A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been classified as critical
A vulnerability was found in code-projects Simple Chat System 1.0. It has been rated as critical. Affected by this issue
A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been declared as critical. Affected by th
A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been rated as critical. Affected
A vulnerability has been found in PHPGurukul Land Record System 1.0 and classified as critical. Affected by this vulnera
A vulnerability was found in PHPGurukul Land Record System 1.0 and classified as critical. Affected by this issue is som
A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.
Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker
Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9
Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to
RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header valu
Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication
Swift Prometheus is a Swift client for the Prometheus monitoring system, supporting counters, gauges and histograms. In
Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on
Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Comp
A vulnerability classified as critical was found in romadebrian WEB-Sekolah 1.0. Affected by this vulnerability is an un
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to HTML Injection in all version
A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) charac
pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified
The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source e
Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. Thi
your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 is vulnerable to NoSQ
A security vulnerability has been detected in Ritlabs TinyWeb Server 1.94. This vulnerability affects unknown code of th
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Brai
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Them
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, un
Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or
Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, whic
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.
A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syn
tqdm is an open source progress bar for Python and CLI. Any optional non-boolean CLI arguments (e.g. `--delim`, `--buf-s
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy
A vulnerability classified as critical has been found in Guangzhou Tuchuang Computer Software Development Interlib Libra
A vulnerability classified as critical was found in Guangzhou Tuchuang Computer Software Development Interlib Library Cl
A vulnerability was found in CodeAstro Real Estate Management System up to 1.0. It has been declared as critical. This v
A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Aff
A vulnerability has been found in TimGeyssens UIOMatic 5 and classified as critical. This vulnerability affects unknown
A vulnerability, which was classified as critical, was found in SourceCodester Best Employee Management System 1.0. This
A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functiona
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been classified as crit
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been declared as critic
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been rated as critical.
A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. Th
A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This vu
A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to
A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241
A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Aff
Frequently Asked Questions
What is CWE-74?
CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-74?
There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.
How can I protect against CWE-74 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.
Detect CWE-74 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.
Get Started