Skip to content
Noroxi

CWE-116 · 336 records

Improper Encoding or Escaping of Output

CVEs in this class

338 records

  • Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.

    CriticalCVSS 9.1KEVWeaponizedEPSS 100%

    apache · http serverJul 1, 2024

  • CVE-2022-42948
    70This week

    Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components.

    CriticalCVSS 9.8KEVWeaponizedEPSS 3%

    helpsystems · cobalt strikeMar 24, 2023

  • CVE-2026-20245
    69This week

    Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 25%

    cisco · catalyst sd-wan managerJun 4, 2026

  • CVE-2022-36446
    68This week

    software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

    CriticalCVSS 9.8WeaponizedEPSS 96%

    webmin · webminJul 25, 2022

  • CVE-2022-24682
    63This week

    An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the w

    MediumCVSS 6.1KEVWeaponizedEPSS 31%

    synacor · zimbra collaboration suiteFeb 9, 2022

  • Gitea before 1.16.7 does not escape git fetch remote.

    HighCVSS 7.5WeaponizedEPSS 88%

    gitea · giteaMay 16, 2022

  • An issue was discovered in Squid before 4.15 and 5.x before 5.0.6.

    MediumCVSS 6.5WeaponizedEPSS 96%

    squid-cache · squidMay 27, 2021

  • nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character i

    HighCVSS 7.5Proof of conceptEPSS 68%

    f5 · nginxNov 23, 2013

  • An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6.

    MediumCVSS 6.5No exploitEPSS 72%

    squid-cache · squidMay 27, 2021

  • Command injection via array-ish $command parameter of proc_open()

    CriticalCVSS 9.4Proof of conceptEPSS 33%

    php · phpApr 29, 2024

  • An issue was discovered on Accellion FTA devices before FTA_9_12_180.

    CriticalCVSS 9.8No exploitEPSS 24%

    accellion · file transfer applianceMay 5, 2017

  • Apache HTTP Server proxy encoding problem

    HighCVSS 8.1Proof of conceptEPSS 26%

    apache · http serverJul 1, 2024

  • xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is val

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    libexpat project · libexpatFeb 15, 2022

  • Commandline class shell injection vulnerabilities

    CriticalCVSS 9.8No exploitEPSS 4%

    apache · maven shared utilsMay 23, 2022

  • Apache Tomcat: Bypass of rules in Rewrite Valve

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    apache · tomcatApr 28, 2025

  • An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8.

    CriticalCVSS 9.8No exploitEPSS 3%

    sensiolabs · symfonyNov 21, 2019

  • Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command

    CriticalCVSS 9.8No exploitEPSS 3%

    magpierss project · magpierssApr 2, 2021

  • The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable

    CriticalCVSS 9.8No exploitEPSS 3%

    ledgersmb · ledgersmbJun 7, 2018

  • In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.

    CriticalCVSS 9.8No exploitEPSS 3%

    dojotoolkit · dojoAug 17, 2018

  • Apache HTTP Server weakness with encoded question marks in backreferences

    CriticalCVSS 9.8No exploitEPSS 2%

    apache · http serverJul 1, 2024

  • A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload inje

    CriticalCVSS 9.8No exploitEPSS 2%

    beekeeperstudio · beekeeper-studioMar 21, 2022

  • Command Injection Remote Code Execution vulnerability on Western Digital My Cloud devices.

    CriticalCVSS 9.8No exploitEPSS 2%

    westerndigital · my cloud osJan 28, 2022

  • FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.

    CriticalCVSS 9.8No exploitEPSS 2%

    fusionpbx · fusionpbxAug 18, 2022

  • XWiki Remote Macros vulnerable to remote code execution using the confluence paste code macro

    CriticalCVSS 10.0No exploitEPSS 1%

    xwikisas · xwiki-pro-macrosSep 9, 2025

  • XWiki Remote Macros vulnerable to remote code execution using the ConfluenceLayoutSection macro

    CriticalCVSS 10.0No exploitEPSS 1%

    xwikisas · xwiki-pro-macrosSep 9, 2025

All vulnerability classes