CWE-74 · 5 324 записей
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE этого класса
5 335 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2013-2251Готовый эксплойт | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,apache · archiva · CWE-74 | Критическая9,8 | KEV | 100,0 % | 19 июл. 2013 г. |
99Срочно | CVE-2023-22527Готовый эксплойт | A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE atlassian · confluence data center · CWE-74 | Критическая9,8 | KEV | 100,0 % | 16 янв. 2024 г. |
99Срочно | CVE-2019-2725Готовый эксплойт | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).oracle · agile product lifecycle management · CWE-74 | Критическая9,8 | KEV | 100,0 % | 26 апр. 2019 г. |
99Срочно | CVE-2022-35914Готовый эксплойт | /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.glpi-project · glpi · CWE-74 | Критическая9,8 | KEV | 99,9 % | 19 сент. 2022 г. |
99Срочно | CVE-2022-46169Готовый эксплойт | Unauthenticated Command Injectioncacti · cacti · CWE-74 | Критическая9,8 | KEV | 99,8 % | 5 дек. 2022 г. |
99Срочно | CVE-2025-20281Готовый эксплойт | Cisco ISE API Unauthenticated Remote Code Execution Vulnerabilitycisco · identity services engine · CWE-74 | Критическая10,0 | KEV | 97,6 % | 25 июн. 2025 г. |
95Срочно | CVE-2020-17496Готовый эксплойт | vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panelvbulletin · vbulletin · CWE-74 | Критическая9,8 | KEV | 87,4 % | 12 авг. 2020 г. |
94Срочно | CVE-2019-11581Готовый эксплойт | There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail aatlassian · jira server · CWE-74 | Критическая9,8 | KEV | 84,6 % | 9 авг. 2019 г. |
90Срочно | CVE-2019-17558Готовый эксплойт | Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter.apache · solr · CWE-74 | Высокая7,5 | KEV | 98,6 % | 30 дек. 2019 г. |
90Срочно | CVE-2025-20337Готовый эксплойт | Cisco ISE API Unauthenticated Remote Code Execution Vulnerabilitycisco · identity services engine · CWE-74 | Критическая10,0 | KEV | 67,8 % | 16 июл. 2025 г. |
87Срочно | CVE-2022-43769Готовый эксплойт | Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)hitachi · vantara pentaho business analytics server · CWE-74 | Высокая7,2 | KEV | 97,7 % | 3 апр. 2023 г. |
86Срочно | CVE-2022-27924Готовый эксплойт | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instasynacor · zimbra collaboration suite · CWE-74 | Высокая7,5 | KEV | 85,4 % | 20 апр. 2022 г. |
67На этой неделе | CVE-2016-4010Готовый эксплойт | Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via craftedmagento · magento · CWE-74 | Критическая9,8 | — | 92,9 % | 23 янв. 2017 г. |
67На этой неделе | CVE-2020-8468Готовый эксплойт | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esctrendmicro · apex one · CWE-74 | Высокая8,8 | KEV | 6,2 % | 17 мар. 2020 г. |
65На этой неделе | CVE-2024-10914Proof of concept | D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injectiondlink · dns-320 firmware · CWE-74 | Критическая9,2 | — | 96,3 % | 6 нояб. 2024 г. |
65На этой неделе | CVE-2022-2992Готовый эксплойт | A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated usgitlab · gitlab · CWE-74 | Критическая9,9 | — | 86,2 % | 17 окт. 2022 г. |
64На этой неделе | CVE-2013-3214Готовый эксплойт | vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.vtiger · vtiger crm · CWE-74 | Критическая9,8 | — | 84,5 % | 28 янв. 2020 г. |
64На этой неделе | CVE-2021-38294Готовый эксплойт | Shell Command Injection Vulnerability in Nimbus Thrift Serverapache · storm · CWE-74 | Критическая9,8 | — | 83,8 % | 25 окт. 2021 г. |
64На этой неделе | CVE-2018-16763Proof of concept | FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.thedaylightstudio · fuel cms · CWE-74 | Критическая9,8 | — | 82,9 % | 9 сент. 2018 г. |
63На этой неделе | CVE-2012-1495Готовый эксплойт | install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.webcalendar project · webcalendar · CWE-74 | Критическая9,8 | — | 79,8 % | 27 янв. 2020 г. |
62На этой неделе | CVE-2023-37462Proof of concept | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-skin-uixwiki · xwiki · CWE-74 | Высокая8,8 | — | 91,6 % | 14 июл. 2023 г. |
62На этой неделе | CVE-2024-22319Proof of concept | IBM Operational Decision Manager JDNI injectionibm · operational decision manager · CWE-74 | Критическая9,8 | — | 76,4 % | 1 февр. 2024 г. |
62На этой неделе | CVE-2023-30547Proof of concept | Sandbox Escape in vm2vm2 project · vm2 · CWE-74 | Критическая10,0 | — | 72,1 % | 17 апр. 2023 г. |
61На этой неделе | CVE-2021-41282Готовый эксплойт | diag_routes.php in pfSense 2.5.2 allows sed data injection.pfsense · pfsense · CWE-74 | Высокая8,8 | — | 87,1 % | 1 мар. 2022 г. |
61На этой неделе | CVE-2021-21242Эксплойта нет | Pre-Auth Unsafe Deserialization on AttachmentUploadServetonedev project · onedev · CWE-74 | Критическая9,8 | — | 74,2 % | 15 янв. 2021 г. |
- CVE-2013-225199Срочно
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · archiva19 июл. 2013 г.
