1Rational Quality Manager Nov 21, 2024 Jul 10, 2018 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server t...Show more |
1Adobe 2Acrobat Dc Acrobat Reader DcNov 21, 2024 Jul 9, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an XFA '\n' POST injection vulnerability. Successful exploitation could lead to a security byp...Show more |
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to send a malicious packet to the management interface on an affected system and execute a command-injection exp...Show more |
3Debian MozillaRedhat8Debian Linux Enterprise LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jun 11, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2. |