İçeriğe atla
Noroxi

CWE-116 · 336 kayıt

Improper Encoding or Escaping of Output

Bu sınıftaki CVE’ler

338 kayıt

  • Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.

    KritikCVSS 9,1KEVSilahlaştırılmışEPSS %100

    apache · http server1 Tem 2024

  • CVE-2022-42948
    70Bu hafta

    Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %3

    helpsystems · cobalt strike24 Mar 2023

  • CVE-2026-20245
    69Bu hafta

    Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %25

    cisco · catalyst sd-wan manager4 Haz 2026

  • CVE-2022-36446
    68Bu hafta

    software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

    KritikCVSS 9,8SilahlaştırılmışEPSS %96

    webmin · webmin25 Tem 2022

  • CVE-2022-24682
    63Bu hafta

    An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the w

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %31

    synacor · zimbra collaboration suite9 Şub 2022

  • CVE-2022-30781
    56Planlayın

    Gitea before 1.16.7 does not escape git fetch remote.

    YüksekCVSS 7,5SilahlaştırılmışEPSS %88

    gitea · gitea16 May 2022

  • CVE-2021-31806
    55Planlayın

    An issue was discovered in Squid before 4.15 and 5.x before 5.0.6.

    OrtaCVSS 6,5SilahlaştırılmışEPSS %96

    squid-cache · squid27 May 2021

  • CVE-2013-4547
    50Planlayın

    nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character i

    YüksekCVSS 7,5Kavram kanıtıEPSS %68

    f5 · nginx23 Kas 2013

  • CVE-2021-28662
    48Planlayın

    An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6.

    OrtaCVSS 6,5İstismar yokEPSS %72

    squid-cache · squid27 May 2021

  • CVE-2024-1874
    47Planlayın

    Command injection via array-ish $command parameter of proc_open()

    KritikCVSS 9,4Kavram kanıtıEPSS %33

    php · php29 Nis 2024

  • CVE-2017-8303
    46Planlayın

    An issue was discovered on Accellion FTA devices before FTA_9_12_180.

    KritikCVSS 9,8İstismar yokEPSS %24

    accellion · file transfer appliance5 May 2017

  • CVE-2024-38473
    40Planlayın

    Apache HTTP Server proxy encoding problem

    YüksekCVSS 8,1Kavram kanıtıEPSS %26

    apache · http server1 Tem 2024

  • CVE-2022-25235
    40Planlayın

    xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is val

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    libexpat project · libexpat15 Şub 2022

  • CVE-2022-29599
    40Planlayın

    Commandline class shell injection vulnerabilities

    KritikCVSS 9,8İstismar yokEPSS %4

    apache · maven shared utils23 May 2022

  • CVE-2025-31651
    40Planlayın

    Apache Tomcat: Bypass of rules in Rewrite Valve

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    apache · tomcat28 Nis 2025

  • CVE-2019-11325
    40Planlayın

    An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8.

    KritikCVSS 9,8İstismar yokEPSS %3

    sensiolabs · symfony21 Kas 2019

  • CVE-2021-28940
    40Planlayın

    Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command

    KritikCVSS 9,8İstismar yokEPSS %3

    magpierss project · magpierss2 Nis 2021

  • CVE-2018-9246
    40Planlayın

    The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable

    KritikCVSS 9,8İstismar yokEPSS %3

    ledgersmb · ledgersmb7 Haz 2018

  • CVE-2018-15494
    40Planlayın

    In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.

    KritikCVSS 9,8İstismar yokEPSS %3

    dojotoolkit · dojo17 Ağu 2018

  • CVE-2024-38474
    40Planlayın

    Apache HTTP Server weakness with encoded question marks in backreferences

    KritikCVSS 9,8İstismar yokEPSS %2

    apache · http server1 Tem 2024

  • CVE-2022-26174
    40Planlayın

    A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload inje

    KritikCVSS 9,8İstismar yokEPSS %2

    beekeeperstudio · beekeeper-studio21 Mar 2022

  • CVE-2022-22992
    40Planlayın

    Command Injection Remote Code Execution vulnerability on Western Digital My Cloud devices.

    KritikCVSS 9,8İstismar yokEPSS %2

    westerndigital · my cloud os28 Oca 2022

  • CVE-2022-35153
    40Planlayın

    FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.

    KritikCVSS 9,8İstismar yokEPSS %2

    fusionpbx · fusionpbx18 Ağu 2022

  • CVE-2025-55730
    40Planlayın

    XWiki Remote Macros vulnerable to remote code execution using the confluence paste code macro

    KritikCVSS 10,0İstismar yokEPSS %1

    xwikisas · xwiki-pro-macros9 Eyl 2025

  • CVE-2025-55729
    40Planlayın

    XWiki Remote Macros vulnerable to remote code execution using the ConfluenceLayoutSection macro

    KritikCVSS 10,0İstismar yokEPSS %1

    xwikisas · xwiki-pro-macros9 Eyl 2025

Tüm zafiyet sınıfları