CWE-74 · 5,324 records
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVEs in this class
5,335 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2013-2251Weaponized | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,apache · archiva · CWE-74 | Critical9.8 | KEV | 100.0% | Jul 19, 2013 |
99Now | CVE-2023-22527Weaponized | A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE atlassian · confluence data center · CWE-74 | Critical9.8 | KEV | 100.0% | Jan 16, 2024 |
99Now | CVE-2019-2725Weaponized | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).oracle · agile product lifecycle management · CWE-74 | Critical9.8 | KEV | 100.0% | Apr 26, 2019 |
99Now | CVE-2022-35914Weaponized | /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.glpi-project · glpi · CWE-74 | Critical9.8 | KEV | 99.9% | Sep 19, 2022 |
99Now | CVE-2022-46169Weaponized | Unauthenticated Command Injectioncacti · cacti · CWE-74 | Critical9.8 | KEV | 99.8% | Dec 5, 2022 |
99Now | CVE-2025-20281Weaponized | Cisco ISE API Unauthenticated Remote Code Execution Vulnerabilitycisco · identity services engine · CWE-74 | Critical10.0 | KEV | 97.6% | Jun 25, 2025 |
95Now | CVE-2020-17496Weaponized | vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panelvbulletin · vbulletin · CWE-74 | Critical9.8 | KEV | 87.4% | Aug 12, 2020 |
94Now | CVE-2019-11581Weaponized | There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail aatlassian · jira server · CWE-74 | Critical9.8 | KEV | 84.6% | Aug 9, 2019 |
90Now | CVE-2019-17558Weaponized | Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter.apache · solr · CWE-74 | High7.5 | KEV | 98.6% | Dec 30, 2019 |
90Now | CVE-2025-20337Weaponized | Cisco ISE API Unauthenticated Remote Code Execution Vulnerabilitycisco · identity services engine · CWE-74 | Critical10.0 | KEV | 67.8% | Jul 16, 2025 |
87Now | CVE-2022-43769Weaponized | Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)hitachi · vantara pentaho business analytics server · CWE-74 | High7.2 | KEV | 97.7% | Apr 3, 2023 |
86Now | CVE-2022-27924Weaponized | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instasynacor · zimbra collaboration suite · CWE-74 | High7.5 | KEV | 85.4% | Apr 20, 2022 |
67This week | CVE-2016-4010Weaponized | Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via craftedmagento · magento · CWE-74 | Critical9.8 | — | 92.9% | Jan 23, 2017 |
67This week | CVE-2020-8468Weaponized | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esctrendmicro · apex one · CWE-74 | High8.8 | KEV | 6.2% | Mar 17, 2020 |
65This week | CVE-2024-10914Proof of concept | D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injectiondlink · dns-320 firmware · CWE-74 | Critical9.2 | — | 96.3% | Nov 6, 2024 |
65This week | CVE-2022-2992Weaponized | A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated usgitlab · gitlab · CWE-74 | Critical9.9 | — | 86.2% | Oct 17, 2022 |
64This week | CVE-2013-3214Weaponized | vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.vtiger · vtiger crm · CWE-74 | Critical9.8 | — | 84.5% | Jan 28, 2020 |
64This week | CVE-2021-38294Weaponized | Shell Command Injection Vulnerability in Nimbus Thrift Serverapache · storm · CWE-74 | Critical9.8 | — | 83.8% | Oct 25, 2021 |
64This week | CVE-2018-16763Proof of concept | FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.thedaylightstudio · fuel cms · CWE-74 | Critical9.8 | — | 82.9% | Sep 9, 2018 |
63This week | CVE-2012-1495Weaponized | install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.webcalendar project · webcalendar · CWE-74 | Critical9.8 | — | 79.8% | Jan 27, 2020 |
62This week | CVE-2023-37462Proof of concept | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-skin-uixwiki · xwiki · CWE-74 | High8.8 | — | 91.6% | Jul 14, 2023 |
62This week | CVE-2024-22319Proof of concept | IBM Operational Decision Manager JDNI injectionibm · operational decision manager · CWE-74 | Critical9.8 | — | 76.4% | Feb 1, 2024 |
62This week | CVE-2023-30547Proof of concept | Sandbox Escape in vm2vm2 project · vm2 · CWE-74 | Critical10.0 | — | 72.1% | Apr 17, 2023 |
