CWE-116 · 336 records
Improper Encoding or Escaping of Output
CVEs in this class
338 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
96Now | CVE-2024-38475Weaponized | Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.apache · http server · CWE-116 | Critical9.1 | KEV | 100.0% | Jul 1, 2024 |
70This week | CVE-2022-42948Weaponized | Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components.helpsystems · cobalt strike · CWE-116 | Critical9.8 | KEV | 2.7% | Mar 24, 2023 |
69This week | CVE-2026-20245Weaponized | Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerabilitycisco · catalyst sd-wan manager · CWE-116 | High7.8 | KEV | 25.3% | Jun 4, 2026 |
68This week | CVE-2022-36446Weaponized | software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.webmin · webmin · CWE-116 | Critical9.8 | — | 96.0% | Jul 25, 2022 |
63This week | CVE-2022-24682Weaponized | An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wsynacor · zimbra collaboration suite · CWE-116 | Medium6.1 | KEV | 30.9% | Feb 9, 2022 |
56Plan | CVE-2022-30781Weaponized | Gitea before 1.16.7 does not escape git fetch remote.gitea · gitea · CWE-116 | High7.5 | — | 87.9% | May 16, 2022 |
55Plan | CVE-2021-31806Weaponized | An issue was discovered in Squid before 4.15 and 5.x before 5.0.6.squid-cache · squid · CWE-116 | Medium6.5 | — | 95.8% | May 27, 2021 |
50Plan | CVE-2013-4547Proof of concept | nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character if5 · nginx · CWE-116 | High7.5 | — | 67.7% | Nov 23, 2013 |
48Plan | CVE-2021-28662No exploit | An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6.squid-cache · squid · CWE-116 | Medium6.5 | — | 71.8% | May 27, 2021 |
47Plan | CVE-2024-1874Proof of concept | Command injection via array-ish $command parameter of proc_open()php · php · CWE-116 | Critical9.4 | — | 32.6% | Apr 29, 2024 |
46Plan | CVE-2017-8303No exploit | An issue was discovered on Accellion FTA devices before FTA_9_12_180.accellion · file transfer appliance · CWE-116 | Critical9.8 | — | 24.2% | May 5, 2017 |
40Plan | CVE-2024-38473Proof of concept | Apache HTTP Server proxy encoding problemapache · http server · CWE-116 | High8.1 | — | 25.9% | Jul 1, 2024 |
40Plan | CVE-2022-25235Proof of concept | xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is vallibexpat project · libexpat · CWE-116 | Critical9.8 | — | 5.0% | Feb 15, 2022 |
40Plan | CVE-2022-29599No exploit | Commandline class shell injection vulnerabilitiesapache · maven shared utils · CWE-116 | Critical9.8 | — | 4.4% | May 23, 2022 |
40Plan | CVE-2025-31651Proof of concept | Apache Tomcat: Bypass of rules in Rewrite Valveapache · tomcat · CWE-116 | Critical9.8 | — | 4.2% | Apr 28, 2025 |
40Plan | CVE-2019-11325No exploit | An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8.sensiolabs · symfony · CWE-116 | Critical9.8 | — | 3.4% | Nov 21, 2019 |
40Plan | CVE-2021-28940No exploit | Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra commandmagpierss project · magpierss · CWE-116 | Critical9.8 | — | 3.3% | Apr 2, 2021 |
40Plan | CVE-2018-9246No exploit | The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variableledgersmb · ledgersmb · CWE-116 | Critical9.8 | — | 2.6% | Jun 7, 2018 |
40Plan | CVE-2018-15494No exploit | In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.dojotoolkit · dojo · CWE-116 | Critical9.8 | — | 2.5% | Aug 17, 2018 |
40Plan | CVE-2024-38474No exploit | Apache HTTP Server weakness with encoded question marks in backreferencesapache · http server · CWE-116 | Critical9.8 | — | 2.5% | Jul 1, 2024 |
40Plan | CVE-2022-26174No exploit | A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload injebeekeeperstudio · beekeeper-studio · CWE-116 | Critical9.8 | — | 2.4% | Mar 21, 2022 |
40Plan | CVE-2022-22992No exploit | Command Injection Remote Code Execution vulnerability on Western Digital My Cloud devices.westerndigital · my cloud os · CWE-116 | Critical9.8 | — | 2.3% | Jan 28, 2022 |
40Plan | CVE-2022-35153No exploit | FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.fusionpbx · fusionpbx · CWE-116 | Critical9.8 | — | 1.8% | Aug 18, 2022 |
40Plan | CVE-2025-55730No exploit | XWiki Remote Macros vulnerable to remote code execution using the confluence paste code macroxwikisas · xwiki-pro-macros · CWE-116 | Critical10.0 | — | 0.7% | Sep 9, 2025 |
40Plan | CVE-2025-55729No exploit | XWiki Remote Macros vulnerable to remote code execution using the ConfluenceLayoutSection macroxwikisas · xwiki-pro-macros · CWE-116 | Critical10.0 | — | 0.7% | Sep 9, 2025 |
- CVE-2024-3847596Now
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
CriticalCVSS 9.1KEVWeaponizedEPSS 100%apache · http serverJul 1, 2024
- CVE-2022-4294870This week
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components.
