CWE-74
5,289 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (5,289)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Inboundnow 1Wordpress Landing Pages May 13, 2026 Oct 18, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter. |
1Redhat 1Enterprise Virtualization Manager May 13, 2026 Sep 25, 2017 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in t...Show more |
The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task. |
AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability. |
The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerability in the way that the WebPlayer works. IBM X-Force ID: 113993. |
1Sma 39Sunny Boy 1.5 Firmware Sunny Boy 2.5 FirmwareSunny Boy 3.0 Firmware+36 moreMay 13, 2026 Aug 5, 2017 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 An issue was discovered in SMA Solar Technology products. The SIP implementation does not properly use authentication with encryption: it is vulnerable to replay attacks, packet injection attacks, and man in the middle a...Show more |
1Cisco 2Web Security Appliance Web Security Virtual ApplianceMay 13, 2026 Jul 25, 2017 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The attacker must authenticate with va...Show more |
1Biscom 1Secure File Transfer May 13, 2026 Jul 18, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in double curly-braces ({{ }...Show more |
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions. |
ntopng before 3.0 allows HTTP Response Splitting. |
1Mimosa 2Backhaul Radios Client RadiosMay 13, 2026 May 21, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4. On the backend of the device's web interface, there are some diagnostic tests available that are not displayed on the...Show more |
1Mimosa 2Backhaul Radios Client RadiosMay 13, 2026 May 21, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. In the device's web interface, after logging in, there is a page that allows you to ping other hosts from the device a...Show more |
A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. An "improper neutralization of HTTP headers for scripting syntax" issue has been identified, which may allow remote code execu...Show more |
Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://safe.example.com@unsafe.example.com/ is displayed without a clear UI indication that it is not a resource on the safe.example.com web site. |
Tablacus Explorer 17.3.30 and earlier allows arbitrary scripts to be executed in the context of the application due to specially crafted directory. |
1Oracle 1Peoplesoft Enterprise Peopletools May 13, 2026 Apr 24, 2017 N/A· v4 7.4 HIGH· v3 7.1 HIGH· v2 Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerab...Show more |
An exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted HTTP request can inject a payload in th...Show more |
HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or set arbitrary values in cookies. |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Apr 12, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-imap.c by calculating a line's end...Show more |
Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of service (process hang) via a crafted filename. |