CWE-74
5,292 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (5,292)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the URI. |
2Apache Oracle2Primavera Unifier SolrJun 17, 2026 Dec 30, 2019 N/A· v4 7.5 HIGH· v3 4.6 MEDIUM· v2 Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or...Show more |
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting. |
File injection vulnerability in Ruby gem Features 0.3.0 allows remote attackers to inject malicious html in the /tmp directory. |
a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in the context of the application due to unspecified vectors. |
6Canonical DebianFedoraproject+3 more7Debian Linux FedoraLeap+4 moreAug 17, 2026 Dec 23, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabiliti...Show more |
An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript c...Show more |
The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstrated by fromName header injection with a %0a or %0d character. (Also, th...Show more |
A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Server Spoofing Vulnerability'. |
1Openshift Origin Controller Project 1Openshift Origin Controller Nov 21, 2024 Dec 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection |
Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized data is used to popula...Show more |
Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging |
2Linux Redhat2Dhcp6c Enterprise LinuxNov 21, 2024 Nov 27, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message. |
3Canonical DebianHaproxy3Debian Linux HaproxyUbuntu LinuxJun 17, 2026 Nov 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulatio...Show more |
2Debian Ruby Lang2Debian Linux RubyJun 17, 2026 Nov 26, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input into the response header, an attacker can exploit it to insert a newline...Show more |
Various methods in WEBrick::HTTPRequest in Ruby 1.9.2 and 1.8.7 and earlier do not validate the X-Forwarded-For, X-Forwarded-Host and X-Forwarded-Server headers in requests, which might allow remote attackers to inject a...Show more |
1Ibm 1Smartcloud Analytics Log Analysis Jun 17, 2026 Nov 22, 2019 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 IBM SmartCloud Analytics 1.3.1 through 1.3.5 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM X-Force ID: 159187. |
1Redhat 2Edeploy Jboss Enterprise Web ServerNov 21, 2024 Nov 21, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data |
2Debian Freedesktop2Debian Linux PopplerNov 21, 2024 Nov 13, 2019 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack. |
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony framework allows service identifiers to be derived from user cont...Show more |