CWE-116 · 336 kayıt
Improper Encoding or Escaping of Output
Bu sınıftaki CVE’ler
338 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
96Hemen | CVE-2024-38475Silahlaştırılmış | Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.apache · http server · CWE-116 | Kritik9,1 | KEV | %100,0 | 1 Tem 2024 |
70Bu hafta | CVE-2022-42948Silahlaştırılmış | Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components.helpsystems · cobalt strike · CWE-116 | Kritik9,8 | KEV | %2,7 | 24 Mar 2023 |
69Bu hafta | CVE-2026-20245Silahlaştırılmış | Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerabilitycisco · catalyst sd-wan manager · CWE-116 | Yüksek7,8 | KEV | %25,3 | 4 Haz 2026 |
68Bu hafta | CVE-2022-36446Silahlaştırılmış | software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.webmin · webmin · CWE-116 | Kritik9,8 | — | %96,0 | 25 Tem 2022 |
63Bu hafta | CVE-2022-24682Silahlaştırılmış | An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wsynacor · zimbra collaboration suite · CWE-116 | Orta6,1 | KEV | %30,9 | 9 Şub 2022 |
56Planlayın | CVE-2022-30781Silahlaştırılmış | Gitea before 1.16.7 does not escape git fetch remote.gitea · gitea · CWE-116 | Yüksek7,5 | — | %87,9 | 16 May 2022 |
55Planlayın | CVE-2021-31806Silahlaştırılmış | An issue was discovered in Squid before 4.15 and 5.x before 5.0.6.squid-cache · squid · CWE-116 | Orta6,5 | — | %95,8 | 27 May 2021 |
50Planlayın | CVE-2013-4547Kavram kanıtı | nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character if5 · nginx · CWE-116 | Yüksek7,5 | — | %67,7 | 23 Kas 2013 |
48Planlayın | CVE-2021-28662İstismar yok | An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6.squid-cache · squid · CWE-116 | Orta6,5 | — | %71,8 | 27 May 2021 |
47Planlayın | CVE-2024-1874Kavram kanıtı | Command injection via array-ish $command parameter of proc_open()php · php · CWE-116 | Kritik9,4 | — | %32,6 | 29 Nis 2024 |
46Planlayın | CVE-2017-8303İstismar yok | An issue was discovered on Accellion FTA devices before FTA_9_12_180.accellion · file transfer appliance · CWE-116 | Kritik9,8 | — | %24,2 | 5 May 2017 |
40Planlayın | CVE-2024-38473Kavram kanıtı | Apache HTTP Server proxy encoding problemapache · http server · CWE-116 | Yüksek8,1 | — | %25,9 | 1 Tem 2024 |
40Planlayın | CVE-2022-25235Kavram kanıtı | xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is vallibexpat project · libexpat · CWE-116 | Kritik9,8 | — | %5,0 | 15 Şub 2022 |
40Planlayın | CVE-2022-29599İstismar yok | Commandline class shell injection vulnerabilitiesapache · maven shared utils · CWE-116 | Kritik9,8 | — | %4,4 | 23 May 2022 |
40Planlayın | CVE-2025-31651Kavram kanıtı | Apache Tomcat: Bypass of rules in Rewrite Valveapache · tomcat · CWE-116 | Kritik9,8 | — | %4,2 | 28 Nis 2025 |
40Planlayın | CVE-2019-11325İstismar yok | An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8.sensiolabs · symfony · CWE-116 | Kritik9,8 | — | %3,4 | 21 Kas 2019 |
40Planlayın | CVE-2021-28940İstismar yok | Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra commandmagpierss project · magpierss · CWE-116 | Kritik9,8 | — | %3,3 | 2 Nis 2021 |
40Planlayın | CVE-2018-9246İstismar yok | The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variableledgersmb · ledgersmb · CWE-116 | Kritik9,8 | — | %2,6 | 7 Haz 2018 |
40Planlayın | CVE-2018-15494İstismar yok | In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.dojotoolkit · dojo · CWE-116 | Kritik9,8 | — | %2,5 | 17 Ağu 2018 |
40Planlayın | CVE-2024-38474İstismar yok | Apache HTTP Server weakness with encoded question marks in backreferencesapache · http server · CWE-116 | Kritik9,8 | — | %2,5 | 1 Tem 2024 |
40Planlayın | CVE-2022-26174İstismar yok | A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload injebeekeeperstudio · beekeeper-studio · CWE-116 | Kritik9,8 | — | %2,4 | 21 Mar 2022 |
40Planlayın | CVE-2022-22992İstismar yok | Command Injection Remote Code Execution vulnerability on Western Digital My Cloud devices.westerndigital · my cloud os · CWE-116 | Kritik9,8 | — | %2,3 | 28 Oca 2022 |
40Planlayın | CVE-2022-35153İstismar yok | FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.fusionpbx · fusionpbx · CWE-116 | Kritik9,8 | — | %1,8 | 18 Ağu 2022 |
40Planlayın | CVE-2025-55730İstismar yok | XWiki Remote Macros vulnerable to remote code execution using the confluence paste code macroxwikisas · xwiki-pro-macros · CWE-116 | Kritik10,0 | — | %0,7 | 9 Eyl 2025 |
40Planlayın | CVE-2025-55729İstismar yok | XWiki Remote Macros vulnerable to remote code execution using the ConfluenceLayoutSection macroxwikisas · xwiki-pro-macros · CWE-116 | Kritik10,0 | — | %0,7 | 9 Eyl 2025 |
- CVE-2024-3847596Hemen
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %100apache · http server1 Tem 2024
- CVE-2022-4294870Bu hafta
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %3helpsystems · cobalt strike24 Mar 2023
- CVE-2026-2024569Bu hafta
Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %25cisco · catalyst sd-wan manager4 Haz 2026
- CVE-2022-3644668Bu hafta
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
KritikCVSS 9,8SilahlaştırılmışEPSS %96webmin · webmin25 Tem 2022
- CVE-2022-2468263Bu hafta
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the w
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %31synacor · zimbra collaboration suite9 Şub 2022
- CVE-2022-3078156Planlayın
Gitea before 1.16.7 does not escape git fetch remote.
