Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.
Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some
In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of al
Monkshu is an enterprise application server for mobile apps (iOS and Android), responsive HTML 5 apps, and JSON API serv
Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker
A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can cha
Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated adminis
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, fi
Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE
An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have e
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code
In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` c
The Kommbox component in Rangee GmbH RangeeOS 8.0.4 could allow a local authenticated attacker to escape from the restri
A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed
SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specia
PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote charac
The dashboard in WhiteSource Application Vulnerability Management (AVM) before version 20.4.1 allows Log Injection via a
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Stri
A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This direc
XWiki Platform before 12.8 mishandles escaping in the property displayer.
SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user contr
BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated u
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which
bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call.
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file,
Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system inf
web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrate
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow an authenticated user to
This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape se
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been di
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes str
An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.ph
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an a
WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attack
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an a
All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artif
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events
LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings,
An issue was discovered in Netdata 1.10.0. Log Injection (or Log Forgery) exists via a %0a sequence in the url parameter
An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be ac
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (o
A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly
An information disclosure vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not prop
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x bef
Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during c
An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send fi
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used
In Counter-Strike: Global Offensive before 8/29/2019, community game servers can display unsafe HTML in a disconnection
Frequently Asked Questions
What is CWE-116?
CWE-116 (CWE-116) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-116?
There are 553 CVE records associated with CWE-116 in our database. Of these, 64 are critical severity, 155 are high severity, and 227 are medium severity.
How can I protect against CWE-116 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-116 using AI-powered security agents.
Detect CWE-116 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-116 vulnerabilities across your infrastructure.
Get Started