LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, wh
PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatCon
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagCon
FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT
FeHelper through 2019-06-19 allows arbitrary code execution during a JSON format operation, as demonstrated by the {"a":
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection.
An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/com
The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been di
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execut
TWiki allows arbitrary shell command execution via the Include function
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dep
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data
The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd
The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitr
Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging
rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perfor
The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an
An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assi
In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrar
cPanel before 58.0.4 has improper session handling for shared users (SEC-139).
A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(
A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute a
An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.ph
An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Sha
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). T
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack a
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78).
cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80).
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Ori
A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spect
poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary propert
In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without
An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API r
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the AP
The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form
b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in t
The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.
PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected b
An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secur
Frequently Asked Questions
What is CWE-74?
CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-74?
There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.
How can I protect against CWE-74 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.
Detect CWE-74 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.
Get Started