Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, wh
A vulnerability in the user interface of Cisco Webex Meetings and Cisco Webex Meetings Server Software could allow an au
In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a re
HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE
The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host para
in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username wit
BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data
Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, A
The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasi
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user
Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute a
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
scripts/email.coffee in the Hubot Scripts module before 2.4.4 for Node.js allows remote attackers to execute arbitrary c
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
libnotify before 1.0.4 for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in a
Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data
Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed
On Swann DVR04B, DVR08B, DVR-16CIF, and DVR16B devices, raysharpdvr application has a vulnerable call to “system”, which
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. SVoice allows arbitrary code executio
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. There is an invalid
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerabili
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance r
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed re
Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe
A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl fi
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary
A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input i
Local file inclusion in WebCalendar before 1.2.5.
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php,
A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let
A Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, whi
A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite
SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a co
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may al
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D3600 before 1.0.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WC7500 before 6.5
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0
Frequently Asked Questions
What is CWE-74?
CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-74?
There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.
How can I protect against CWE-74 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.
Detect CWE-74 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.
Get Started