CWE-75 · 29 kayıt
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
Bu sınıftaki CVE’ler
29 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
68Bu hafta | CVE-2021-22911Kavram kanıtı | A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injectiorocket.chat · rocket.chat · CWE-75 | Kritik9,8 | — | %95,2 | 27 May 2021 |
43Planlayın | CVE-2024-0801Kavram kanıtı | Unauthenticated DoS in Arcserve Unified Data Protectionarcserve · udp · CWE-75 | Yüksek7,5 | — | %41,8 | 13 Mar 2024 |
40Planlayın | CVE-2021-22910İstismar yok | A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which couldrocket.chat · rocket.chat · CWE-75 | Kritik9,8 | — | %2,3 | 9 Ağu 2021 |
39İzleyin | CVE-2024-35373İstismar yok | Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.mocodo · mocodo online · CWE-75 | Kritik9,8 | — | %1,2 | 24 May 2024 |
39İzleyin | CVE-2025-50213İstismar yok | Apache Airflow Providers Snowflake: Potential SQL injection in CopyFromExternalStageToSnowflakeOperatorapache · apache-airflow-providers-snowflake · CWE-75 | Kritik9,8 | — | %0,7 | 24 Haz 2025 |
37İzleyin | CVE-2021-39174Kavram kanıtı | Cachet is an open source status page system.catchethq · catchet · CWE-75 | Yüksek8,8 | — | %5,0 | 27 Ağu 2021 |
37İzleyin | CVE-2022-24039İstismar yok | A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884).siemens · desigo pxc5 firmware · CWE-75 | Kritik9,0 | — | %2,0 | 10 May 2022 |
36İzleyin | CVE-2026-29042İstismar yok | Nuclio Shell Runtime Command Injection Leading to Privilege Escalationiguazio · nuclio · CWE-75 | Yüksek8,9 | — | %3,3 | 6 Mar 2026 |
36İzleyin | CVE-2023-27533İstismar yok | A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on malihaxx · curl · CWE-75 | Yüksek8,8 | — | %2,0 | 30 Mar 2023 |
36İzleyin | CVE-2026-31908Kavram kanıtı | Apache APISIX: forward auth plugin allows header injectionapache · apisix · CWE-75 | Kritik9,1 | — | %0,6 | 14 Nis 2026 |
35İzleyin | CVE-2024-37779İstismar yok | WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant scriptCWE-75 | Yüksek8,8 | — | %1,1 | 23 Eyl 2024 |
35İzleyin | CVE-2024-31809İstismar yok | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in thtotolink · ex200 firmware · CWE-75 | Yüksek8,8 | — | %1,0 | 8 Nis 2024 |
35İzleyin | CVE-2023-23912İstismar yok | A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with tui · usg firmware · CWE-75 | Yüksek8,8 | — | %1,0 | 9 Şub 2023 |
34İzleyin | CVE-2024-58362İstismar yok | SurrealDB before 1.5.5 Query Injection via RPC APIsurrealdb · surrealdb · CWE-75 | Yüksek8,7 | — | %0,6 | 18 Tem 2026 |
32İzleyin | CVE-2022-48217İstismar yok | The tf_remapper_node component 1.1.1 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in ttradr-project · tf remapper · CWE-75 | Yüksek8,1 | — | %0,7 | 4 Oca 2023 |
32İzleyin | CVE-2026-54771İstismar yok | Langroid: handle_message() executes user-supplied tool JSON without sender verificationlangroid · langroid · CWE-75 | Yüksek8,1 | — | %0,4 | 9 Tem 2026 |
31İzleyin | CVE-2023-0302İstismar yok | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in radareorg/radare2radare · radare2 · CWE-75 | Yüksek7,8 | — | %0,4 | 14 Oca 2023 |
30İzleyin | CVE-2024-24257İstismar yok | An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information vCWE-75 | Yüksek7,5 | — | %0,4 | 26 Tem 2024 |
29İzleyin | CVE-2024-27622İstismar yok | A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21.cmsmadesimple · cms made simple · CWE-75 | Yüksek7,2 | — | %2,0 | 5 Mar 2024 |
26İzleyin | CVE-2024-31806İstismar yok | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which ctotolink · ex200 firmware · CWE-75 | Orta6,5 | — | %0,4 | 8 Nis 2024 |
26İzleyin | CVE-2024-31812İstismar yok | In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExttotolink · ex200 firmware · CWE-75 | Orta6,5 | — | %0,3 | 8 Nis 2024 |
24İzleyin | CVE-2022-3607İstismar yok | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in octoprint/octoprintoctoprint · octoprint · CWE-75 | Orta6,0 | — | %0,4 | 19 Eki 2022 |
24İzleyin | CVE-2026-27120İstismar yok | Leaf-kit html escaping does not work on characters that are part of extended grapheme clustervapor · leafkit · CWE-75 | Orta6,1 | — | %0,3 | 20 Şub 2026 |
22İzleyin | CVE-2025-61911İstismar yok | python-ldap has sanitization bypass in ldap.filter.escape_filter_charspython-ldap · python-ldap · CWE-75 | Orta5,5 | — | %0,3 | 10 Eki 2025 |
21İzleyin | CVE-2023-1758İstismar yok | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in thorsten/phpmyfaqphpmyfaq · phpmyfaq · CWE-75 | Orta5,4 | — | %0,5 | 5 Nis 2023 |
- CVE-2021-2291168Bu hafta
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injectio
KritikCVSS 9,8Kavram kanıtıEPSS %95rocket.chat · rocket.chat27 May 2021
- CVE-2024-080143Planlayın
Unauthenticated DoS in Arcserve Unified Data Protection
YüksekCVSS 7,5Kavram kanıtıEPSS %42arcserve · udp13 Mar 2024
- CVE-2021-2291040Planlayın
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could
KritikCVSS 9,8İstismar yokEPSS %2rocket.chat · rocket.chat9 Ağu 2021
- CVE-2024-3537339İzleyin
Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.