YüksekCVSS 7,5SilahlaştırılmışEPSS %88gitea · gitea16 May 2022
- CVE-2021-3180655Planlayın
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6.
OrtaCVSS 6,5SilahlaştırılmışEPSS %96squid-cache · squid27 May 2021
- CVE-2013-454750Planlayın
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character i
YüksekCVSS 7,5Kavram kanıtıEPSS %68f5 · nginx23 Kas 2013
- CVE-2021-2866248Planlayın
An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6.
OrtaCVSS 6,5İstismar yokEPSS %72squid-cache · squid27 May 2021
- CVE-2024-187447Planlayın
Command injection via array-ish $command parameter of proc_open()
KritikCVSS 9,4Kavram kanıtıEPSS %33php · php29 Nis 2024
- CVE-2017-830346Planlayın
An issue was discovered on Accellion FTA devices before FTA_9_12_180.
KritikCVSS 9,8İstismar yokEPSS %24accellion · file transfer appliance5 May 2017
- CVE-2024-3847340Planlayın
Apache HTTP Server proxy encoding problem
YüksekCVSS 8,1Kavram kanıtıEPSS %26apache · http server1 Tem 2024
- CVE-2022-2523540Planlayın
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is val
KritikCVSS 9,8Kavram kanıtıEPSS %5libexpat project · libexpat15 Şub 2022
- CVE-2022-2959940Planlayın
Commandline class shell injection vulnerabilities
KritikCVSS 9,8İstismar yokEPSS %4apache · maven shared utils23 May 2022
- CVE-2025-3165140Planlayın
Apache Tomcat: Bypass of rules in Rewrite Valve
KritikCVSS 9,8Kavram kanıtıEPSS %4apache · tomcat28 Nis 2025
- CVE-2019-1132540Planlayın
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8.
KritikCVSS 9,8İstismar yokEPSS %3sensiolabs · symfony21 Kas 2019
- CVE-2021-2894040Planlayın
Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command
KritikCVSS 9,8İstismar yokEPSS %3magpierss project · magpierss2 Nis 2021
- CVE-2018-924640Planlayın
The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable
KritikCVSS 9,8İstismar yokEPSS %3ledgersmb · ledgersmb7 Haz 2018
- CVE-2018-1549440Planlayın
In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.
KritikCVSS 9,8İstismar yokEPSS %3dojotoolkit · dojo17 Ağu 2018
- CVE-2024-3847440Planlayın
Apache HTTP Server weakness with encoded question marks in backreferences
KritikCVSS 9,8İstismar yokEPSS %2apache · http server1 Tem 2024
- CVE-2022-2617440Planlayın
A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload inje
KritikCVSS 9,8İstismar yokEPSS %2beekeeperstudio · beekeeper-studio21 Mar 2022
- CVE-2022-2299240Planlayın
Command Injection Remote Code Execution vulnerability on Western Digital My Cloud devices.
KritikCVSS 9,8İstismar yokEPSS %2westerndigital · my cloud os28 Oca 2022
- CVE-2022-3515340Planlayın
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
KritikCVSS 9,8İstismar yokEPSS %2fusionpbx · fusionpbx18 Ağu 2022
- CVE-2025-5573040Planlayın
XWiki Remote Macros vulnerable to remote code execution using the confluence paste code macro
KritikCVSS 10,0İstismar yokEPSS %1xwikisas · xwiki-pro-macros9 Eyl 2025
- CVE-2025-5572940Planlayın
XWiki Remote Macros vulnerable to remote code execution using the ConfluenceLayoutSection macro
KritikCVSS 10,0İstismar yokEPSS %1xwikisas · xwiki-pro-macros9 Eyl 2025