A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.3
The Simple Quotation WordPress plugin through 1.3.2 does not have CSRF check when creating or editing a quote and does n
The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not have CSRF check in place when updating its set
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a
Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal env
In choosePrivateKeyAlias of KeyChain.java, there is a possible access to the user's certificate due to improper input va
IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is vulnerable to HTTP header injec
The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving me
Jenkins Random String Parameter Plugin 1.0 and earlier does not escape the name and description of Random String paramet
IBM API Connect V10.0.0.0 through V10.0.5.0, V10.0.1.0 through V10.0.1.7, and V2018.4.1.0 through 2018.4.1.19 is vulnera
KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handlin
Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge l
A vulnerability has been found in Activity Log Plugin and classified as critical. This vulnerability affects unknown cod
IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 prepares a structured message for communication with another componen
Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP
The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the cat
The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitiz
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 an
The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote auth
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual mess
Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who c
IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used b
In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality
Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to
OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do
An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the
A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account
Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send mal
Due to insufficient input validation of Kyma, authenticated users can pass a Header of their choice and escalate privile
Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configura
Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there
Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could ad
In onCreate of CompanionDeviceActivity.java or DeviceChooserActivity.java, there is a possible way for HTML tags to inte
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to impro
IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive i
Roblox-Purchasing-Hub is an open source Roblox product purchasing hub. A security risk in versions 1.0.1 and prior allow
go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipf
An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response heade
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user n
xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. x
The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to view sensitive system info
The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to get source code informatio
Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to f
There is an information leak vulnerability in eCNS280_TD V100R005C10SPC650. The vulnerability is caused by improper log
Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cr
Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications
Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log e
Frequently Asked Questions
What is CWE-116?
CWE-116 (CWE-116) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-116?
There are 553 CVE records associated with CWE-116 in our database. Of these, 64 are critical severity, 155 are high severity, and 227 are medium severity.
How can I protect against CWE-116 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-116 using AI-powered security agents.
Detect CWE-116 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-116 vulnerabilities across your infrastructure.
Get Started