- CVE-2023-2252799Срочно
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center16 янв. 2024 г.
- CVE-2019-272599Срочно
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %oracle · agile product lifecycle management26 апр. 2019 г.
- CVE-2022-3591499Срочно
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %glpi-project · glpi19 сент. 2022 г.
- CVE-2022-4616999Срочно
Unauthenticated Command Injection
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %cacti · cacti5 дек. 2022 г.
- CVE-2025-2028199Срочно
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 98 %cisco · identity services engine25 июн. 2025 г.
- CVE-2020-1749695Срочно
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 87 %vbulletin · vbulletin12 авг. 2020 г.
- CVE-2019-1158194Срочно
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 85 %atlassian · jira server9 авг. 2019 г.
- CVE-2019-1755890Срочно
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter.
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 99 %apache · solr30 дек. 2019 г.
- CVE-2025-2033790Срочно
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 68 %cisco · identity services engine16 июл. 2025 г.
- CVE-2022-4376987Срочно
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 98 %hitachi · vantara pentaho business analytics server3 апр. 2023 г.
- CVE-2022-2792486Срочно
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted insta
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 85 %synacor · zimbra collaboration suite20 апр. 2022 г.
- CVE-2016-401067На этой неделе
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted
КритическаяCVSS 9,8Готовый эксплойтEPSS 93 %magento · magento23 янв. 2017 г.
- CVE-2020-846867На этой неделе
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esc
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 6 %trendmicro · apex one17 мар. 2020 г.
- CVE-2024-1091465На этой неделе
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
КритическаяCVSS 9,2Proof of conceptEPSS 96 %dlink · dns-320 firmware6 нояб. 2024 г.
- CVE-2022-299265На этой неделе
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated us
КритическаяCVSS 9,9Готовый эксплойтEPSS 86 %gitlab · gitlab17 окт. 2022 г.
- CVE-2013-321464На этой неделе
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
КритическаяCVSS 9,8Готовый эксплойтEPSS 85 %vtiger · vtiger crm28 янв. 2020 г.
- CVE-2021-3829464На этой неделе
Shell Command Injection Vulnerability in Nimbus Thrift Server
КритическаяCVSS 9,8Готовый эксплойтEPSS 84 %apache · storm25 окт. 2021 г.
- CVE-2018-1676364На этой неделе
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.
КритическаяCVSS 9,8Proof of conceptEPSS 83 %thedaylightstudio · fuel cms9 сент. 2018 г.
- CVE-2012-149563На этой неделе
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.
КритическаяCVSS 9,8Готовый эксплойтEPSS 80 %webcalendar project · webcalendar27 янв. 2020 г.
- CVE-2023-3746262На этой неделе
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-skin-ui
ВысокаяCVSS 8,8Proof of conceptEPSS 92 %xwiki · xwiki14 июл. 2023 г.
- CVE-2024-2231962На этой неделе
IBM Operational Decision Manager JDNI injection
КритическаяCVSS 9,8Proof of conceptEPSS 76 %ibm · operational decision manager1 февр. 2024 г.
- CVE-2023-3054762На этой неделе
Sandbox Escape in vm2
КритическаяCVSS 10,0Proof of conceptEPSS 72 %vm2 project · vm217 апр. 2023 г.
- CVE-2021-4128261На этой неделе
diag_routes.php in pfSense 2.5.2 allows sed data injection.
ВысокаяCVSS 8,8Готовый эксплойтEPSS 87 %pfsense · pfsense1 мар. 2022 г.
- CVE-2021-2124261На этой неделе
Pre-Auth Unsafe Deserialization on AttachmentUploadServet
КритическаяCVSS 9,8Эксплойта нетEPSS 74 %onedev project · onedev15 янв. 2021 г.