İçeriğe atla
Noroxi

CWE-75 · 29 kayıt

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)

Bu sınıftaki CVE’ler

29 kayıt

  • CVE-2021-22911
    68Bu hafta

    A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injectio

    KritikCVSS 9,8Kavram kanıtıEPSS %95

    rocket.chat · rocket.chat27 May 2021

  • CVE-2024-0801
    43Planlayın

    Unauthenticated DoS in Arcserve Unified Data Protection

    YüksekCVSS 7,5Kavram kanıtıEPSS %42

    arcserve · udp13 Mar 2024

  • CVE-2021-22910
    40Planlayın

    A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could

    KritikCVSS 9,8İstismar yokEPSS %2

    rocket.chat · rocket.chat9 Ağu 2021

  • CVE-2024-35373
    39İzleyin

    Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.

    KritikCVSS 9,8İstismar yokEPSS %1

    mocodo · mocodo online24 May 2024

  • CVE-2025-50213
    39İzleyin

    Apache Airflow Providers Snowflake: Potential SQL injection in CopyFromExternalStageToSnowflakeOperator

    KritikCVSS 9,8İstismar yokEPSS %1

    apache · apache-airflow-providers-snowflake24 Haz 2025

  • CVE-2021-39174
    37İzleyin

    Cachet is an open source status page system.

    YüksekCVSS 8,8Kavram kanıtıEPSS %5

    catchethq · catchet27 Ağu 2021

  • CVE-2022-24039
    37İzleyin

    A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884).

    KritikCVSS 9,0İstismar yokEPSS %2

    siemens · desigo pxc5 firmware10 May 2022

  • CVE-2026-29042
    36İzleyin

    Nuclio Shell Runtime Command Injection Leading to Privilege Escalation

    YüksekCVSS 8,9İstismar yokEPSS %3

    iguazio · nuclio6 Mar 2026

  • CVE-2023-27533
    36İzleyin

    A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on mali

    YüksekCVSS 8,8İstismar yokEPSS %2

    haxx · curl30 Mar 2023

  • CVE-2026-31908
    36İzleyin

    Apache APISIX: forward auth plugin allows header injection

    KritikCVSS 9,1Kavram kanıtıEPSS %1

    apache · apisix14 Nis 2026

  • CVE-2024-37779
    35İzleyin

    WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script

    YüksekCVSS 8,8İstismar yokEPSS %1

    23 Eyl 2024

  • CVE-2024-31809
    35İzleyin

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in th

    YüksekCVSS 8,8İstismar yokEPSS %1

    totolink · ex200 firmware8 Nis 2024

  • CVE-2023-23912
    35İzleyin

    A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with t

    YüksekCVSS 8,8İstismar yokEPSS %1

    ui · usg firmware9 Şub 2023

  • CVE-2024-58362
    34İzleyin

    SurrealDB before 1.5.5 Query Injection via RPC API

    YüksekCVSS 8,7İstismar yokEPSS %1

    surrealdb · surrealdb18 Tem 2026

  • CVE-2022-48217
    32İzleyin

    The tf_remapper_node component 1.1.1 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in t

    YüksekCVSS 8,1İstismar yokEPSS %1

    tradr-project · tf remapper4 Oca 2023

  • CVE-2026-54771
    32İzleyin

    Langroid: handle_message() executes user-supplied tool JSON without sender verification

    YüksekCVSS 8,1İstismar yokEPSS %0

    langroid · langroid9 Tem 2026

  • CVE-2023-0302
    31İzleyin

    Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in radareorg/radare2

    YüksekCVSS 7,8İstismar yokEPSS %0

    radare · radare214 Oca 2023

  • CVE-2024-24257
    30İzleyin

    An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information v

    YüksekCVSS 7,5İstismar yokEPSS %0

    26 Tem 2024

  • CVE-2024-27622
    29İzleyin

    A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21.

    YüksekCVSS 7,2İstismar yokEPSS %2

    cmsmadesimple · cms made simple5 Mar 2024

  • CVE-2024-31806
    26İzleyin

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which c

    OrtaCVSS 6,5İstismar yokEPSS %0

    totolink · ex200 firmware8 Nis 2024

  • CVE-2024-31812
    26İzleyin

    In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExt

    OrtaCVSS 6,5İstismar yokEPSS %0

    totolink · ex200 firmware8 Nis 2024

  • CVE-2022-3607
    24İzleyin

    Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in octoprint/octoprint

    OrtaCVSS 6,0İstismar yokEPSS %0

    octoprint · octoprint19 Eki 2022

  • CVE-2026-27120
    24İzleyin

    Leaf-kit html escaping does not work on characters that are part of extended grapheme cluster

    OrtaCVSS 6,1İstismar yokEPSS %0

    vapor · leafkit20 Şub 2026

  • CVE-2025-61911
    22İzleyin

    python-ldap has sanitization bypass in ldap.filter.escape_filter_chars

    OrtaCVSS 5,5İstismar yokEPSS %0

    python-ldap · python-ldap10 Eki 2025

  • CVE-2023-1758
    21İzleyin

    Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in thorsten/phpmyfaq

    OrtaCVSS 5,4İstismar yokEPSS %1

    phpmyfaq · phpmyfaq5 Nis 2023

Tüm zafiyet sınıfları