HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before bu
There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authentic
A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/o
some-natalie/ghas-to-csv (GitHub Advanced Security to CSV) is a GitHub action which scrapes the GitHub Advanced Security
A vulnerability classified as problematic has been found in chbrown rfc6902. This affects an unknown part of the file po
ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside t
Nextcloud server is an open source personal cloud server. Affected versions were found to be vulnerable to SMTP command
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header i
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22
An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject a
An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject a
A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers
A vulnerability has been identified in Polarion ALM (All versions < V2304.0). The affected application contains a Host h
Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO
The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attacke
Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails v
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection
Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory an
A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This
The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` functio
Tabit - HTTP Method manipulation. https://bridge.tabit.cloud/configuration/addresses-query - can be POST-ed to add addre
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform
A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenti
A vulnerability has been found in TEM FLEX-1085 1.6.0 and classified as problematic. Using the input <h1>HTML Injection<
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 20.0.
Insufficient validation of untrusted input in CORS in Google Chrome on Android prior to 108.0.5359.71 allowed a remote a
Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer
A vulnerability was found in Dalli up to 3.2.2. It has been classified as problematic. Affected is the function self.met
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape th
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lea
Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could l
In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline characte
CITSmart before 9.1.2.23 allows LDAP Injection.
An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via
Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. Th
Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.
An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an
IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafte
AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacke
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Ap
neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures d
Frequently Asked Questions
What is CWE-74?
CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-74?
There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.
How can I protect against CWE-74 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.
Detect CWE-74 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.
Get Started