In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization
api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnera
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3
The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injectio
redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote auth
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands
OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and re
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
Tablacus Explorer 17.3.30 and earlier allows arbitrary scripts to be executed in the context of the application due to s
A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. An "improper neutralizatio
An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. In the device's we
An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4. On the backend of
The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parame
Opencast 2.3.2 and older versions are vulnerable to script injections through media and metadata in the player and media
sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the program specified by the
lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWS
KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, w
TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment va
boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variab
etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environm
scripts/inspect_webbrowser.py in Reddit Terminal Viewer (RTV) 1.19.0 does not validate strings before launching the prog
libsylph/utils.c in Sylpheed through 3.6 does not validate strings before launching the program specified by the BROWSER
swt/motif/browser.c in White_dune (aka whitedune) 0.30.10 does not validate strings before launching the program specifi
batteriesConfig.mlp in OCaml Batteries Included (aka ocaml-batteries) 2.6 does not validate strings before launching the
tools/url_handler.pl in TIN 2.4.1 does not validate strings before launching the program specified by the BROWSER enviro
uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER e
Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSE
library/www_browser.pl in SWI-Prolog 7.2.3 does not validate strings before launching the program specified by the BROWS
guiclient/guiclient.cpp in xTuple PostBooks 4.7.0 does not validate strings before launching the program specified by th
Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSE
delphi_gui/WWWBrowserRunnerDM.pas in PasDoc 0.14 does not validate strings before launching the program specified by the
backends/platform/sdl/posix/posix.cpp in ScummVM 1.9.0 does not validate strings before launching the program specified
af/util/xp/ut_go_file.cpp in AbiWord 3.0.2-2 does not validate strings before launching the program specified by the BRO
common/help.c in Geomview 1.9.5 does not validate strings before launching the program specified by the BROWSER environm
gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environmen
examples/framework/news/news3.py in Kiwi 1.9.22 does not validate strings before launching the program specified by the
default.tcl in Tkabber 1.1 does not validate strings before launching the program specified by the BROWSER environment v
uiutil.c in Mensis 0.0.080507 does not validate strings before launching the program specified by the BROWSER environmen
lib/gui.py in Bob Hepple gjots2 2.4.1 does not validate strings before launching the program specified by the BROWSER en
Huawei SmartCare V200R003C10 has a CSV injection vulnerability. An remote authenticated attacker could inject malicious
The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component,
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenam
AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via v
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malf
ntopng before 3.0 allows HTTP Response Splitting.
An Injection issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort
Two potential audit log injections in SAP HANA extended application services 1.0, advanced model: 1) Certain HTTP/REST e
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChann
A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker
Frequently Asked Questions
What is CWE-74?
CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-74?
There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.
How can I protect against CWE-74 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.
Detect CWE-74 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.
Get Started