File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the fil
Improper neutralization of special elements leaves the Eyes of Network Web application vulnerable to an iFrame injection
The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rend
Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject marku
An injection vulnerability in the syslog-ng configuration wizard in Securonix Snypr 6.4 allows an application user with
GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD
Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an accoun
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio
iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with
Shescape is a simple shell escape package for JavaScript. Versions prior to 1.5.8 were found to be subject to code injec
matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading t
fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git re
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d
URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parame
In getView of AddAppNetworksFragment.java, there is a possible way to mislead the user about network add requests due to
The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_
When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using onl
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locato
The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs begi
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands i
Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequ
NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack. This oc
Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <=
A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this
A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality
Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not pro
In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, a
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A m
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A m
MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mai
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio
A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) w
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a mu
Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote
An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider r
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work
A vulnerability classified as critical was found in School Club Application System 1.0. This vulnerability affects a req
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyrin
A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15), Mendix Applic
HTTP header injection vulnerability in Cybozu Office 10.0.0 to 10.8.5 may allow a remote attacker to obtain and/or alter
An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to cr
Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface res
By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context c
A vulnerability, which was classified as critical, has been found in SevOne Network Management System up to 5.7.2.22. Th
A vulnerability classified as critical has been found in Furqan node-whois. Affected is an unknown function of the file
A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper va
Frequently Asked Questions
What is CWE-74?
CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-74?
There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.
How can I protect against CWE-74 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.
Detect CWE-74 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.
Get Started