CWE-74 · 5.324 kayıt
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Bu sınıftaki CVE’ler
5.335 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2013-2251Silahlaştırılmış | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,apache · archiva · CWE-74 | Kritik9,8 | KEV | %100,0 | 19 Tem 2013 |
99Hemen | CVE-2023-22527Silahlaştırılmış | A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE atlassian · confluence data center · CWE-74 | Kritik9,8 | KEV | %100,0 | 16 Oca 2024 |
99Hemen | CVE-2019-2725Silahlaştırılmış | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).oracle · agile product lifecycle management · CWE-74 | Kritik9,8 | KEV | %100,0 | 26 Nis 2019 |
99Hemen | CVE-2022-35914Silahlaştırılmış | /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.glpi-project · glpi · CWE-74 | Kritik9,8 | KEV | %99,9 | 19 Eyl 2022 |
99Hemen | CVE-2022-46169Silahlaştırılmış | Unauthenticated Command Injectioncacti · cacti · CWE-74 | Kritik9,8 | KEV | %99,8 | 5 Ara 2022 |
99Hemen | CVE-2025-20281Silahlaştırılmış | Cisco ISE API Unauthenticated Remote Code Execution Vulnerabilitycisco · identity services engine · CWE-74 | Kritik10,0 | KEV | %97,6 | 25 Haz 2025 |
95Hemen | CVE-2020-17496Silahlaştırılmış | vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panelvbulletin · vbulletin · CWE-74 | Kritik9,8 | KEV | %87,4 | 12 Ağu 2020 |
94Hemen | CVE-2019-11581Silahlaştırılmış | There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail aatlassian · jira server · CWE-74 | Kritik9,8 | KEV | %84,6 | 9 Ağu 2019 |
90Hemen | CVE-2019-17558Silahlaştırılmış | Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter.apache · solr · CWE-74 | Yüksek7,5 | KEV | %98,6 | 30 Ara 2019 |
90Hemen | CVE-2025-20337Silahlaştırılmış | Cisco ISE API Unauthenticated Remote Code Execution Vulnerabilitycisco · identity services engine · CWE-74 | Kritik10,0 | KEV | %67,8 | 16 Tem 2025 |
87Hemen | CVE-2022-43769Silahlaştırılmış | Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)hitachi · vantara pentaho business analytics server · CWE-74 | Yüksek7,2 | KEV | %97,7 | 3 Nis 2023 |
86Hemen | CVE-2022-27924Silahlaştırılmış | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instasynacor · zimbra collaboration suite · CWE-74 | Yüksek7,5 | KEV | %85,4 | 20 Nis 2022 |
67Bu hafta | CVE-2016-4010Silahlaştırılmış | Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via craftedmagento · magento · CWE-74 | Kritik9,8 | — | %92,9 | 23 Oca 2017 |
67Bu hafta | CVE-2020-8468Silahlaştırılmış | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esctrendmicro · apex one · CWE-74 | Yüksek8,8 | KEV | %6,2 | 17 Mar 2020 |
65Bu hafta | CVE-2024-10914Kavram kanıtı | D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injectiondlink · dns-320 firmware · CWE-74 | Kritik9,2 | — | %96,3 | 6 Kas 2024 |
65Bu hafta | CVE-2022-2992Silahlaştırılmış | A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated usgitlab · gitlab · CWE-74 | Kritik9,9 | — | %86,2 | 17 Eki 2022 |
64Bu hafta | CVE-2013-3214Silahlaştırılmış | vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.vtiger · vtiger crm · CWE-74 | Kritik9,8 | — | %84,5 | 28 Oca 2020 |
64Bu hafta | CVE-2021-38294Silahlaştırılmış | Shell Command Injection Vulnerability in Nimbus Thrift Serverapache · storm · CWE-74 | Kritik9,8 | — | %83,8 | 25 Eki 2021 |
64Bu hafta | CVE-2018-16763Kavram kanıtı | FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.thedaylightstudio · fuel cms · CWE-74 | Kritik9,8 | — | %82,9 | 9 Eyl 2018 |
63Bu hafta | CVE-2012-1495Silahlaştırılmış | install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.webcalendar project · webcalendar · CWE-74 | Kritik9,8 | — | %79,8 | 27 Oca 2020 |
62Bu hafta | CVE-2023-37462Kavram kanıtı | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-skin-uixwiki · xwiki · CWE-74 | Yüksek8,8 | — | %91,6 | 14 Tem 2023 |
62Bu hafta | CVE-2024-22319Kavram kanıtı | IBM Operational Decision Manager JDNI injectionibm · operational decision manager · CWE-74 | Kritik9,8 | — | %76,4 | 1 Şub 2024 |
