← Back
CWE-74

4,976 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

JSON object

Loading...

CVEs (4,976)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ektron
1Ektron Content Management System
May 6, 2026
Feb 14, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attackers to execute arbitrary code via a crafted XSLT document, related to a "resour...Show more
Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attackers to execute arbitrary code via a crafted XSLT document, related to a "resource injection" issue.Show less
1Apereo
1Central Authentication Service
May 6, 2026
Feb 10, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP au...Show more
Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP authentication.Show less
1Symantec
2Encryption Management Server
Pgp Universal Server
May 6, 2026
Feb 1, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID valu...Show more
The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.Show less
2Debian
Rpm
2Debian Linux
Rpm
May 6, 2026
Dec 16, 2014
N/A· v4
N/A· v3
7.6 HIGH· v2
Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrat...Show more
Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the /etc/cron.d directory.Show less
1Arris
1Vap2500 Firmware
May 6, 2026
Nov 28, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown vectors.
3Apache
FujitsuOracle
10Archiva
Gp S FirmwareGp5000 Firmware+7 more
Apr 22, 2026
Jul 20, 2013
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
5Canonical
MozillaOpensuse+2 more
13Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+10 more
Apr 29, 2026
Oct 29, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read...Show more
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.Show less
2Apple
Google
4Chrome
Iphone OsItunes+1 more
Apr 29, 2026
Sep 19, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown ve...Show more
Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."Show less
2Apple
Google
3Chrome
Iphone OsSafari
Apr 29, 2026
Aug 3, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy and conduct script injection attacks via unspecified vectors.
1Frax
1Php Recommend
Apr 23, 2026
May 22, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inject arbitrary PHP code into phpre_config.php via the form_aula parameter.
2Apache
Redhat
4Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+1 more
Apr 23, 2026
Jan 25, 2008
N/A· v4
N/A· v3
2.6 LOW· v2
CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote...Show more
CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.Show less
1Joomla
1Joomla
Apr 23, 2026
Aug 8, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF sequences in the url parameter....Show more
CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF sequences in the url parameter. NOTE: this can be leveraged for cross-site scripting (XSS) attacks. NOTE: some of these details are obtained from third party information.Show less
1Opera
1Opera Browser
Apr 16, 2026
Nov 22, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Opera before 8.51 on Linux and Unix systems allows remote attackers to execute arbitrary code via shell metacharacters (backticks) in a URL that another product provides in a command line argument when launching Opera.
1Opera
1Opera Browser
Apr 16, 2026
Sep 21, 2005
N/A· v4
N/A· v3
2.6 LOW· v2
Opera before 8.50 allows remote attackers to spoof the content type of files via a filename with a trailing "." (dot), which might allow remote attackers to trick users into processing dangerous content.
1Opera
1Opera Browser
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as...Show more
Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.Show less
1Opera
1Opera Browser
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript to read arbitrary files from the client's local filesystem or display a false URL to the user.