CWE-116 · 336 записей
Improper Encoding or Escaping of Output
CVE этого класса
338 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
96Срочно | CVE-2024-38475Готовый эксплойт | Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.apache · http server · CWE-116 | Критическая9,1 | KEV | 100,0 % | 1 июл. 2024 г. |
70На этой неделе | CVE-2022-42948Готовый эксплойт | Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components.helpsystems · cobalt strike · CWE-116 | Критическая9,8 | KEV | 2,7 % | 24 мар. 2023 г. |
69На этой неделе | CVE-2026-20245Готовый эксплойт | Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerabilitycisco · catalyst sd-wan manager · CWE-116 | Высокая7,8 | KEV | 25,3 % | 4 июн. 2026 г. |
68На этой неделе | CVE-2022-36446Готовый эксплойт | software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.webmin · webmin · CWE-116 | Критическая9,8 | — | 96,0 % | 25 июл. 2022 г. |
63На этой неделе | CVE-2022-24682Готовый эксплойт | An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wsynacor · zimbra collaboration suite · CWE-116 | Средняя6,1 | KEV | 30,9 % | 9 февр. 2022 г. |
56В плане | CVE-2022-30781Готовый эксплойт | Gitea before 1.16.7 does not escape git fetch remote.gitea · gitea · CWE-116 | Высокая7,5 | — | 87,9 % | 16 мая 2022 г. |
55В плане | CVE-2021-31806Готовый эксплойт | An issue was discovered in Squid before 4.15 and 5.x before 5.0.6.squid-cache · squid · CWE-116 | Средняя6,5 | — | 95,8 % | 27 мая 2021 г. |
50В плане | CVE-2013-4547Proof of concept | nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character if5 · nginx · CWE-116 | Высокая7,5 | — | 67,7 % | 23 нояб. 2013 г. |
48В плане | CVE-2021-28662Эксплойта нет | An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6.squid-cache · squid · CWE-116 | Средняя6,5 | — | 71,8 % | 27 мая 2021 г. |
47В плане | CVE-2024-1874Proof of concept | Command injection via array-ish $command parameter of proc_open()php · php · CWE-116 | Критическая9,4 | — | 32,6 % | 29 апр. 2024 г. |
46В плане | CVE-2017-8303Эксплойта нет | An issue was discovered on Accellion FTA devices before FTA_9_12_180.accellion · file transfer appliance · CWE-116 | Критическая9,8 | — | 24,2 % | 5 мая 2017 г. |
40В плане | CVE-2024-38473Proof of concept | Apache HTTP Server proxy encoding problemapache · http server · CWE-116 | Высокая8,1 | — | 25,9 % | 1 июл. 2024 г. |
40В плане | CVE-2022-25235Proof of concept | xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is vallibexpat project · libexpat · CWE-116 | Критическая9,8 | — | 5,0 % | 15 февр. 2022 г. |
40В плане | CVE-2022-29599Эксплойта нет | Commandline class shell injection vulnerabilitiesapache · maven shared utils · CWE-116 | Критическая9,8 | — | 4,4 % | 23 мая 2022 г. |
40В плане | CVE-2025-31651Proof of concept | Apache Tomcat: Bypass of rules in Rewrite Valveapache · tomcat · CWE-116 | Критическая9,8 | — | 4,2 % | 28 апр. 2025 г. |
40В плане | CVE-2019-11325Эксплойта нет | An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8.sensiolabs · symfony · CWE-116 | Критическая9,8 | — | 3,4 % | 21 нояб. 2019 г. |
40В плане | CVE-2021-28940Эксплойта нет | Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra commandmagpierss project · magpierss · CWE-116 | Критическая9,8 | — | 3,3 % | 2 апр. 2021 г. |
40В плане | CVE-2018-9246Эксплойта нет | The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variableledgersmb · ledgersmb · CWE-116 | Критическая9,8 | — | 2,6 % | 7 июн. 2018 г. |
40В плане | CVE-2018-15494Эксплойта нет | In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.dojotoolkit · dojo · CWE-116 | Критическая9,8 | — | 2,5 % | 17 авг. 2018 г. |
40В плане | CVE-2024-38474Эксплойта нет | Apache HTTP Server weakness with encoded question marks in backreferencesapache · http server · CWE-116 | Критическая9,8 | — | 2,5 % | 1 июл. 2024 г. |
40В плане | CVE-2022-26174Эксплойта нет | A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload injebeekeeperstudio · beekeeper-studio · CWE-116 | Критическая9,8 | — | 2,4 % | 21 мар. 2022 г. |
40В плане | CVE-2022-22992Эксплойта нет | Command Injection Remote Code Execution vulnerability on Western Digital My Cloud devices.westerndigital · my cloud os · CWE-116 | Критическая9,8 | — | 2,3 % | 28 янв. 2022 г. |
40В плане | CVE-2022-35153Эксплойта нет | FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.fusionpbx · fusionpbx · CWE-116 | Критическая9,8 | — | 1,8 % | 18 авг. 2022 г. |
40В плане | CVE-2025-55730Эксплойта нет | XWiki Remote Macros vulnerable to remote code execution using the confluence paste code macroxwikisas · xwiki-pro-macros · CWE-116 | Критическая10,0 | — | 0,7 % | 9 сент. 2025 г. |
40В плане | CVE-2025-55729Эксплойта нет | XWiki Remote Macros vulnerable to remote code execution using the ConfluenceLayoutSection macroxwikisas · xwiki-pro-macros · CWE-116 | Критическая10,0 | — | 0,7 % | 9 сент. 2025 г. |
- CVE-2024-3847596Срочно
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 100 %apache · http server1 июл. 2024 г.
