Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13.
A vulnerability has been found in rahman SelectCours 1.0 and classified as problematic. Affected by this vulnerability i
An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnera
Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, i
dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to
A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Phot
A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the funct
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Auto
A vulnerability was found in HM Courts & Tribunals Service Probate Back Office up to c1afe0cdb2b2766d9e24872c4e827f8b82a
A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects
A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unk
A vulnerability was found in MonoCMS up to 20240528. It has been classified as problematic. Affected is an unknown funct
A vulnerability was found in MonoCMS up to 20240528. It has been declared as problematic. Affected by this vulnerability
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it
A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this vulnerability is an un
A vulnerability was found in playSMS 1.4.3. It has been rated as problematic. Affected by this issue is some unknown fun
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDi
A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prio
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulner
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue aff
A vulnerability classified as problematic has been found in romadebrian WEB-Sekolah 1.0. Affected is an unknown function
A vulnerability, which was classified as problematic, has been found in romadebrian WEB-Sekolah 1.0. Affected by this is
cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields
RDS Light is a simplified version of the Reflective Dialogue System (RDS), a self-reflecting AI framework. Versions prio
MediaCMS is an open source video and media CMS, written in Python/Django and React, featuring a REST API. MediaCMS has b
Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal whi
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object executio
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In XWiki, every
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with e
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with e
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with v
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with v
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with v
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who ca
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versio
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who ca
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By either creat
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escapi
A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to u
An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3.
In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the sess
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username paramet
In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in e
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be i
Frequently Asked Questions
What is CWE-74?
CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-74?
There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.
How can I protect against CWE-74 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.
Detect CWE-74 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.
Get Started