Перейти к содержимому
Noroxi

CWE-116 · 336 записей

Improper Encoding or Escaping of Output

CVE этого класса

338 записей

  • CVE-2024-38475
    96Срочно

    Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.

    КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 100 %

    apache · http server1 июл. 2024 г.

  • CVE-2022-42948
    70На этой неделе

    Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 3 %

    helpsystems · cobalt strike24 мар. 2023 г.

  • CVE-2026-20245
    69На этой неделе

    Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 25 %

    cisco · catalyst sd-wan manager4 июн. 2026 г.

  • CVE-2022-36446
    68На этой неделе

    software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 96 %

    webmin · webmin25 июл. 2022 г.

  • CVE-2022-24682
    63На этой неделе

    An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the w

    СредняяCVSS 6,1KEVГотовый эксплойтEPSS 31 %

    synacor · zimbra collaboration suite9 февр. 2022 г.

  • CVE-2022-30781
    56В плане

    Gitea before 1.16.7 does not escape git fetch remote.

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 88 %

    gitea · gitea16 мая 2022 г.

  • CVE-2021-31806
    55В плане

    An issue was discovered in Squid before 4.15 and 5.x before 5.0.6.

    СредняяCVSS 6,5Готовый эксплойтEPSS 96 %

    squid-cache · squid27 мая 2021 г.

  • CVE-2013-4547
    50В плане

    nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character i

    ВысокаяCVSS 7,5Proof of conceptEPSS 68 %

    f5 · nginx23 нояб. 2013 г.

  • CVE-2021-28662
    48В плане

    An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6.

    СредняяCVSS 6,5Эксплойта нетEPSS 72 %

    squid-cache · squid27 мая 2021 г.

  • CVE-2024-1874
    47В плане

    Command injection via array-ish $command parameter of proc_open()

    КритическаяCVSS 9,4Proof of conceptEPSS 33 %

    php · php29 апр. 2024 г.

  • CVE-2017-8303
    46В плане

    An issue was discovered on Accellion FTA devices before FTA_9_12_180.

    КритическаяCVSS 9,8Эксплойта нетEPSS 24 %

    accellion · file transfer appliance5 мая 2017 г.

  • CVE-2024-38473
    40В плане

    Apache HTTP Server proxy encoding problem

    ВысокаяCVSS 8,1Proof of conceptEPSS 26 %

    apache · http server1 июл. 2024 г.

  • CVE-2022-25235
    40В плане

    xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is val

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    libexpat project · libexpat15 февр. 2022 г.

  • CVE-2022-29599
    40В плане

    Commandline class shell injection vulnerabilities

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    apache · maven shared utils23 мая 2022 г.

  • CVE-2025-31651
    40В плане

    Apache Tomcat: Bypass of rules in Rewrite Valve

    КритическаяCVSS 9,8Proof of conceptEPSS 4 %

    apache · tomcat28 апр. 2025 г.

  • CVE-2019-11325
    40В плане

    An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    sensiolabs · symfony21 нояб. 2019 г.

  • CVE-2021-28940
    40В плане

    Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    magpierss project · magpierss2 апр. 2021 г.

  • CVE-2018-9246
    40В плане

    The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    ledgersmb · ledgersmb7 июн. 2018 г.

  • CVE-2018-15494
    40В плане

    In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    dojotoolkit · dojo17 авг. 2018 г.

  • CVE-2024-38474
    40В плане

    Apache HTTP Server weakness with encoded question marks in backreferences

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    apache · http server1 июл. 2024 г.

  • CVE-2022-26174
    40В плане

    A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload inje

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    beekeeperstudio · beekeeper-studio21 мар. 2022 г.

  • CVE-2022-22992
    40В плане

    Command Injection Remote Code Execution vulnerability on Western Digital My Cloud devices.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    westerndigital · my cloud os28 янв. 2022 г.

  • CVE-2022-35153
    40В плане

    FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    fusionpbx · fusionpbx18 авг. 2022 г.

  • CVE-2025-55730
    40В плане

    XWiki Remote Macros vulnerable to remote code execution using the confluence paste code macro

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    xwikisas · xwiki-pro-macros9 сент. 2025 г.

  • CVE-2025-55729
    40В плане

    XWiki Remote Macros vulnerable to remote code execution using the ConfluenceLayoutSection macro

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    xwikisas · xwiki-pro-macros9 сент. 2025 г.

Все классы уязвимостей