İçeriğe atla
Noroxi

CWE-74 · 5.324 kayıt

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Bu sınıftaki CVE’ler

5.335 kayıt

  • Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · archiva19 Tem 2013

  • A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    atlassian · confluence data center16 Oca 2024

  • Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    oracle · agile product lifecycle management26 Nis 2019

  • /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    glpi-project · glpi19 Eyl 2022

  • Unauthenticated Command Injection

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    cacti · cacti5 Ara 2022

  • Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %98

    cisco · identity services engine25 Haz 2025

  • vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %87

    vbulletin · vbulletin12 Ağu 2020

  • There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail a

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %85

    atlassian · jira server9 Ağu 2019

  • Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter.

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %99

    apache · solr30 Ara 2019

  • Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %68

    cisco · identity services engine16 Tem 2025

  • Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)

    YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %98

    hitachi · vantara pentaho business analytics server3 Nis 2023

  • Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted insta

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %85

    synacor · zimbra collaboration suite20 Nis 2022

  • CVE-2016-4010
    67Bu hafta

    Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted

    KritikCVSS 9,8SilahlaştırılmışEPSS %93

    magento · magento23 Oca 2017

  • CVE-2020-8468
    67Bu hafta

    Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation esc

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %6

    trendmicro · apex one17 Mar 2020

  • CVE-2024-10914
    65Bu hafta

    D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection

    KritikCVSS 9,2Kavram kanıtıEPSS %96

    dlink · dns-320 firmware6 Kas 2024

  • CVE-2022-2992
    65Bu hafta

    A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated us

    KritikCVSS 9,9SilahlaştırılmışEPSS %86

    gitlab · gitlab17 Eki 2022

  • CVE-2013-3214
    64Bu hafta

    vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

    KritikCVSS 9,8SilahlaştırılmışEPSS %85

    vtiger · vtiger crm28 Oca 2020

  • CVE-2021-38294
    64Bu hafta

    Shell Command Injection Vulnerability in Nimbus Thrift Server

    KritikCVSS 9,8SilahlaştırılmışEPSS %84

    apache · storm25 Eki 2021

  • CVE-2018-16763
    64Bu hafta

    FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.

    KritikCVSS 9,8Kavram kanıtıEPSS %83

    thedaylightstudio · fuel cms9 Eyl 2018

  • CVE-2012-1495
    63Bu hafta

    install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.

    KritikCVSS 9,8SilahlaştırılmışEPSS %80

    webcalendar project · webcalendar27 Oca 2020

  • CVE-2023-37462
    62Bu hafta

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-skin-ui

    YüksekCVSS 8,8Kavram kanıtıEPSS %92

    xwiki · xwiki14 Tem 2023

  • CVE-2024-22319
    62Bu hafta

    IBM Operational Decision Manager JDNI injection

    KritikCVSS 9,8Kavram kanıtıEPSS %76

    ibm · operational decision manager1 Şub 2024

  • CVE-2023-30547
    62Bu hafta

    Sandbox Escape in vm2

    KritikCVSS 10,0Kavram kanıtıEPSS %72

    vm2 project · vm217 Nis 2023

  • CVE-2021-41282
    61Bu hafta

    diag_routes.php in pfSense 2.5.2 allows sed data injection.

    YüksekCVSS 8,8SilahlaştırılmışEPSS %87

    pfsense · pfsense1 Mar 2022

  • CVE-2021-21242
    61Bu hafta

    Pre-Auth Unsafe Deserialization on AttachmentUploadServet

    KritikCVSS 9,8İstismar yokEPSS %74

    onedev project · onedev15 Oca 2021

Tüm zafiyet sınıfları