Перейти к содержимому
Noroxi

CWE-75 · 29 записей

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)

CVE этого класса

29 записей

  • CVE-2021-22911
    68На этой неделе

    A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injectio

    КритическаяCVSS 9,8Proof of conceptEPSS 95 %

    rocket.chat · rocket.chat27 мая 2021 г.

  • CVE-2024-0801
    43В плане

    Unauthenticated DoS in Arcserve Unified Data Protection

    ВысокаяCVSS 7,5Proof of conceptEPSS 42 %

    arcserve · udp13 мар. 2024 г.

  • CVE-2021-22910
    40В плане

    A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    rocket.chat · rocket.chat9 авг. 2021 г.

  • CVE-2024-35373
    39Наблюдать

    Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    mocodo · mocodo online24 мая 2024 г.

  • CVE-2025-50213
    39Наблюдать

    Apache Airflow Providers Snowflake: Potential SQL injection in CopyFromExternalStageToSnowflakeOperator

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    apache · apache-airflow-providers-snowflake24 июн. 2025 г.

  • CVE-2021-39174
    37Наблюдать

    Cachet is an open source status page system.

    ВысокаяCVSS 8,8Proof of conceptEPSS 5 %

    catchethq · catchet27 авг. 2021 г.

  • CVE-2022-24039
    37Наблюдать

    A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884).

    КритическаяCVSS 9,0Эксплойта нетEPSS 2 %

    siemens · desigo pxc5 firmware10 мая 2022 г.

  • CVE-2026-29042
    36Наблюдать

    Nuclio Shell Runtime Command Injection Leading to Privilege Escalation

    ВысокаяCVSS 8,9Эксплойта нетEPSS 3 %

    iguazio · nuclio6 мар. 2026 г.

  • CVE-2023-27533
    36Наблюдать

    A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on mali

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    haxx · curl30 мар. 2023 г.

  • CVE-2026-31908
    36Наблюдать

    Apache APISIX: forward auth plugin allows header injection

    КритическаяCVSS 9,1Proof of conceptEPSS 1 %

    apache · apisix14 апр. 2026 г.

  • CVE-2024-37779
    35Наблюдать

    WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    23 сент. 2024 г.

  • CVE-2024-31809
    35Наблюдать

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in th

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    totolink · ex200 firmware8 апр. 2024 г.

  • CVE-2023-23912
    35Наблюдать

    A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with t

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    ui · usg firmware9 февр. 2023 г.

  • CVE-2024-58362
    34Наблюдать

    SurrealDB before 1.5.5 Query Injection via RPC API

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    surrealdb · surrealdb18 июл. 2026 г.

  • CVE-2022-48217
    32Наблюдать

    The tf_remapper_node component 1.1.1 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in t

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    tradr-project · tf remapper4 янв. 2023 г.

  • CVE-2026-54771
    32Наблюдать

    Langroid: handle_message() executes user-supplied tool JSON without sender verification

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    langroid · langroid9 июл. 2026 г.

  • CVE-2023-0302
    31Наблюдать

    Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in radareorg/radare2

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    radare · radare214 янв. 2023 г.

  • CVE-2024-24257
    30Наблюдать

    An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information v

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    26 июл. 2024 г.

  • CVE-2024-27622
    29Наблюдать

    A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %

    cmsmadesimple · cms made simple5 мар. 2024 г.

  • CVE-2024-31806
    26Наблюдать

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which c

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    totolink · ex200 firmware8 апр. 2024 г.

  • CVE-2024-31812
    26Наблюдать

    In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExt

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    totolink · ex200 firmware8 апр. 2024 г.

  • CVE-2022-3607
    24Наблюдать

    Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in octoprint/octoprint

    СредняяCVSS 6,0Эксплойта нетEPSS 0 %

    octoprint · octoprint19 окт. 2022 г.

  • CVE-2026-27120
    24Наблюдать

    Leaf-kit html escaping does not work on characters that are part of extended grapheme cluster

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    vapor · leafkit20 февр. 2026 г.

  • CVE-2025-61911
    22Наблюдать

    python-ldap has sanitization bypass in ldap.filter.escape_filter_chars

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    python-ldap · python-ldap10 окт. 2025 г.

  • CVE-2023-1758
    21Наблюдать

    Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in thorsten/phpmyfaq

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    phpmyfaq · phpmyfaq5 апр. 2023 г.

Все классы уязвимостей