← Back
CWE-74

4,976 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

JSON object

Loading...

CVEs (4,976)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dreamerslab
1Node.extend
Nov 21, 2024
Feb 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
1Mpath Project
1Mpath
Nov 21, 2024
Feb 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
1Just Extend Project
1Just Extend
Nov 21, 2024
Feb 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions.
1Defaults Deep Project
1Defaults Deep
Nov 21, 2024
Feb 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype.
1Python
1Pypiserver
Jun 17, 2026
Jan 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.
4Canonical
DebianDjangoproject+1 more
4Debian Linux
DjangoFedora+1 more
Jun 17, 2026
Jan 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found()...Show more
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.Show less
1Getkirby
1Kirby
Nov 21, 2024
Dec 20, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
1Esigate
1Esigate
Nov 21, 2024
Dec 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in ESI directive with user specified XSLT th...Show more
esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in ESI directive with user specified XSLT that can result in Remote Code Execution. This attack appear to be exploitable via Use of another weakness in backend application to reflect ESI directives. This vulnerability appears to have been fixed in 5.3.Show less
1Icinga
1Icinga Web 2
Nov 21, 2024
Dec 17, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation item.
1Enlightenment
1Terminology
Nov 21, 2024
Dec 17, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat README.md" command when \e}pn is used. A popmedia control sequence can allow the malicious execution...Show more
Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat README.md" command when \e}pn is used. A popmedia control sequence can allow the malicious execution of executable file formats registered in the X desktop share MIME types (/usr/share/applications). The control sequence defers unknown file types to the handle_unknown_media() function, which executes xdg-open against the filename specified in the sequence. The use of xdg-open for all unknown file types allows executable file formats with a registered shared MIME type to be executed. An attacker can achieve remote code execution by introducing an executable file and a plain text file containing the control sequence through a fake software project (e.g., in Git or a tarball). When the control sequence is rendered (such as with cat), the executable file will be run.Show less
1Ibm
1Bigfix Platform
Nov 21, 2024
Dec 12, 2018
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to...Show more
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning or cross-site scripting, and possibly obtain sensitive information. IBM X-force ID: 140692.Show less
1Ibm
1Connections
Nov 21, 2024
Dec 7, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain. IBM X-Force ID: 152456.
1Virtualmin
1Virtualmin
Nov 21, 2024
Oct 10, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.
1Thedaylightstudio
1Fuel Cms
Nov 21, 2024
Sep 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
1Ibm
1Campaign
Nov 21, 2024
Sep 7, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hos...Show more
IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 121153.Show less
1Lenovo
39E42 80 Firmware
E42 80 Isk FirmwareE52 80 Firmware+36 more
Jun 17, 2026
Jul 19, 2018
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code.
1Ibm
1Rational Quality Manager
Nov 21, 2024
Jul 10, 2018
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server t...Show more
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 142658.Show less
1Adobe
2Acrobat Dc
Acrobat Reader Dc
Nov 21, 2024
Jul 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an XFA '\n' POST injection vulnerability. Successful exploitation could lead to a security byp...Show more
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an XFA '\n' POST injection vulnerability. Successful exploitation could lead to a security bypass.Show less
1Cisco
1Nx Os
Nov 21, 2024
Jun 21, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to send a malicious packet to the management interface on an affected system and execute a command-injection exp...Show more
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to send a malicious packet to the management interface on an affected system and execute a command-injection exploit. The vulnerability is due to incorrect input validation of user-supplied data to the NX-API subsystem. An attacker could exploit this vulnerability by sending a malicious HTTP or HTTPS packet to the management interface of an affected system that has the NX-API feature enabled. A successful exploit could allow the attacker to execute arbitrary commands with root privileges. Note: NX-API is disabled by default. This vulnerability affects MDS 9000 Series Multilayer Switches, Nexus 2000 Series Fabric Extenders, Nexus 3000 Series Switches, Nexus 3500 Platform Switches, Nexus 5500 Platform Switches, Nexus 5600 Platform Switches, Nexus 6000 Series Switches, Nexus 7000 Series Switches, Nexus 7700 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 9500 R-Series Line Cards and Fabric Modules. Cisco Bug IDs: CSCvd47415, CSCve03216, CSCve03224, CSCve03234.Show less
3Debian
MozillaRedhat
8Debian Linux
Enterprise LinuxEnterprise Linux Desktop+5 more
Nov 21, 2024
Jun 11, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.