The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes
WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-
In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Str
The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before renderin
Injection in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain sensitive infor
The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding i
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited
A vulnerability was identified in Daptin 0.10.3. Affected by this vulnerability is the function goqu.L of the file serve
A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected by this v
A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager o
A vulnerability was identified in itsourcecode Society Management System 1.0. This affects an unknown part of the file /
A weakness has been identified in code-projects Online Product Reservation System 1.0. This issue affects some unknown p
A vulnerability was determined in code-projects Online Product Reservation System 1.0. The affected element is an unknow
A vulnerability was identified in code-projects Online Product Reservation System 1.0. The impacted element is an unknow
A flaw has been found in Campcodes Supplier Management System 1.0. Affected by this issue is some unknown functionality
A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112_B20190227. This vulnerability affects the functi
A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.as
A vulnerability was determined in PHPGurukul Online Course Registration System up to 3.1. This impacts an unknown functi
A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file s
A vulnerability was found in PHPGurukul Online Course Registration System up to 3.1. This affects an unknown part of the
A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/
A vulnerability has been found in RainyGao DocSys up to 2.02.37. This affects an unknown function of the file com/DocSys
A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/
A vulnerability has been found in jiujiujia/victor123/wxw850227 jjjfood and jjjshop_food up to 20260103. This vulnerabil
A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /
A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file
A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the function setDiagnosisCfg
A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg o
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. This vulnerability affects the function setWan
A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function se
A vulnerability was found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the
A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This impact
A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillI
A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi
A flaw has been found in Totolink A7000R 4.1cu.4154. This impacts the function CloudACMunualUpdateUserdata of the file /
A weakness has been identified in itsourcecode School Management System 1.0. This affects an unknown part of the file /r
A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_In
A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/
A weakness has been identified in Totolink A7000R 4.1cu.4154. The impacted element is the function setUploadUserData of
A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin
A security vulnerability has been detected in D-Link DWR-M961 1.1.47. The affected element is an unknown function of the
A vulnerability was detected in D-Link DWR-M961 1.1.47. The impacted element is the function sub_4250E0 of the file /boa
A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZ
A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/ap
A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e298
A vulnerability was detected in abhiphile fermat-mcp up to 47f11def1cd37e45dd060f30cdce346cbdbd6f0a. This vulnerability
A security flaw has been discovered in Xiaopi Panel up to 20260126. This impacts an unknown function of the file /demo.p
A vulnerability was determined in BurtTheCoder mcp-maigret up to 1.0.12. This affects an unknown part of the file src/in
A vulnerability was detected in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_43F020 of the file
A flaw has been found in D-Link DWR-M921 1.1.50. This affects the function sub_419920 of the file /boafrm/formLtefotaUpg
Frequently Asked Questions
What is CWE-74?
CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-74?
There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.
How can I protect against CWE-74 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.
Detect CWE-74 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.
Get Started