A security vulnerability has been detected in DedeBIZ up to 6.5.9. Affected by this vulnerability is an unknown function
A vulnerability was found in ketr JEPaaS up to 7.2.8. This impacts the function readAllPostil of the file /je/postil/pos
A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save
A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown f
A vulnerability has been found in ZZCMS 2025. Affected by this issue is the function stripfxg of the file /admin/sitecon
A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown functi
A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of
A weakness has been identified in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the f
A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. Affected is an unknown functi
A vulnerability was found in code-projects Online Appointment Booking System 1.0. Impacted is an unknown function of the
A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function selectpage of the file applic
A vulnerability was found in SeaCMS up to 13.3. The impacted element is an unknown function of the file admin_video.php.
A vulnerability has been found in shanyu SyCms up to a242ef2d194e8bb249dc175e7c49f2c1673ec921. This issue affects the fu
A security flaw has been discovered in EyouCMS up to 1.7.6. The affected element is an unknown function of the file /app
A flaw has been found in CmsEasy up to 7.7.7. Affected is the function savetemp_action in the library /lib/admin/templat
A weakness has been identified in BiggiDroid Simple PHP CMS 1.0. Affected by this issue is some unknown functionality of
A security vulnerability has been detected in 08CMS Novel System up to 3.4. This issue affects some unknown processing o
A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php
A vulnerability was detected in PKrystian Full-Stack-Bank up to bf73a0179e3ff07c0d7dc35297cea0be0e5b1317. This vulnerabi
Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the l
A vulnerability was found in Incorta 2023.4.3. It has been classified as problematic. Affected is an unknown function of
A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been rated as problematic. This issue affects the functi
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escapi
A vulnerability has been found in OpenClinica Community Edition up to 3.12.2/3.13. Affected by this issue is some unknow
Caido is a web security auditing toolkit. Prior to version 0.53.0, the Markdown renderer used in Caido’s Findings page i
A vulnerability was found in code-projects Rental Management System 2.0. This affects an unknown function of the file Tr
Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling
A vulnerability was found in TMD Custom Header Menu 4.0.0.1 on OpenCart. It has been rated as problematic. This issue af
A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the f
A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng
A vulnerability, which was classified as problematic, was found in Eastnets PaymentSafe 2.5.26.0. This affects an unknow
A flaw has been found in Bdtask/CodeCanyon SalesERP up to 20250728. This vulnerability affects unknown code of the file
A vulnerability was found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 2025032
A security flaw has been discovered in Grandstream GXP1625 1.0.7.4. The impacted element is an unknown function of the f
FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetr
A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerabilit
A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown func
A vulnerability was determined in mrvautin expressCart up to b31302f4e99c3293bd742c6d076a721e168118b0. This impacts an u
TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expr
Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it
Integrated Scripting is a tool for creating scripts for handling complex operations in Integrated Dynamics. Minecraft us
Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid.This issue affects MediaWiki: before 1.39.
Host Header Injection (HHI) vulnerability in the Hotspot Shield VPN client, which can induce unexpected behaviour when a
Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of
A security issue affecting multiple Cisco devices also directly impacts Stratix® 5410, 5700, and 8000 devices. This can
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The
Open Access Management (OpenAM) is an access management solution. In versions prior to 16.0.0, if the "claims_parameter_
trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies
Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious
Frequently Asked Questions
What is CWE-74?
CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-74?
There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.
How can I protect against CWE-74 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.
Detect CWE-74 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.
Get Started