CWE-75 · 29 записей
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
CVE этого класса
29 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
68На этой неделе | CVE-2021-22911Proof of concept | A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injectiorocket.chat · rocket.chat · CWE-75 | Критическая9,8 | — | 95,2 % | 27 мая 2021 г. |
43В плане | CVE-2024-0801Proof of concept | Unauthenticated DoS in Arcserve Unified Data Protectionarcserve · udp · CWE-75 | Высокая7,5 | — | 41,8 % | 13 мар. 2024 г. |
40В плане | CVE-2021-22910Эксплойта нет | A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which couldrocket.chat · rocket.chat · CWE-75 | Критическая9,8 | — | 2,3 % | 9 авг. 2021 г. |
39Наблюдать | CVE-2024-35373Эксплойта нет | Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.mocodo · mocodo online · CWE-75 | Критическая9,8 | — | 1,2 % | 24 мая 2024 г. |
39Наблюдать | CVE-2025-50213Эксплойта нет | Apache Airflow Providers Snowflake: Potential SQL injection in CopyFromExternalStageToSnowflakeOperatorapache · apache-airflow-providers-snowflake · CWE-75 | Критическая9,8 | — | 0,7 % | 24 июн. 2025 г. |
37Наблюдать | CVE-2021-39174Proof of concept | Cachet is an open source status page system.catchethq · catchet · CWE-75 | Высокая8,8 | — | 5,0 % | 27 авг. 2021 г. |
37Наблюдать | CVE-2022-24039Эксплойта нет | A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884).siemens · desigo pxc5 firmware · CWE-75 | Критическая9,0 | — | 2,0 % | 10 мая 2022 г. |
36Наблюдать | CVE-2026-29042Эксплойта нет | Nuclio Shell Runtime Command Injection Leading to Privilege Escalationiguazio · nuclio · CWE-75 | Высокая8,9 | — | 3,3 % | 6 мар. 2026 г. |
36Наблюдать | CVE-2023-27533Эксплойта нет | A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on malihaxx · curl · CWE-75 | Высокая8,8 | — | 2,0 % | 30 мар. 2023 г. |
36Наблюдать | CVE-2026-31908Proof of concept | Apache APISIX: forward auth plugin allows header injectionapache · apisix · CWE-75 | Критическая9,1 | — | 0,6 % | 14 апр. 2026 г. |
35Наблюдать | CVE-2024-37779Эксплойта нет | WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant scriptCWE-75 | Высокая8,8 | — | 1,1 % | 23 сент. 2024 г. |
35Наблюдать | CVE-2024-31809Эксплойта нет | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in thtotolink · ex200 firmware · CWE-75 | Высокая8,8 | — | 1,0 % | 8 апр. 2024 г. |
35Наблюдать | CVE-2023-23912Эксплойта нет | A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with tui · usg firmware · CWE-75 | Высокая8,8 | — | 1,0 % | 9 февр. 2023 г. |
34Наблюдать | CVE-2024-58362Эксплойта нет | SurrealDB before 1.5.5 Query Injection via RPC APIsurrealdb · surrealdb · CWE-75 | Высокая8,7 | — | 0,6 % | 18 июл. 2026 г. |
32Наблюдать | CVE-2022-48217Эксплойта нет | The tf_remapper_node component 1.1.1 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in ttradr-project · tf remapper · CWE-75 | Высокая8,1 | — | 0,7 % | 4 янв. 2023 г. |
32Наблюдать | CVE-2026-54771Эксплойта нет | Langroid: handle_message() executes user-supplied tool JSON without sender verificationlangroid · langroid · CWE-75 | Высокая8,1 | — | 0,4 % | 9 июл. 2026 г. |
31Наблюдать | CVE-2023-0302Эксплойта нет | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in radareorg/radare2radare · radare2 · CWE-75 | Высокая7,8 | — | 0,4 % | 14 янв. 2023 г. |
30Наблюдать | CVE-2024-24257Эксплойта нет | An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information vCWE-75 | Высокая7,5 | — | 0,4 % | 26 июл. 2024 г. |
29Наблюдать | CVE-2024-27622Эксплойта нет | A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21.cmsmadesimple · cms made simple · CWE-75 | Высокая7,2 | — | 2,0 % | 5 мар. 2024 г. |
26Наблюдать | CVE-2024-31806Эксплойта нет | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which ctotolink · ex200 firmware · CWE-75 | Средняя6,5 | — | 0,4 % | 8 апр. 2024 г. |
26Наблюдать | CVE-2024-31812Эксплойта нет | In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExttotolink · ex200 firmware · CWE-75 | Средняя6,5 | — | 0,3 % | 8 апр. 2024 г. |
24Наблюдать | CVE-2022-3607Эксплойта нет | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in octoprint/octoprintoctoprint · octoprint · CWE-75 | Средняя6,0 | — | 0,4 % | 19 окт. 2022 г. |
24Наблюдать | CVE-2026-27120Эксплойта нет | Leaf-kit html escaping does not work on characters that are part of extended grapheme clustervapor · leafkit · CWE-75 | Средняя6,1 | — | 0,3 % | 20 февр. 2026 г. |
22Наблюдать | CVE-2025-61911Эксплойта нет | python-ldap has sanitization bypass in ldap.filter.escape_filter_charspython-ldap · python-ldap · CWE-75 | Средняя5,5 | — | 0,3 % | 10 окт. 2025 г. |
21Наблюдать | CVE-2023-1758Эксплойта нет | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in thorsten/phpmyfaqphpmyfaq · phpmyfaq · CWE-75 | Средняя5,4 | — | 0,5 % | 5 апр. 2023 г. |
- CVE-2021-2291168На этой неделе
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injectio
КритическаяCVSS 9,8Proof of conceptEPSS 95 %rocket.chat · rocket.chat27 мая 2021 г.
