CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,420 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 2 of 109
- CVE-2014-5083HIGHCVSS 8.8EG 8.82020-02-10
A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5083 pertains to instances of fwrite in Sphid…
- CVE-2014-5084HIGHCVSS 8.8EG 8.82020-02-10
A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious user execute arbitrary code. CVE-2014-5084 pertains to instances of fwrite in Sphider Pro only, but …
- CVE-2014-5085HIGHCVSS 8.8EG 8.82020-02-10
A Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5085 pertains to instances of fwrite in Sphider P…
- CVE-2014-5086HIGHCVSS 8.8EG 8.82020-02-10
A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5086 pertains to instances of fw…
- CVE-2014-5287HIGHCVSS 8.8EG 8.82020-01-08
A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).
- CVE-2014-7236CRITICALCVSS 9.1EG 9.12020-02-17
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.
- CVE-2014-7287MEDIUMCVSS v2 5.0EG 5.02015-02-01
The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-m…
- CVE-2014-7844HIGHCVSS 7.8EG 7.82020-01-14
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
- CVE-2014-7952HIGHCVSS 7.8EG 7.82018-01-12
The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveraging failure to filter application data streams.
- CVE-2014-8423HIGHCVSS v2 10.0EG 10.02014-11-28
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown vectors.
- CVE-2015-0931MEDIUMCVSS v2 6.8EG 6.82015-02-14
Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attackers to execute arbitrary code via a crafted XSLT document, related to a "resource injection" issue.
- CVE-2015-10027CRITICALCVSS 5.5EG 9.82023-01-07
A vulnerability, which was classified as problematic, has been found in hydrian TTRSS-Auth-LDAP. Affected by this issue is some unknown functionality of the component Username Handler. The manipulation leads to ldap injection. Upgrading to…
- CVE-2015-10040MEDIUMCVSS 5.4EG 6.52023-01-13
A vulnerability was found in gitlearn. It has been declared as problematic. This vulnerability affects the function getGrade/getOutOf of the file scripts/config.sh of the component Escape Sequence Handler. The manipulation leads to injecti…
- CVE-2015-10062CRITICALCVSS 5.5EG 9.82023-01-17
A vulnerability, which was classified as problematic, was found in galaxy-data-resource up to 14.10.0. This affects an unknown part of the component Command Line Template. The manipulation leads to injection. Upgrading to version 14.10.1 i…
- CVE-2015-1169HIGHCVSS v2 7.5EG 7.52015-02-10
Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP authentication.
- CVE-2015-1592HIGHCVSS v2 7.5EG 7.52015-02-19
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw function, which allows remote attackers to include and execute arbitrary local Perl files and p…
- CVE-2015-1975HIGHCVSS 7.8EG 7.82018-04-03
The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 37 and IBM Security Directory Server 6.3.1 before iFix 11 and 6.4 before iFix 2 allows loca…
- CVE-2015-2180HIGHCVSS 8.8EG 8.82017-01-30
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.
- CVE-2015-3154MEDIUMCVSS 6.1EG 6.12020-01-27
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF …
- CVE-2015-4075HIGHCVSS 8.1EG 8.12017-09-20
The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task.
- CVE-2015-5227HIGHCVSS 8.8EG 8.82017-10-18
The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter.
- CVE-2015-5377CRITICALCVSS 9.8EG 9.82018-03-06
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability
- CVE-2015-5462MEDIUMCVSS 6.1EG 6.12019-04-03
AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier allows remote attackers to inject HTML into the scoping dashboard features.
- CVE-2015-7264CRITICALCVSS 9.8EG 9.82017-04-10
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injection attacks.
- CVE-2015-7466LOWCVSS 3.1EG 3.12016-01-10
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restrictions or modify the L…
- CVE-2015-7544CRITICALCVSS 9.1EG 9.12017-09-25
redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment.
- CVE-2015-8258HIGHCVSS 7.5EG 7.52017-04-10
AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script Editor, aka a "resource injection vulnerability."
- CVE-2015-8800HIGHCVSS 7.3EG 7.32016-06-08
Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6…
- CVE-2016-0881MEDIUMCVSS 6.5EG 6.52016-02-12
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and obtain sensitive repository information by appending a query to a REST reques…
- CVE-2016-10131CRITICALCVSS 9.8EG 9.82017-01-12
system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from field to insert sendmail command-line arguments.
- CVE-2016-10498CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9635M, MDM9645, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 617, SD 6…
- CVE-2016-10761MEDIUMCVSS 6.5EG 6.52019-06-29
Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.
- CVE-2016-10801HIGHCVSS 8.8EG 8.82019-08-07
cPanel before 58.0.4 has improper session handling for shared users (SEC-139).
- CVE-2016-10845HIGHCVSS 8.1EG 8.12019-08-01
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78).
- CVE-2016-10847HIGHCVSS 8.1EG 8.12019-08-01
cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80).
- CVE-2016-11068MEDIUMCVSS 5.3EG 5.32020-06-19
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
- CVE-2016-1155CRITICALCVSS 9.8EG 9.82017-04-13
HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or set arbitrary values in cookies.
- CVE-2016-15004CRITICALCVSS 7.3EG 9.82022-07-23
A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to injection. The attack can be launched remotely. Up…
- CVE-2016-15007CRITICALCVSS 5.5EG 9.82023-01-02
A vulnerability was found in Centralized-Salesforce-Dev-Framework. It has been declared as problematic. Affected by this vulnerability is the function SObjectService of the file src/classes/SObjectService.cls of the component SOQL Handler.…
- CVE-2016-2204HIGHCVSS 8.2EG 8.22016-04-22
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to obtain root-shell access via crafted terminal-window input.
- CVE-2016-2980MEDIUMCVSS 6.3EG 6.32017-08-29
The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerability in the way that the WebPlayer works. IBM X-Force ID: 113993.
- CVE-2016-3695MEDIUMCVSS 5.5EG 5.52017-12-29
The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disable APEI error injection through EINJ whe…
- CVE-2016-4010CRITICALCVSS 9.8EG 9.82017-01-23
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.
- CVE-2016-5013MEDIUMCVSS 5.4EG 5.42017-01-20
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.
- CVE-2016-5685HIGHCVSS 8.8EG 8.82016-11-29
Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection.
- CVE-2016-5701MEDIUMCVSS 6.1EG 6.12016-07-03
setup/frames/index.inc.php in phpMyAdmin 4.0.10.x before 4.0.10.16, 4.4.15.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to conduct BBCode injection attacks against HTTP sessions via a crafted URI.
- CVE-2016-6473MEDIUMCVSS 6.5EG 6.52016-12-14
A vulnerability in Cisco IOS on Catalyst Switches and Nexus 9300 Series Switches could allow an unauthenticated, adjacent attacker to cause a Layer 2 network storm. More Information: CSCuu69332, CSCux07028. Known Affected Releases: 15.2(3)…
- CVE-2016-6754HIGHCVSS 8.8EG 8.82016-11-25
A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a website. This issue is …
- CVE-2016-7125HIGHCVSS 7.5EG 7.52016-09-12
ext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing, which allows remote attackers to inject arbitrary-type session data by leveraging control of a session n…
- CVE-2016-8720MEDIUMCVSS 4.3EG 4.32017-04-13
An exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted HTTP request can inject a payload in the bkpath parameter …
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →