CWE-74
5,289 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (5,289)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Axis 1Axis Communications Firmware May 13, 2026 Apr 10, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script Editor, aka a "resource injection vulnerability." |
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injection attacks. |
2Alienvault Nfsen3Nfsen OssimUnified Security ManagementMay 13, 2026 Mar 22, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, or launch a reverse shell, via vectors involving the PHP session ID and...Show more |
1Microsoft 1Internet Explorer May 13, 2026 Mar 17, 2017 N/A· v4 4.4 MEDIUM· v3 5.8 MEDIUM· v2 Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a craft...Show more |
1Opentext 1Documentum Content Server May 13, 2026 Feb 22, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row_based config option is false, does not properly restrict DQL hints, which allow...Show more |
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as d...Show more |
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password. |
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data. |
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam. |
system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from field to insert sendmail command-line arguments. |
A vulnerability in Cisco IOS on Catalyst Switches and Nexus 9300 Series Switches could allow an unauthenticated, adjacent attacker to cause a Layer 2 network storm. More Information: CSCuu69332, CSCux07028. Known Affecte...Show more |
1Pwc 1Ace Advanced Business Application Programming May 6, 2026 Dec 10, 2016 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and execute arbitrary code via (1) SAPGUI or (2) Internet Communication Framework (ICF)...Show more |
1Dell 2Idrac7 Firmware Idrac8 FirmwareMay 6, 2026 Nov 29, 2016 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection. |
A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a webs...Show more |
ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging con...Show more |
2Opensuse Phpmyadmin3Leap OpensusePhpmyadminMay 6, 2026 Jul 3, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to conduct BBCode injection attacks against HTTP sessions via a crafted URI. |
1Broadcom 5Symantec Critical System Protection Symantec Data Center Security ServerSymantec Data Center Security Server And Agents+2 moreMay 6, 2026 Jun 8, 2016 N/A· v4 7.3 HIGH· v3 4.9 MEDIUM· v2 Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCS...Show more |
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to obtain root-shell access via crafted terminal-window input. |
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and obtain sensitive repository information by appending a que...Show more |
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restricti...Show more |