Перейти к содержимому
Noroxi

CWE-74 · 5 324 записей

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CVE этого класса

5 335 записей

  • CVE-2013-2251
    99Срочно

    Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    apache · archiva19 июл. 2013 г.

  • CVE-2023-22527
    99Срочно

    A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    atlassian · confluence data center16 янв. 2024 г.

  • CVE-2019-2725
    99Срочно

    Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    oracle · agile product lifecycle management26 апр. 2019 г.

  • CVE-2022-35914
    99Срочно

    /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    glpi-project · glpi19 сент. 2022 г.

  • CVE-2022-46169
    99Срочно

    Unauthenticated Command Injection

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    cacti · cacti5 дек. 2022 г.

  • CVE-2025-20281
    99Срочно

    Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 98 %

    cisco · identity services engine25 июн. 2025 г.

  • CVE-2020-17496
    95Срочно

    vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 87 %

    vbulletin · vbulletin12 авг. 2020 г.

  • CVE-2019-11581
    94Срочно

    There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail a

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 85 %

    atlassian · jira server9 авг. 2019 г.

  • CVE-2019-17558
    90Срочно

    Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter.

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 99 %

    apache · solr30 дек. 2019 г.

  • CVE-2025-20337
    90Срочно

    Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 68 %

    cisco · identity services engine16 июл. 2025 г.

  • CVE-2022-43769
    87Срочно

    Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)

    ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 98 %

    hitachi · vantara pentaho business analytics server3 апр. 2023 г.

  • CVE-2022-27924
    86Срочно

    Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted insta

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 85 %

    synacor · zimbra collaboration suite20 апр. 2022 г.

  • CVE-2016-4010
    67На этой неделе

    Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted

    КритическаяCVSS 9,8Готовый эксплойтEPSS 93 %

    magento · magento23 янв. 2017 г.

  • CVE-2020-8468
    67На этой неделе

    Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esc

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 6 %

    trendmicro · apex one17 мар. 2020 г.

  • CVE-2024-10914
    65На этой неделе

    D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection

    КритическаяCVSS 9,2Proof of conceptEPSS 96 %

    dlink · dns-320 firmware6 нояб. 2024 г.

  • CVE-2022-2992
    65На этой неделе

    A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated us

    КритическаяCVSS 9,9Готовый эксплойтEPSS 86 %

    gitlab · gitlab17 окт. 2022 г.

  • CVE-2013-3214
    64На этой неделе

    vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 85 %

    vtiger · vtiger crm28 янв. 2020 г.

  • CVE-2021-38294
    64На этой неделе

    Shell Command Injection Vulnerability in Nimbus Thrift Server

    КритическаяCVSS 9,8Готовый эксплойтEPSS 84 %

    apache · storm25 окт. 2021 г.

  • CVE-2018-16763
    64На этой неделе

    FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.

    КритическаяCVSS 9,8Proof of conceptEPSS 83 %

    thedaylightstudio · fuel cms9 сент. 2018 г.

  • CVE-2012-1495
    63На этой неделе

    install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 80 %

    webcalendar project · webcalendar27 янв. 2020 г.

  • CVE-2023-37462
    62На этой неделе

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-skin-ui

    ВысокаяCVSS 8,8Proof of conceptEPSS 92 %

    xwiki · xwiki14 июл. 2023 г.

  • CVE-2024-22319
    62На этой неделе

    IBM Operational Decision Manager JDNI injection

    КритическаяCVSS 9,8Proof of conceptEPSS 76 %

    ibm · operational decision manager1 февр. 2024 г.

  • CVE-2023-30547
    62На этой неделе

    Sandbox Escape in vm2

    КритическаяCVSS 10,0Proof of conceptEPSS 72 %

    vm2 project · vm217 апр. 2023 г.

  • CVE-2021-41282
    61На этой неделе

    diag_routes.php in pfSense 2.5.2 allows sed data injection.

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 87 %

    pfsense · pfsense1 мар. 2022 г.

  • CVE-2021-21242
    61На этой неделе

    Pre-Auth Unsafe Deserialization on AttachmentUploadServet

    КритическаяCVSS 9,8Эксплойта нетEPSS 74 %

    onedev project · onedev15 янв. 2021 г.

Все классы уязвимостей