CWE-74
4,976 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (4,976)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apache Oracle3Financial Services Market Risk Measurement And Management Peoplesoft Enterprise PeopletoolsSynapseMay 13, 2026 Dec 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution...Show more |
lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a c...Show more |
1Sensible Utils Project 1Sensible Utils May 13, 2026 Dec 11, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks v...Show more |
Opencast 2.3.2 and older versions are vulnerable to script injections through media and metadata in the player and media module resulting in arbitrary code execution, fixed in 2.3.3 and 3.0. |
1Moxa 3Nport 5110 Firmware Nport 5130 FirmwareNport 5150 FirmwareMay 13, 2026 Nov 16, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Injection issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacke...Show more |
2Debian Mediawiki2Debian Linux MediawikiMay 13, 2026 Nov 15, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability. |
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization is vulnerable to an injection attack where a carefully crafted username could impersonate another u...Show more |
1Inboundnow 1Wordpress Landing Pages May 13, 2026 Oct 18, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter. |
1Redhat 1Enterprise Virtualization Manager May 13, 2026 Sep 25, 2017 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in t...Show more |
The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task. |
AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability. |
The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerability in the way that the WebPlayer works. IBM X-Force ID: 113993. |
1Sma 39Sunny Boy 1.5 Firmware Sunny Boy 2.5 FirmwareSunny Boy 3.0 Firmware+36 moreMay 13, 2026 Aug 5, 2017 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 An issue was discovered in SMA Solar Technology products. The SIP implementation does not properly use authentication with encryption: it is vulnerable to replay attacks, packet injection attacks, and man in the middle a...Show more |
1Cisco 2Web Security Appliance Web Security Virtual ApplianceMay 13, 2026 Jul 25, 2017 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The attacker must authenticate with va...Show more |
1Biscom 1Secure File Transfer May 13, 2026 Jul 18, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in double curly-braces ({{ }...Show more |
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions. |
ntopng before 3.0 allows HTTP Response Splitting. |
1Mimosa 2Backhaul Radios Client RadiosMay 13, 2026 May 21, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4. On the backend of the device's web interface, there are some diagnostic tests available that are not displayed on the...Show more |
1Mimosa 2Backhaul Radios Client RadiosMay 13, 2026 May 21, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. In the device's web interface, after logging in, there is a page that allows you to ping other hosts from the device a...Show more |
A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. An "improper neutralization of HTTP headers for scripting syntax" issue has been identified, which may allow remote code execu...Show more |