vm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malici
OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Exec
An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Pyth
MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerab
An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the fro
An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted
An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak functi
An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskst
Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal.
A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this co
The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX actio
Usedesk before 1.7.57 allows chat template injection.
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN c
main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may all
Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by
Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with admini
An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A registered us
Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki
A program using FoundationNetworking in swift-corelibs-foundation is potentially vulnerable to CRLF ( ) injection in URL
ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an atta
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain w
The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This mak
In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM o
Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrar
CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CS
Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote C
Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to crea
This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject u
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder
zenstruck/collections is a set of helpers for iterating/paginating/filtering collections. Passing _callable strings_ (ie
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with v
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution v
ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because A
RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality
Cocos Engine is an open-source framework for building 2D & 3D real-time rendering and interactive content. In the github
DataEase is an open source data visualization analysis tool. In Dataease users are normally allowed to modify data and t
Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Mac
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository radareorg/r
An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1. An app may be able t
Frequently Asked Questions
What is CWE-74?
CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-74?
There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.
How can I protect against CWE-74 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.
Detect CWE-74 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.
Get Started