- CVE-2022-4294870На этой неделе
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 3 %helpsystems · cobalt strike24 мар. 2023 г.
- CVE-2026-2024569На этой неделе
Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 25 %cisco · catalyst sd-wan manager4 июн. 2026 г.
- CVE-2022-3644668На этой неделе
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
КритическаяCVSS 9,8Готовый эксплойтEPSS 96 %webmin · webmin25 июл. 2022 г.
- CVE-2022-2468263На этой неделе
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the w
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 31 %synacor · zimbra collaboration suite9 февр. 2022 г.
- CVE-2022-3078156В плане
Gitea before 1.16.7 does not escape git fetch remote.
ВысокаяCVSS 7,5Готовый эксплойтEPSS 88 %gitea · gitea16 мая 2022 г.
- CVE-2021-3180655В плане
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6.
СредняяCVSS 6,5Готовый эксплойтEPSS 96 %squid-cache · squid27 мая 2021 г.
- CVE-2013-454750В плане
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character i
ВысокаяCVSS 7,5Proof of conceptEPSS 68 %f5 · nginx23 нояб. 2013 г.
- CVE-2021-2866248В плане
An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6.
СредняяCVSS 6,5Эксплойта нетEPSS 72 %squid-cache · squid27 мая 2021 г.
- CVE-2024-187447В плане
Command injection via array-ish $command parameter of proc_open()
КритическаяCVSS 9,4Proof of conceptEPSS 33 %php · php29 апр. 2024 г.
- CVE-2017-830346В плане
An issue was discovered on Accellion FTA devices before FTA_9_12_180.
КритическаяCVSS 9,8Эксплойта нетEPSS 24 %accellion · file transfer appliance5 мая 2017 г.
- CVE-2024-3847340В плане
Apache HTTP Server proxy encoding problem
ВысокаяCVSS 8,1Proof of conceptEPSS 26 %apache · http server1 июл. 2024 г.
- CVE-2022-2523540В плане
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is val
КритическаяCVSS 9,8Proof of conceptEPSS 5 %libexpat project · libexpat15 февр. 2022 г.
- CVE-2022-2959940В плане
Commandline class shell injection vulnerabilities
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %apache · maven shared utils23 мая 2022 г.
- CVE-2025-3165140В плане
Apache Tomcat: Bypass of rules in Rewrite Valve
КритическаяCVSS 9,8Proof of conceptEPSS 4 %apache · tomcat28 апр. 2025 г.
- CVE-2019-1132540В плане
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %sensiolabs · symfony21 нояб. 2019 г.
- CVE-2021-2894040В плане
Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %magpierss project · magpierss2 апр. 2021 г.
- CVE-2018-924640В плане
The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ledgersmb · ledgersmb7 июн. 2018 г.
- CVE-2018-1549440В плане
In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %dojotoolkit · dojo17 авг. 2018 г.
- CVE-2024-3847440В плане
Apache HTTP Server weakness with encoded question marks in backreferences
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %apache · http server1 июл. 2024 г.
- CVE-2022-2617440В плане
A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload inje
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %beekeeperstudio · beekeeper-studio21 мар. 2022 г.
- CVE-2022-2299240В плане
Command Injection Remote Code Execution vulnerability on Western Digital My Cloud devices.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %westerndigital · my cloud os28 янв. 2022 г.
- CVE-2022-3515340В плане
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %fusionpbx · fusionpbx18 авг. 2022 г.
- CVE-2025-5573040В плане
XWiki Remote Macros vulnerable to remote code execution using the confluence paste code macro
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %xwikisas · xwiki-pro-macros9 сент. 2025 г.
- CVE-2025-5572940В плане
XWiki Remote Macros vulnerable to remote code execution using the ConfluenceLayoutSection macro
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %xwikisas · xwiki-pro-macros9 сент. 2025 г.