← Back
CWE-74

5,289 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

JSON object

Loading...

CVEs (5,289)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qualcomm
30Mdm9206 Firmware
Mdm9607 FirmwareMdm9615 Firmware+27 more
Nov 21, 2024
Apr 18, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, MDM9645, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/S...Show more
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, MDM9645, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SDM630, SDM636, SDM660, and Snapdragon_High_Med_2016, stopping of the DTR prematurely causes micro kernel to be stuck. This can be triggered with a timing change injectable in RACH procedure.Show less
1Openwebanalytics
1Open Web Analytics
Nov 21, 2024
Apr 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Open Web Analytics (OWA) before 1.5.7 allows remote attackers to conduct PHP object injection attacks via a crafted serialized object in the owa_event parameter to queue.php.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
1Mcafee
6Anti Virus Plus
Endpoint SecurityHost Intrusion Prevention+3 more
Nov 21, 2024
Apr 3, 2018
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulatio...Show more
Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters.Show less
1Ibm
1Tivoli Directory Server
Nov 21, 2024
Apr 3, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 37 and IBM Security Directory Server 6.3.1 before iFix 11 and 6.4 before...Show more
The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 37 and IBM Security Directory Server 6.3.1 before iFix 11 and 6.4 before iFix 2 allows local users to gain privileges via vectors related to argument injection. IBM X-Force ID: 103694.Show less
1Apple
1Mac Os X
Nov 21, 2024
Apr 3, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the Bracketed Paste Mode of the "Terminal" component. It allows user-assisted attackers to inject arbitrary commands...Show more
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the Bracketed Paste Mode of the "Terminal" component. It allows user-assisted attackers to inject arbitrary commands within pasted content.Show less
1Apache
1Allura
Nov 21, 2024
Mar 15, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial for the victim's bro...Show more
In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial for the victim's browsing session.Show less
1Trendmicro
1Email Encryption Gateway
Jun 17, 2026
Mar 15, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to gaining code execution on vulnerable systems.
1Jolokia
1Webarchive Agent
Nov 21, 2024
Mar 14, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
1Elastic
1Elasticsearch
Nov 21, 2024
Mar 6, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnera...Show more
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerabilityShow less
1Samsung
2Knox Enterprise Mobility Management
Knox Identity Access Management
Nov 21, 2024
Feb 20, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's...Show more
In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's knowledge) by inspecting network traffic from a Samsung server and injecting content at a certain point in the update sequence. This installed application can further leak information stored inside the Knox container to the outside world.Show less
1Hp
1Opencall Media Platform
Nov 21, 2024
Feb 15, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).
1Myrepos Project
1Myrepos
Jun 17, 2026
Feb 14, 2018
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for arbitrary code execution, as demonstrate...Show more
webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for arbitrary code execution, as demonstrated by an "ext::sh -c" attack or an option injection attack.Show less
1Promise
1Webpam Proe
Jun 17, 2026
Feb 7, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injection attacks via JavaScript code in a PHPSESSID cookie.
1Kaspersky
1Secure Mail Gateway
Jun 17, 2026
Feb 6, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
2Debian
Simplesamlphp
2Debian Linux
Saml2
Jun 17, 2026
Feb 2, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.
1Wondercms
1Wondercms
Nov 21, 2024
Jan 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local m...Show more
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as a self attackShow less
1Silverstripe
1Silverstripe
Nov 21, 2024
Jan 23, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into co...Show more
In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For example, the CSV data may contain untrusted user input from the "First Name" field of a user's /myprofile page.Show less
1Trendmicro
1Smart Protection Server
Nov 21, 2024
Jan 19, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a cron job injection on a vulnerable system.
1Google
1Android
Nov 21, 2024
Jan 12, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveraging failure to filter application data streams.