Skip to main content

CWE archive

CWE-74 CVEs

Programmatic archive

4,975 CVEs tagged with CWE-74242 Critical, 531 High, 3,008 Medium, 1,193 Low, 1 Unrated.

CVE-2018-16627

Published Dec 20, 2018

panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000854

Published Dec 20, 2018

esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-18250

Published Dec 17, 2018

Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation item.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20167

Published Dec 17, 2018

Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat README.md" command when \e}pn is used. A popmedia control s…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1474

Published Dec 12, 2018

IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote att…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1896

Published Dec 7, 2018

IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain. IBM X-Force ID: 152456.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16763

Published Sep 9, 2018

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
16.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2017-1115

Published Sep 7, 2018

IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web brows…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1549

Published Jul 10, 2018

IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using sp…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7848

Published Jun 11, 2018

RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2017-7846

Published Jun 11, 2018

It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View ->…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2017-7788

Published Jun 11, 2018

When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content Security Policy (CSP) as it sho…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-16043

Published Jun 4, 2018

Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the victim's browser. Affects sho…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6015

Published May 11, 2018

Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02 remains ambiguous, which may allow an attacker to link to o…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-2294

Published Apr 17, 2018

Open Web Analytics (OWA) before 1.5.7 allows remote attackers to conduct PHP object injection attacks via a crafted serialized object in the owa_event parameter to queue.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 4,826-4,850 of 4,975 CVEsPage 194 of 199