Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnera
OTCLient is an alternative tibia client for otserv. Prior to commit db560de0b56476c87a2f967466407939196dd254, the /mehah
Intumit inc. SmartRobot's web framwork has a remote code execution vulnerability. An unauthorized remote attacker can ex
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the
Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect
An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay Online E-Learning System usi
DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerabi
An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/adm
Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev. 1.4.0 allows a remote attacker to ex
The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when proc
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/
sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses
DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote com
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through
A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a spe
PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sani
An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted
A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to
Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execu
An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker
The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all ver
Ghost before 5.82.0 allows CSV Injection during a member CSV export.
Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can t
Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-
sp-php-email-handler is a PHP package for handling contact form submissions. Messages sent using this script are vulnera
MantisBT is an open source issue tracker. Prior to version 2.26.1, an unauthenticated attacker who knows a user's email
A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web app
Monkeytype is a minimalistic and customizable typing test. Monkeytype is vulnerable to Poisoned Pipeline Execution throu
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remo
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered
Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to
turbo_boost-commands is a set of commands to help you build robust reactive applications with Rails & Hotwire. TurboBoo
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code bec
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as cri
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critic
iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users'
LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM's log configuration al
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of ar
An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Son
An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Son
This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Trans
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to ac
PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and
FreeScout is a free, self-hosted help desk and shared mailbox. A stored HTML Injection vulnerability has been identified
An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of servi
Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When auto
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, th
Frequently Asked Questions
What is CWE-74?
CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-74?
There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.
How can I protect against CWE-74 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.
Detect CWE-74 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.
Get Started