61This week | CVE-2021-41282Weaponized | diag_routes.php in pfSense 2.5.2 allows sed data injection.pfsense · pfsense · CWE-74 | High8.8 | — | 87.1% | Mar 1, 2022 |
61This week | CVE-2021-21242No exploit | Pre-Auth Unsafe Deserialization on AttachmentUploadServetonedev project · onedev · CWE-74 | Critical9.8 | — | 74.2% | Jan 15, 2021 |
- CVE-2013-225199Now
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · archivaJul 19, 2013
- CVE-2023-2252799Now
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence data centerJan 16, 2024
- CVE-2019-272599Now
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%oracle · agile product lifecycle managementApr 26, 2019
- CVE-2022-3591499Now
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%glpi-project · glpiSep 19, 2022
- CVE-2022-4616999Now
Unauthenticated Command Injection
CriticalCVSS 9.8KEVWeaponizedEPSS 100%cacti · cactiDec 5, 2022
- CVE-2025-2028199Now
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
CriticalCVSS 10.0KEVWeaponizedEPSS 98%cisco · identity services engineJun 25, 2025
- CVE-2020-1749695Now
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel
CriticalCVSS 9.8KEVWeaponizedEPSS 87%vbulletin · vbulletinAug 12, 2020
- CVE-2019-1158194Now
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail a
CriticalCVSS 9.8KEVWeaponizedEPSS 85%atlassian · jira serverAug 9, 2019
- CVE-2019-1755890Now
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter.
HighCVSS 7.5KEVWeaponizedEPSS 99%apache · solrDec 30, 2019
- CVE-2025-2033790Now
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
CriticalCVSS 10.0KEVWeaponizedEPSS 68%cisco · identity services engineJul 16, 2025
- CVE-2022-4376987Now
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
HighCVSS 7.2KEVWeaponizedEPSS 98%hitachi · vantara pentaho business analytics serverApr 3, 2023
- CVE-2022-2792486Now
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted insta
HighCVSS 7.5KEVWeaponizedEPSS 85%synacor · zimbra collaboration suiteApr 20, 2022
- CVE-2016-401067This week
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted
CriticalCVSS 9.8WeaponizedEPSS 93%magento · magentoJan 23, 2017
- CVE-2020-846867This week
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esc
HighCVSS 8.8KEVWeaponizedEPSS 6%trendmicro · apex oneMar 17, 2020
- CVE-2024-1091465This week
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
CriticalCVSS 9.2Proof of conceptEPSS 96%dlink · dns-320 firmwareNov 6, 2024
- CVE-2022-299265This week
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated us
CriticalCVSS 9.9WeaponizedEPSS 86%gitlab · gitlabOct 17, 2022
- CVE-2013-321464This week
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
CriticalCVSS 9.8WeaponizedEPSS 85%vtiger · vtiger crmJan 28, 2020
- CVE-2021-3829464This week
Shell Command Injection Vulnerability in Nimbus Thrift Server
CriticalCVSS 9.8WeaponizedEPSS 84%apache · stormOct 25, 2021
- CVE-2018-1676364This week
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.
CriticalCVSS 9.8Proof of conceptEPSS 83%thedaylightstudio · fuel cmsSep 9, 2018
- CVE-2012-149563This week
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.
CriticalCVSS 9.8WeaponizedEPSS 80%webcalendar project · webcalendarJan 27, 2020
- CVE-2023-3746262This week
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-skin-ui
HighCVSS 8.8Proof of conceptEPSS 92%xwiki · xwikiJul 14, 2023
- CVE-2024-2231962This week
IBM Operational Decision Manager JDNI injection
CriticalCVSS 9.8Proof of conceptEPSS 76%ibm · operational decision managerFeb 1, 2024
- CVE-2023-3054762This week
Sandbox Escape in vm2
CriticalCVSS 10.0Proof of conceptEPSS 72%vm2 project · vm2Apr 17, 2023
- CVE-2021-4128261This week
diag_routes.php in pfSense 2.5.2 allows sed data injection.
HighCVSS 8.8WeaponizedEPSS 87%pfsense · pfsenseMar 1, 2022
- CVE-2021-2124261This week
Pre-Auth Unsafe Deserialization on AttachmentUploadServet
CriticalCVSS 9.8No exploitEPSS 74%onedev project · onedevJan 15, 2021