SHIRASAGI is a Content Management System. Prior to version 1.18.0, SHIRASAGI is vulnerable to a Post-Unicode normalizati
lockss-daemon (aka Classic LOCKSS Daemon) before 1.77.3 performs post-Unicode normalization, which may allow bypass of i
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior t
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being i
A vulnerability classified as problematic has been found in OpenDNS OpenResolve. This affects an unknown part of the fil
Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions sta
A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that use remote authentication
IBM QRadar WinCollect Agent 10.0 through 10.1.7 could allow a local user to perform unauthorized actions due to imprope
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 o
Mutagen provides real-time file synchronization and flexible network forwarding for developers. Prior to versions 0.16.6
Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issu
iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f
XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting
XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Start
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with v
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UT
A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.
phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.ph
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Ple
Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.
A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups paramet
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This c
SVG's <code><use></code> element could have been used to load unexpected content that could have executed script i
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions <
CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs:
The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnera
A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could al
A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interfac
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code e
Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later allows a user with a modified Soulseek client to cras
Gitea before 1.16.7 does not escape git fetch remote.
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and und
Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbi
XWiki Platform Flamingo Theme UI is a tool that allows customization and preview of any Flamingo-based skin. Starting wi
XWiki Platform Wiki UI Main Wiki is a package for managing subwikis. Starting with version 5.3-milestone-2, XWiki Platfo
XWiki Platform Filter UI provides a generic user interface to convert from a XWiki Filter input stream to an output stre
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submit
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept heade
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
An issue was discovered in COINS Construction Cloud 11.12. Due to improper validation of user-controlled HTTP headers, a
A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue affects some unknown proce
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthent
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), a
Frequently Asked Questions
What is CWE-116?
CWE-116 (CWE-116) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-116?
There are 553 CVE records associated with CWE-116 in our database. Of these, 64 are critical severity, 155 are high severity, and 227 are medium severity.
How can I protect against CWE-116 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-116 using AI-powered security agents.
Detect CWE-116 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-116 vulnerabilities across your infrastructure.
Get Started