CriticalCVSS 9.8KEVWeaponizedEPSS 3%helpsystems · cobalt strikeMar 24, 2023
- CVE-2026-2024569This week
Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 25%cisco · catalyst sd-wan managerJun 4, 2026
- CVE-2022-3644668This week
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
CriticalCVSS 9.8WeaponizedEPSS 96%webmin · webminJul 25, 2022
- CVE-2022-2468263This week
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the w
MediumCVSS 6.1KEVWeaponizedEPSS 31%synacor · zimbra collaboration suiteFeb 9, 2022
- CVE-2022-3078156Plan
Gitea before 1.16.7 does not escape git fetch remote.
HighCVSS 7.5WeaponizedEPSS 88%gitea · giteaMay 16, 2022
- CVE-2021-3180655Plan
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6.
MediumCVSS 6.5WeaponizedEPSS 96%squid-cache · squidMay 27, 2021
- CVE-2013-454750Plan
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character i
HighCVSS 7.5Proof of conceptEPSS 68%f5 · nginxNov 23, 2013
- CVE-2021-2866248Plan
An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6.
MediumCVSS 6.5No exploitEPSS 72%squid-cache · squidMay 27, 2021
- CVE-2024-187447Plan
Command injection via array-ish $command parameter of proc_open()
CriticalCVSS 9.4Proof of conceptEPSS 33%php · phpApr 29, 2024
- CVE-2017-830346Plan
An issue was discovered on Accellion FTA devices before FTA_9_12_180.
CriticalCVSS 9.8No exploitEPSS 24%accellion · file transfer applianceMay 5, 2017
- CVE-2024-3847340Plan
Apache HTTP Server proxy encoding problem
HighCVSS 8.1Proof of conceptEPSS 26%apache · http serverJul 1, 2024
- CVE-2022-2523540Plan
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is val
CriticalCVSS 9.8Proof of conceptEPSS 5%libexpat project · libexpatFeb 15, 2022
- CVE-2022-2959940Plan
Commandline class shell injection vulnerabilities
CriticalCVSS 9.8No exploitEPSS 4%apache · maven shared utilsMay 23, 2022
- CVE-2025-3165140Plan
Apache Tomcat: Bypass of rules in Rewrite Valve
CriticalCVSS 9.8Proof of conceptEPSS 4%apache · tomcatApr 28, 2025
- CVE-2019-1132540Plan
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8.
CriticalCVSS 9.8No exploitEPSS 3%sensiolabs · symfonyNov 21, 2019
- CVE-2021-2894040Plan
Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command
CriticalCVSS 9.8No exploitEPSS 3%magpierss project · magpierssApr 2, 2021
- CVE-2018-924640Plan
The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable
CriticalCVSS 9.8No exploitEPSS 3%ledgersmb · ledgersmbJun 7, 2018
- CVE-2018-1549440Plan
In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.
CriticalCVSS 9.8No exploitEPSS 3%dojotoolkit · dojoAug 17, 2018
- CVE-2024-3847440Plan
Apache HTTP Server weakness with encoded question marks in backreferences
CriticalCVSS 9.8No exploitEPSS 2%apache · http serverJul 1, 2024
- CVE-2022-2617440Plan
A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload inje
CriticalCVSS 9.8No exploitEPSS 2%beekeeperstudio · beekeeper-studioMar 21, 2022
- CVE-2022-2299240Plan
Command Injection Remote Code Execution vulnerability on Western Digital My Cloud devices.
CriticalCVSS 9.8No exploitEPSS 2%westerndigital · my cloud osJan 28, 2022
- CVE-2022-3515340Plan
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
CriticalCVSS 9.8No exploitEPSS 2%fusionpbx · fusionpbxAug 18, 2022
- CVE-2025-5573040Plan
XWiki Remote Macros vulnerable to remote code execution using the confluence paste code macro
CriticalCVSS 10.0No exploitEPSS 1%xwikisas · xwiki-pro-macrosSep 9, 2025
- CVE-2025-5572940Plan
XWiki Remote Macros vulnerable to remote code execution using the ConfluenceLayoutSection macro
CriticalCVSS 10.0No exploitEPSS 1%xwikisas · xwiki-pro-macrosSep 9, 2025