CWE-74
5,292 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (5,292)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be problematic for operation and security since such identifiers are sometimes used for file system ope...Show more |
A vulnerability in the AntivirusforMac binary as used in Bitdefender Antivirus for Mac allows an attacker to inject a library using DYLD environment variable to cause third-party code execution |
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'. |
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code. |
2Fedoraproject Module Metadata Project2Fedora Module MetadataNov 21, 2024 Jan 28, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value. |
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splittin...Show more |
1Webcalendar Project 1Webcalendar Nov 21, 2024 Jan 27, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Local file inclusion in WebCalendar before 1.2.5. |
1Webcalendar Project 1Webcalendar Nov 21, 2024 Jan 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter. |
Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters. |
3Apereo DebianFedoraproject5.net Cas Client Debian LinuxFedora+2 moreNov 21, 2024 Jan 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow rem...Show more |
Angular Expressions before version 1.0.1 has a remote code execution vulnerability if you call expressions.compile(userControlledInput) where userControlledInput is text that comes from user input. If running angular-exp...Show more |
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1.0, and 6.2.0. If user-supplied input was passed into append/override_content_security_policy_direct...Show more |
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0. If user-supplied input was passed into append/override_content_security_policy_direct...Show more |
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Successful exploitation could lead to sensitive information disclosure. |
spamdyke prior to 4.2.1: STARTTLS reveals plaintext |
3Bsd Mailx Project DebianRedhat8Bsd Mailx Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jan 14, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address. |
1Ep Imageconvert Project 1Ep Imageconvert Nov 21, 2024 Jan 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability |
PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file. |
2Kemptechnologies Progress2Loadmaster LoadmasterJul 13, 2026 Jan 8, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI). |
1Dlink 14Dir 818lx Firmware Dir 822 FirmwareDir 823 Firmware+11 moreJun 17, 2026 Jan 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php. |