Skip to main content

CWE archive

CWE-74 CVEs

Programmatic archive

4,976 CVEs tagged with CWE-74242 Critical, 531 High, 3,009 Medium, 1,193 Low, 1 Unrated.

CVE-2018-21258

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite_people slash command.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13445

Published Jun 10, 2020

In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensiti…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16385

Published Jun 4, 2020

Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an example.pdf?mimetype= substring.…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5574

Published May 14, 2020

HTML attribute value injection vulnerability in Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1) and earlier…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11060

Published May 12, 2020

In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited by an attacker without a vali…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12790

Published May 11, 2020

In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side Template Injection and credentials disclo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11056

Published May 7, 2020

In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which could lead to the execution o…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-3246

Published May 6, 2020

A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5336

Published May 4, 2020

RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could potentially exploit this vulnerability by tricking a victi…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1961

Published May 4, 2020

Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject ar…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12425

Published Apr 30, 2020

Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 4,601-4,625 of 4,976 CVEsPage 185 of 200