Skip to main content

CWE archive

CWE-74 CVEs

Programmatic archive

4,975 CVEs tagged with CWE-74242 Critical, 531 High, 3,008 Medium, 1,193 Low, 1 Unrated.

CVE-2020-7111

Published Apr 16, 2020

A server side injection vulnerability exists which could allow an authenticated administrative user to achieve Remote Code Execution in ClearPass. Resolution: Fixed in 6.7.13, 6.8…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11814

Published Apr 16, 2020

A Host Header Injection vulnerability in qdPM 9.1 may allow an attacker to spoof a particular header and redirect users to malicious websites.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11709

Published Apr 12, 2020

cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP respons…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11703

Published Apr 12, 2020

An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response Splitting via the language parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11002

Published Apr 10, 2020

dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template injection was identified in the self-validating feature en…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2018-21051

Published Apr 8, 2020

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. There is an invalid free in the fingerprint Trustlet, leading to arbitrary cod…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-18652

Published Apr 7, 2020

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. SVoice allows arbitrary code execution by changing dynamic libraries. The Samsung ID is SVE-2017…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-11593

Published Apr 6, 2020

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is later leveraged to sen…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10960

Published Apr 3, 2020

In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM no…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1958

Published Apr 1, 2020

When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrie…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-3884

Published Apr 1, 2020

An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbitrary javascript code executio…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11441

Published Mar 31, 2020

phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6982

Published Mar 24, 2020

In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may allow remote code execution.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7475

Published Mar 23, 2020

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (a…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2019-12416

Published Mar 19, 2020

we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrategy which is not the default.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11073

Published Mar 16, 2020

A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execute code due to insufficient sanitization when passing argume…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6858

Published Mar 12, 2020

Hotels Styx through 1.0.0.beta8 allows HTTP response splitting due to CRLF Injection. This is exploitable if untrusted user input can appear in a response header.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,651-4,675 of 4,975 CVEsPage 187 of 199