- CVE-2024-080143В плане
Unauthenticated DoS in Arcserve Unified Data Protection
ВысокаяCVSS 7,5Proof of conceptEPSS 42 %arcserve · udp13 мар. 2024 г.
- CVE-2021-2291040В плане
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %rocket.chat · rocket.chat9 авг. 2021 г.
- CVE-2024-3537339Наблюдать
Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mocodo · mocodo online24 мая 2024 г.
- CVE-2025-5021339Наблюдать
Apache Airflow Providers Snowflake: Potential SQL injection in CopyFromExternalStageToSnowflakeOperator
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache · apache-airflow-providers-snowflake24 июн. 2025 г.
- CVE-2021-3917437Наблюдать
Cachet is an open source status page system.
ВысокаяCVSS 8,8Proof of conceptEPSS 5 %catchethq · catchet27 авг. 2021 г.
- CVE-2022-2403937Наблюдать
A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884).
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %siemens · desigo pxc5 firmware10 мая 2022 г.
- CVE-2026-2904236Наблюдать
Nuclio Shell Runtime Command Injection Leading to Privilege Escalation
ВысокаяCVSS 8,9Эксплойта нетEPSS 3 %iguazio · nuclio6 мар. 2026 г.
- CVE-2023-2753336Наблюдать
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on mali
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %haxx · curl30 мар. 2023 г.
- CVE-2026-3190836Наблюдать
Apache APISIX: forward auth plugin allows header injection
КритическаяCVSS 9,1Proof of conceptEPSS 1 %apache · apisix14 апр. 2026 г.
- CVE-2024-3777935Наблюдать
WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %23 сент. 2024 г.
- CVE-2024-3180935Наблюдать
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in th
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %totolink · ex200 firmware8 апр. 2024 г.
- CVE-2023-2391235Наблюдать
A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with t
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ui · usg firmware9 февр. 2023 г.
- CVE-2024-5836234Наблюдать
SurrealDB before 1.5.5 Query Injection via RPC API
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %surrealdb · surrealdb18 июл. 2026 г.
- CVE-2022-4821732Наблюдать
The tf_remapper_node component 1.1.1 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in t
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %tradr-project · tf remapper4 янв. 2023 г.
- CVE-2026-5477132Наблюдать
Langroid: handle_message() executes user-supplied tool JSON without sender verification
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %langroid · langroid9 июл. 2026 г.
- CVE-2023-030231Наблюдать
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in radareorg/radare2
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %radare · radare214 янв. 2023 г.
- CVE-2024-2425730Наблюдать
An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information v
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %26 июл. 2024 г.
- CVE-2024-2762229Наблюдать
A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21.
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %cmsmadesimple · cms made simple5 мар. 2024 г.
- CVE-2024-3180626Наблюдать
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which c
СредняяCVSS 6,5Эксплойта нетEPSS 0 %totolink · ex200 firmware8 апр. 2024 г.
- CVE-2024-3181226Наблюдать
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExt
СредняяCVSS 6,5Эксплойта нетEPSS 0 %totolink · ex200 firmware8 апр. 2024 г.
- CVE-2022-360724Наблюдать
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in octoprint/octoprint
СредняяCVSS 6,0Эксплойта нетEPSS 0 %octoprint · octoprint19 окт. 2022 г.
- CVE-2026-2712024Наблюдать
Leaf-kit html escaping does not work on characters that are part of extended grapheme cluster
СредняяCVSS 6,1Эксплойта нетEPSS 0 %vapor · leafkit20 февр. 2026 г.
- CVE-2025-6191122Наблюдать
python-ldap has sanitization bypass in ldap.filter.escape_filter_chars
СредняяCVSS 5,5Эксплойта нетEPSS 0 %python-ldap · python-ldap10 окт. 2025 г.
- CVE-2023-175821Наблюдать
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in thorsten/phpmyfaq
СредняяCVSS 5,4Эксплойта нетEPSS 1 %phpmyfaq · phpmyfaq5 апр. 2023 г.