← Back
CWE-74

5,289 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

JSON object

Loading...

CVEs (5,289)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Envoyproxy
Redhat
2Envoy
Openshift Service Mesh
Jun 17, 2026
Apr 25, 2019
N/A· v4
8.3 HIGH· v3
7.5 HIGH· v2
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially...Show more
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.Show less
1Ea
1Origin
Jun 17, 2026
Apr 19, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote cod...Show more
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication.Show less
1Ibm
1Cloud Private
Nov 21, 2024
Apr 8, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cloud Private 3.1.0 and 3.1.1 is vulnerable to HTTP HOST header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vu...Show more
IBM Cloud Private 3.1.0 and 3.1.1 is vulnerable to HTTP HOST header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 153385.Show less
1Axiomsl
1Axiom
Nov 21, 2024
Apr 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier allows remote attackers to inject HTML into the scoping dashboard features.
1Apple
1Mac Os X
Nov 21, 2024
Apr 3, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An injection issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14.
1Ofcms Project
1Ofcms
Jun 17, 2026
Mar 6, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("' followed by the command.
1Papercut
2Papercut Mf
Papercut Ng
Jun 17, 2026
Feb 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.
1Cisco
2Webex Business Suite
Webex Meetings Online
Jun 17, 2026
Feb 7, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in Cisco Webex Business Suite could allow an unauthenticated, remote attacker to inject arbitrary text into a user's browser. The vulnerability is due to improper validation of input. An attacker could ex...Show more
A vulnerability in Cisco Webex Business Suite could allow an unauthenticated, remote attacker to inject arbitrary text into a user's browser. The vulnerability is due to improper validation of input. An attacker could exploit this vulnerability by convincing a targeted user to view a malicious URL. A successful exploit could allow the attacker to inject arbitrary text into the user's browser. The attacker could use the content injection to conduct spoofing attacks. Versions prior than 3.0.9 are affected.Show less
1Lcds
1Laquis Scada
Nov 21, 2024
Feb 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the server.
1Lcds
1Laquis Scada
Nov 21, 2024
Feb 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote code on the server.
1Ibm
1Bigfix Compliance
Nov 21, 2024
Feb 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within t...Show more
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 123677.Show less
1Zoneminder
1Zoneminder
Jun 17, 2026
Feb 4, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject a custom Log message provided by the attacker in the 'log' view page, a...Show more
Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject a custom Log message provided by the attacker in the 'log' view page, as demonstrated by the message=User%20'admin'%20Logged%20in value.Show less
1Extend Project
1Extend
Nov 21, 2024
Feb 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.
1Dreamerslab
1Node.extend
Nov 21, 2024
Feb 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
1Mpath Project
1Mpath
Nov 21, 2024
Feb 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
1Just Extend Project
1Just Extend
Nov 21, 2024
Feb 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions.
1Defaults Deep Project
1Defaults Deep
Nov 21, 2024
Feb 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype.
1Python
1Pypiserver
Jun 17, 2026
Jan 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.
4Canonical
DebianDjangoproject+1 more
4Debian Linux
DjangoFedora+1 more
Jun 17, 2026
Jan 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found()...Show more
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.Show less
1Getkirby
1Kirby
Nov 21, 2024
Dec 20, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.