Fides is an open-source privacy engineering platform. The Fides webserver requires a connection to a hosted PostgreSQL d
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escapi
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with th
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted
ConEmu through 220807 and Cmder before 1.3.21 report the title of the terminal, including control characters, which allo
Controller DoS due to stack overflow when decoding a message from the server. See Honeywell Security Notification for
iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences relate
iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences relate
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filt
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, a
XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, a
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In `org.xwiki.p
Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run atta
An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global ob
In Splunk Enterprise versions below 9.1.0.2, 9.0.5.1, and 8.2.11.2, an attacker can inject American National Standards I
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4,
Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s t
Improper input validation in some firmware for Intel(R) AMT and Intel(R) Standard Manageability before versions 11.8.94,
In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3, 4.15.3, or 4.17.1, a malicious actor can inject Am
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to
HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive info
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-iste
An issue was discovered in Croc through 9.6.5. A sender may place ANSI or CSI escape sequences in a filename to attack t
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, mess
PDFZorro PDFZorro Online r20220428 using TCPDF 6.2.5, despite having workflows claiming to correctly remove redacted inf
Interactive Forms (IAF) in GX Software XperienCentral versions 10.33.1 until 10.35.0 was vulnerable to invalid data inpu
Input verification vulnerability in the storage module. Successful exploitation of this vulnerability may cause the dev
Input verification vulnerability in the audio module. Successful exploitation of this vulnerability may cause virtual m
Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnera
Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation o
AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, explo
SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers in a client request.
Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.
When copying a network request from the developer tools panel as a curl command the output was not being properly saniti
The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in
Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, whi
RTX TRAP v1.0 was discovered to be vulnerable to host header poisoning.
Critters versions 0.0.17-0.0.19 have an issue when parsing the HTML, which leads to a potential cross-site scripting (XS
WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote (").
A vulnerability was found in gitlearn. It has been declared as problematic. This vulnerability affects the function getG
Dell EMC Data Protection Central, versions 19.1 through 19.7, contains a Host Header Injection vulnerability. A remote
Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform
A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log fi
Sudo before 1.9.13 does not escape control characters in log messages.
Sudo before 1.9.13 does not escape control characters in sudoreplay output.
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the R
Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious f
OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 4.0.0 and prior to versio
Frequently Asked Questions
What is CWE-116?
CWE-116 (CWE-116) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-116?
There are 553 CVE records associated with CWE-116 in our database. Of these, 64 are critical severity, 155 are high severity, and 227 are medium severity.
How can I protect against CWE-116 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-116 using AI-powered security agents.
Detect CWE-116 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-116 vulnerabilities across your infrastructure.
Get Started