62Bu hafta | CVE-2023-30547Kavram kanıtı | Sandbox Escape in vm2vm2 project · vm2 · CWE-74 | Kritik10,0 | — | %72,1 | 17 Nis 2023 |
61Bu hafta | CVE-2021-41282Silahlaştırılmış | diag_routes.php in pfSense 2.5.2 allows sed data injection.pfsense · pfsense · CWE-74 | Yüksek8,8 | — | %87,1 | 1 Mar 2022 |
61Bu hafta | CVE-2021-21242İstismar yok | Pre-Auth Unsafe Deserialization on AttachmentUploadServetonedev project · onedev · CWE-74 | Kritik9,8 | — | %74,2 | 15 Oca 2021 |
- CVE-2013-225199Hemen
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100apache · archiva19 Tem 2013
- CVE-2023-2252799Hemen
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100atlassian · confluence data center16 Oca 2024
- CVE-2019-272599Hemen
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100oracle · agile product lifecycle management26 Nis 2019
- CVE-2022-3591499Hemen
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100glpi-project · glpi19 Eyl 2022
- CVE-2022-4616999Hemen
Unauthenticated Command Injection
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100cacti · cacti5 Ara 2022
- CVE-2025-2028199Hemen
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %98cisco · identity services engine25 Haz 2025
- CVE-2020-1749695Hemen
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %87vbulletin · vbulletin12 Ağu 2020
- CVE-2019-1158194Hemen
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail a
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %85atlassian · jira server9 Ağu 2019
- CVE-2019-1755890Hemen
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %99apache · solr30 Ara 2019
- CVE-2025-2033790Hemen
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %68cisco · identity services engine16 Tem 2025
- CVE-2022-4376987Hemen
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %98hitachi · vantara pentaho business analytics server3 Nis 2023
- CVE-2022-2792486Hemen
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted insta
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %85synacor · zimbra collaboration suite20 Nis 2022
- CVE-2016-401067Bu hafta
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted
KritikCVSS 9,8SilahlaştırılmışEPSS %93magento · magento23 Oca 2017
- CVE-2020-846867Bu hafta
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esc
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %6trendmicro · apex one17 Mar 2020
- CVE-2024-1091465Bu hafta
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
KritikCVSS 9,2Kavram kanıtıEPSS %96dlink · dns-320 firmware6 Kas 2024
- CVE-2022-299265Bu hafta
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated us
KritikCVSS 9,9SilahlaştırılmışEPSS %86gitlab · gitlab17 Eki 2022
- CVE-2013-321464Bu hafta
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
KritikCVSS 9,8SilahlaştırılmışEPSS %85vtiger · vtiger crm28 Oca 2020
- CVE-2021-3829464Bu hafta
Shell Command Injection Vulnerability in Nimbus Thrift Server
KritikCVSS 9,8SilahlaştırılmışEPSS %84apache · storm25 Eki 2021
- CVE-2018-1676364Bu hafta
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.
KritikCVSS 9,8Kavram kanıtıEPSS %83thedaylightstudio · fuel cms9 Eyl 2018
- CVE-2012-149563Bu hafta
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.
KritikCVSS 9,8SilahlaştırılmışEPSS %80webcalendar project · webcalendar27 Oca 2020
- CVE-2023-3746262Bu hafta
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-skin-ui
YüksekCVSS 8,8Kavram kanıtıEPSS %92xwiki · xwiki14 Tem 2023
- CVE-2024-2231962Bu hafta
IBM Operational Decision Manager JDNI injection
KritikCVSS 9,8Kavram kanıtıEPSS %76ibm · operational decision manager1 Şub 2024
- CVE-2023-3054762Bu hafta
Sandbox Escape in vm2
KritikCVSS 10,0Kavram kanıtıEPSS %72vm2 project · vm217 Nis 2023
- CVE-2021-4128261Bu hafta
diag_routes.php in pfSense 2.5.2 allows sed data injection.
YüksekCVSS 8,8SilahlaştırılmışEPSS %87pfsense · pfsense1 Mar 2022
- CVE-2021-2124261Bu hafta
Pre-Auth Unsafe Deserialization on AttachmentUploadServet
KritikCVSS 9,8İstismar yokEPSS %74onedev project · onedev15 Oca 2021