CWE-74
5,289 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (5,289)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Envoyproxy Redhat2Envoy Openshift Service MeshJun 17, 2026 Apr 25, 2019 N/A· v4 8.3 HIGH· v3 7.5 HIGH· v2 When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially...Show more |
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote cod...Show more |
IBM Cloud Private 3.1.0 and 3.1.1 is vulnerable to HTTP HOST header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vu...Show more |
AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier allows remote attackers to inject HTML into the scoping dashboard features. |
An injection issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14. |
An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("' followed by the command. |
1Papercut 2Papercut Mf Papercut NgJun 17, 2026 Feb 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163. |
1Cisco 2Webex Business Suite Webex Meetings OnlineJun 17, 2026 Feb 7, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in Cisco Webex Business Suite could allow an unauthenticated, remote attacker to inject arbitrary text into a user's browser. The vulnerability is due to improper validation of input. An attacker could ex...Show more |
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the server. |
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote code on the server. |
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within t...Show more |
Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject a custom Log message provided by the attacker in the 'log' view page, a...Show more |
A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype. |
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype. |
A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype. |
1Just Extend Project 1Just Extend Nov 21, 2024 Feb 1, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A prototype pollution vulnerability was found in just-extend <4.0.0 that allows attack to inject properties onto Object.prototype through its functions. |
1Defaults Deep Project 1Defaults Deep Nov 21, 2024 Feb 1, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A prototype pollution vulnerability was found in defaults-deep <=0.2.4 that would allow a malicious user to inject properties onto Object.prototype. |
CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI. |
4Canonical DebianDjangoproject+1 more4Debian Linux DjangoFedora+1 moreJun 17, 2026 Jan 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found()...Show more |
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature. |