KritikCVSS 9,8İstismar yokEPSS %1mocodo · mocodo online24 May 2024
- CVE-2025-5021339İzleyin
Apache Airflow Providers Snowflake: Potential SQL injection in CopyFromExternalStageToSnowflakeOperator
KritikCVSS 9,8İstismar yokEPSS %1apache · apache-airflow-providers-snowflake24 Haz 2025
- CVE-2021-3917437İzleyin
Cachet is an open source status page system.
YüksekCVSS 8,8Kavram kanıtıEPSS %5catchethq · catchet27 Ağu 2021
- CVE-2022-2403937İzleyin
A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884).
KritikCVSS 9,0İstismar yokEPSS %2siemens · desigo pxc5 firmware10 May 2022
- CVE-2026-2904236İzleyin
Nuclio Shell Runtime Command Injection Leading to Privilege Escalation
YüksekCVSS 8,9İstismar yokEPSS %3iguazio · nuclio6 Mar 2026
- CVE-2023-2753336İzleyin
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on mali
YüksekCVSS 8,8İstismar yokEPSS %2haxx · curl30 Mar 2023
- CVE-2026-3190836İzleyin
Apache APISIX: forward auth plugin allows header injection
KritikCVSS 9,1Kavram kanıtıEPSS %1apache · apisix14 Nis 2026
- CVE-2024-3777935İzleyin
WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script
YüksekCVSS 8,8İstismar yokEPSS %123 Eyl 2024
- CVE-2024-3180935İzleyin
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in th
YüksekCVSS 8,8İstismar yokEPSS %1totolink · ex200 firmware8 Nis 2024
- CVE-2023-2391235İzleyin
A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with t
YüksekCVSS 8,8İstismar yokEPSS %1ui · usg firmware9 Şub 2023
- CVE-2024-5836234İzleyin
SurrealDB before 1.5.5 Query Injection via RPC API
YüksekCVSS 8,7İstismar yokEPSS %1surrealdb · surrealdb18 Tem 2026
- CVE-2022-4821732İzleyin
The tf_remapper_node component 1.1.1 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in t
YüksekCVSS 8,1İstismar yokEPSS %1tradr-project · tf remapper4 Oca 2023
- CVE-2026-5477132İzleyin
Langroid: handle_message() executes user-supplied tool JSON without sender verification
YüksekCVSS 8,1İstismar yokEPSS %0langroid · langroid9 Tem 2026
- CVE-2023-030231İzleyin
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in radareorg/radare2
YüksekCVSS 7,8İstismar yokEPSS %0radare · radare214 Oca 2023
- CVE-2024-2425730İzleyin
An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information v
YüksekCVSS 7,5İstismar yokEPSS %026 Tem 2024
- CVE-2024-2762229İzleyin
A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21.
YüksekCVSS 7,2İstismar yokEPSS %2cmsmadesimple · cms made simple5 Mar 2024
- CVE-2024-3180626İzleyin
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which c
OrtaCVSS 6,5İstismar yokEPSS %0totolink · ex200 firmware8 Nis 2024
- CVE-2024-3181226İzleyin
In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExt
OrtaCVSS 6,5İstismar yokEPSS %0totolink · ex200 firmware8 Nis 2024
- CVE-2022-360724İzleyin
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in octoprint/octoprint
OrtaCVSS 6,0İstismar yokEPSS %0octoprint · octoprint19 Eki 2022
- CVE-2026-2712024İzleyin
Leaf-kit html escaping does not work on characters that are part of extended grapheme cluster
OrtaCVSS 6,1İstismar yokEPSS %0vapor · leafkit20 Şub 2026
- CVE-2025-6191122İzleyin
python-ldap has sanitization bypass in ldap.filter.escape_filter_chars
OrtaCVSS 5,5İstismar yokEPSS %0python-ldap · python-ldap10 Eki 2025
- CVE-2023-175821İzleyin
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in thorsten/phpmyfaq
OrtaCVSS 5,4İstismar yokEPSS %1phpmyfaq · phpmyfaq5 Nis 2023