A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS versions 7.2
PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username coll
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as proble
In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger
Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting
Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to s
Mattermost fails to use innerText / textContent when setting the channel name in the webapp during autocomplete, allowi
The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS In
A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could
Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RC
Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in R
cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl startin
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with v
An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image file
An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 1
Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display tex
NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows at
A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during dele
Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration us
There is an object injection vulnerability in swfupload plugin for wordpress.
Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in t
Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of
PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format par
MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data para
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authTo
Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration u
Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/[email protected] || 3.0.1` users that use `
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management fram
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker ca
This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with admini
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special eleme
In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user
OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an atta
An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a py
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versi
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versi
IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to cond
Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter mus
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data abo
In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d
Known v1.3.1+2020120201 was discovered to allow attackers to perform an account takeover via a host header injection att
SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by th
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to c
Frequently Asked Questions
What is CWE-74?
CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-74?
There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.
How can I protect against CWE-74 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.
Detect CWE-74 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.
Get Started