CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,420 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 3 of 109
- CVE-2016-8899CRITICALCVSS 9.8EG 9.82019-05-23
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change_cats.
- CVE-2016-8900CRITICALCVSS 9.8EG 9.82019-05-24
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related to change_tags.
- CVE-2016-8901CRITICALCVSS 9.8EG 9.82019-05-23
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.
- CVE-2016-9832CRITICALCVSS 9.9EG 9.92016-12-10
PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and execute arbitrary code via (1) SAPGUI or (2) Internet Communication Framework (ICF) over HTTP or HTTPS,…
- CVE-2017-0154MEDIUMCVSS 4.4EG 4.42017-03-17
Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka…
- CVE-2017-0372CRITICALCVSS 9.8EG 9.82018-04-13
Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
- CVE-2017-1000052HIGHCVSS 7.8EG 7.82017-07-17
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions.
- CVE-2017-1000217HIGHCVSS 8.8EG 8.82017-11-17
Opencast 2.3.2 and older versions are vulnerable to script injections through media and metadata in the player and media module resulting in arbitrary code execution, fixed in 2.3.3 and 3.0.
- CVE-2017-1000453CRITICALCVSS 9.8EG 9.82018-01-02
CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execution.
- CVE-2017-1000454HIGHCVSS 7.8EG 7.82018-01-02
CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1
- CVE-2017-1000493CRITICALCVSS 9.8EG 9.82018-01-03
Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover
- CVE-2017-10963MEDIUMCVSS 5.9EG 5.92018-02-20
In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's knowledge) by inspe…
- CVE-2017-1115MEDIUMCVSS 5.4EG 5.42018-09-07
IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Fo…
- CVE-2017-1202MEDIUMCVSS 5.4EG 5.42019-02-05
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context…
- CVE-2017-14094CRITICALCVSS 9.8EG 9.82018-01-19
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a cron job injection on a vulnerable system.
- CVE-2017-14397CRITICALCVSS 9.8EG 9.82017-09-12
AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability.
- CVE-2017-14523HIGHCVSS 7.5EG 7.52018-01-26
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the …
- CVE-2017-15313HIGHCVSS 8.8EG 8.82017-12-22
Huawei SmartCare V200R003C10 has a CSV injection vulnerability. An remote authenticated attacker could inject malicious CSV expression to the affected device.
- CVE-2017-15708CRITICALCVSS 9.8EG 9.82017-12-11
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be…
- CVE-2017-15714CRITICALCVSS 9.8EG 9.82018-01-04
The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert(%27xss%27)" to the…
- CVE-2017-16043MEDIUMCVSS 6.1EG 6.12018-06-04
Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the victim's browser. Affects shout >=0.44.0 <=0.49.3.
- CVE-2017-16680HIGHCVSS 7.5EG 7.52017-12-12
Two potential audit log injections in SAP HANA extended application services 1.0, advanced model: 1) Certain HTTP/REST endpoints of controller service are missing user input validation which could allow unprivileged attackers to forge audi…
- CVE-2017-16719HIGHCVSS 7.5EG 7.52017-11-16
An Injection issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacker may be able to in…
- CVE-2017-16766MEDIUMCVSS 6.5EG 6.52017-12-22
An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary web script or HTML via the -fn option.
- CVE-2017-17511HIGHCVSS 8.8EG 8.82017-12-14
KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to prefs.c and world…
- CVE-2017-17512HIGHCVSS 8.8EG 8.82017-12-11
sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, a…
- CVE-2017-17513HIGHCVSS 8.8EG 8.82017-12-14
TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to linked_s…
- CVE-2017-17514HIGHCVSS 8.8EG 8.82017-12-14
boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software mainta…
- CVE-2017-17515HIGHCVSS 8.8EG 8.82017-12-14
etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a third…
- CVE-2017-17516HIGHCVSS 8.8EG 8.82017-12-14
scripts/inspect_webbrowser.py in Reddit Terminal Viewer (RTV) 1.19.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection att…
- CVE-2017-17517HIGHCVSS 8.8EG 8.82017-12-14
libsylph/utils.c in Sylpheed through 3.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
- CVE-2017-17518HIGHCVSS 8.8EG 8.82017-12-14
swt/motif/browser.c in White_dune (aka whitedune) 0.30.10 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a …
- CVE-2017-17519HIGHCVSS 8.8EG 8.82017-12-14
batteriesConfig.mlp in OCaml Batteries Included (aka ocaml-batteries) 2.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injectio…
- CVE-2017-17520HIGHCVSS 8.8EG 8.82017-12-14
tools/url_handler.pl in TIN 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a thi…
- CVE-2017-17521HIGHCVSS 8.8EG 8.82017-12-14
uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a diff…
- CVE-2017-17522HIGHCVSS 8.8EG 8.82017-12-14
Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOT…
- CVE-2017-17523HIGHCVSS 8.8EG 8.82017-12-11
lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demo…
- CVE-2017-17524HIGHCVSS 8.8EG 8.82017-12-14
library/www_browser.pl in SWI-Prolog 7.2.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
- CVE-2017-17525HIGHCVSS 8.8EG 8.82017-12-14
guiclient/guiclient.cpp in xTuple PostBooks 4.7.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted …
- CVE-2017-17526HIGHCVSS 8.8EG 8.82017-12-14
Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
- CVE-2017-17527HIGHCVSS 8.8EG 8.82017-12-14
delphi_gui/WWWBrowserRunnerDM.pas in PasDoc 0.14 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted U…
- CVE-2017-17528HIGHCVSS 8.8EG 8.82017-12-14
backends/platform/sdl/posix/posix.cpp in ScummVM 1.9.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a cra…
- CVE-2017-17529HIGHCVSS 8.8EG 8.82017-12-14
af/util/xp/ut_go_file.cpp in AbiWord 3.0.2-2 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
- CVE-2017-17530HIGHCVSS 8.8EG 8.82017-12-14
common/help.c in Geomview 1.9.5 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: this is…
- CVE-2017-17531HIGHCVSS 8.8EG 8.82017-12-14
gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
- CVE-2017-17532HIGHCVSS 8.8EG 8.82017-12-14
examples/framework/news/news3.py in Kiwi 1.9.22 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted UR…
- CVE-2017-17533HIGHCVSS 8.8EG 8.82017-12-14
default.tcl in Tkabber 1.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a third part…
- CVE-2017-17534HIGHCVSS 8.8EG 8.82017-12-14
uiutil.c in Mensis 0.0.080507 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vul…
- CVE-2017-17535HIGHCVSS 8.8EG 8.82017-12-14
lib/gui.py in Bob Hepple gjots2 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
- CVE-2017-17790CRITICALCVSS 9.8EG 9.82017-12-20
The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|' character, a different vulnerability t…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →