Skip to content
Noroxi

CWE-74 · 5,324 records

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CVEs in this class

5,335 records

  • Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · archivaJul 19, 2013

  • A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    atlassian · confluence data centerJan 16, 2024

  • Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    oracle · agile product lifecycle managementApr 26, 2019

  • /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    glpi-project · glpiSep 19, 2022

  • Unauthenticated Command Injection

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    cacti · cactiDec 5, 2022

  • Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

    CriticalCVSS 10.0KEVWeaponizedEPSS 98%

    cisco · identity services engineJun 25, 2025

  • vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel

    CriticalCVSS 9.8KEVWeaponizedEPSS 87%

    vbulletin · vbulletinAug 12, 2020

  • There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail a

    CriticalCVSS 9.8KEVWeaponizedEPSS 85%

    atlassian · jira serverAug 9, 2019

  • Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter.

    HighCVSS 7.5KEVWeaponizedEPSS 99%

    apache · solrDec 30, 2019

  • Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

    CriticalCVSS 10.0KEVWeaponizedEPSS 68%

    cisco · identity services engineJul 16, 2025

  • Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)

    HighCVSS 7.2KEVWeaponizedEPSS 98%

    hitachi · vantara pentaho business analytics serverApr 3, 2023

  • Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted insta

    HighCVSS 7.5KEVWeaponizedEPSS 85%

    synacor · zimbra collaboration suiteApr 20, 2022

  • CVE-2016-4010
    67This week

    Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted

    CriticalCVSS 9.8WeaponizedEPSS 93%

    magento · magentoJan 23, 2017

  • CVE-2020-8468
    67This week

    Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esc

    HighCVSS 8.8KEVWeaponizedEPSS 6%

    trendmicro · apex oneMar 17, 2020

  • CVE-2024-10914
    65This week

    D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection

    CriticalCVSS 9.2Proof of conceptEPSS 96%

    dlink · dns-320 firmwareNov 6, 2024

  • CVE-2022-2992
    65This week

    A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated us

    CriticalCVSS 9.9WeaponizedEPSS 86%

    gitlab · gitlabOct 17, 2022

  • CVE-2013-3214
    64This week

    vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

    CriticalCVSS 9.8WeaponizedEPSS 85%

    vtiger · vtiger crmJan 28, 2020

  • CVE-2021-38294
    64This week

    Shell Command Injection Vulnerability in Nimbus Thrift Server

    CriticalCVSS 9.8WeaponizedEPSS 84%

    apache · stormOct 25, 2021

  • CVE-2018-16763
    64This week

    FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.

    CriticalCVSS 9.8Proof of conceptEPSS 83%

    thedaylightstudio · fuel cmsSep 9, 2018

  • CVE-2012-1495
    63This week

    install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.

    CriticalCVSS 9.8WeaponizedEPSS 80%

    webcalendar project · webcalendarJan 27, 2020

  • CVE-2023-37462
    62This week

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-skin-ui

    HighCVSS 8.8Proof of conceptEPSS 92%

    xwiki · xwikiJul 14, 2023

  • CVE-2024-22319
    62This week

    IBM Operational Decision Manager JDNI injection

    CriticalCVSS 9.8Proof of conceptEPSS 76%

    ibm · operational decision managerFeb 1, 2024

  • CVE-2023-30547
    62This week

    Sandbox Escape in vm2

    CriticalCVSS 10.0Proof of conceptEPSS 72%

    vm2 project · vm2Apr 17, 2023

  • CVE-2021-41282
    61This week

    diag_routes.php in pfSense 2.5.2 allows sed data injection.

    HighCVSS 8.8WeaponizedEPSS 87%

    pfsense · pfsenseMar 1, 2022

  • CVE-2021-21242
    61This week

    Pre-Auth Unsafe Deserialization on AttachmentUploadServet

    CriticalCVSS 9.8No exploitEPSS 74%

    onedev project · onedevJan 15, 2021

All vulnerability classes