Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-74

265
CRITICAL
2,613
HIGH
2,203
MEDIUM
50
LOW
5,159 CVEs · Page 92/104
6.1
CVE-2022-30991

HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before bu

6.1
CVE-2022-38191

There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authentic

6.1
CVE-2022-38796

A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be

6.0
CVE-2022-3607

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/o

5.8
CVE-2022-39217

some-natalie/ghas-to-csv (GitHub Advanced Security to CSV) is a GitHub action which scrapes the GitHub Advanced Security

5.5
CVE-2021-4245

A vulnerability classified as problematic has been found in chbrown rfc6902. This affects an unknown part of the file po

5.4
CVE-2022-23068

ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside t

5.4
CVE-2022-31014

Nextcloud server is an open source personal cloud server. Affected versions were found to be vulnerable to SMTP command

5.4
CVE-2021-39028

IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header i

5.4
CVE-2022-34165

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22

5.4
CVE-2022-40248

An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject a

5.4
CVE-2022-40257

An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject a

5.4
CVE-2022-31777

A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers

5.4
CVE-2022-46265

A vulnerability has been identified in Polarion ALM (All versions < V2304.0). The affected application contains a Host h

5.4
CVE-2022-4864

Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

5.3
CVE-2022-23701

A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO

5.3
CVE-2021-22055

The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attacke

5.3
CVE-2022-24838

Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails v

5.3
CVE-2022-31088

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d

5.3
CVE-2022-35948

undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection

5.3
CVE-2022-45910

Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory an

5.0
CVE-2021-40336

A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This

5.0
CVE-2022-35954

The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` functio

4.9
CVE-2022-34773

Tabit - HTTP Method manipulation. https://bridge.tabit.cloud/configuration/addresses-query - can be POST-ed to add addre

4.7
CVE-2022-20693

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform

4.7
CVE-2022-20772

A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenti

4.3
CVE-2022-1074

A vulnerability has been found in TEM FLEX-1085 1.6.0 and classified as problematic. Using the input <h1>HTML Injection<

4.3
CVE-2022-24888

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 20.0.

4.3
CVE-2022-4188

Insufficient validation of untrusted input in CORS in Google Chrome on Android prior to 108.0.5359.71 allowed a remote a

4.1
CVE-2022-31108

Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer

3.7
CVE-2022-4064

A vulnerability was found in Dalli up to 3.2.2. It has been classified as problematic. Affected is the function self.met

3.0
CVE-2022-43562

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape th

2.8
CVE-2022-29816

In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible

10.0
CVE-2021-21243

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods

10.0
CVE-2021-21244

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth

10.0
CVE-2021-21242

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lea

10.0
CVE-2021-41163

Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could l

9.8
CVE-2020-15690

In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline characte

9.8
CVE-2020-35775

CITSmart before 9.1.2.23 allows LDAP Injection.

9.8
CVE-2021-3197

An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by

9.8
CVE-2021-27132

SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via

9.8
CVE-2021-27730

Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. Th

9.8
CVE-2018-25016

Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.

9.8
CVE-2021-3169

An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an

9.8
CVE-2021-20509

IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute

9.8
CVE-2021-41392

static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafte

9.8
CVE-2021-41862

AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (

9.8
CVE-2021-38458

A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacke

9.8
CVE-2021-38294

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Ap

9.8
CVE-2021-41170

neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures d

Frequently Asked Questions

What is CWE-74?

CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-74?

There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.

How can I protect against CWE-74 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.

Detect CWE-74 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.

Get Started