JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.
An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the P
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX ev
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availabi
NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the inf
Hygeia is an application for collecting and processing personal and case data in connection with communicable diseases.
Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability. A remote high privileged at
An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a F
An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers t
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowi
An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Ne
Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who con
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from
When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been inte
IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP inject
ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client co
Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several fau
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the
In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 an
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by
In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the we
http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or re
RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in file
angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-exp
vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versio
Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, N
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP req
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.h
This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulner
Ticketer is a command based ticket system cog (plugin) for the red discord bot. A vulnerability allowing discord users t
An issue was discovered in the POP3 component of Courier Mail Server before 1.1.5. Meddler-in-the-middle attackers can p
A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel
HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject a
Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there
An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a ma
Emissary is a P2P based data-driven workflow engine. Affected versions of Emissary are vulnerable to post-authentication
In onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to improper input validatio
In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is v
TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a HTML injection vulnerability in the userFirs
Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability tha
In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass. This coul
An injection issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5, Security Update 20
IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary command
All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused
Frequently Asked Questions
What is CWE-74?
CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-74?
There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.
How can I protect against CWE-74 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.
Detect CWE-74 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.
Get Started