Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JR6150 before 1.0
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects JNR1010v2 before
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.
NETGEAR WNR854T devices before 1.5.2 are affected by command execution.
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6
MineTime through 1.8.5 allows arbitrary command execution via the notes field in a meeting. Could lead to RCE via meetin
A Host header injection vulnerability has been discovered in SecZetta NEProfile 3.3.11. Authenticated remote adversaries
The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vu
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send
The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevate
Angular Expressions before version 1.0.1 has a remote code execution vulnerability if you call expressions.compile(userC
Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passin
In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could
Dependabot is a set of packages for automated dependency management for Ruby, JavaScript, Python, PHP, Elixir, Rust, Jav
An issue was discovered in Zalo.exe in VNG Zalo Desktop 19.8.1.0. An attacker can run arbitrary commands on a remote Win
Red Discord Bot before versions 3.3.12 and 3.4 has a Remote Code Execution vulnerability in the Streams module. This exp
In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to th
NETGEAR D6100 devices before 1.0.0.50_0.0.50 are affected by command injection.
Certain NETGEAR devices are affected by command injection. This affects R6300v2 before 1.0.4.8_10.0.77, R6400 before 1.0
<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet argume
In Red Discord Bot before version 3.3.11, a RCE exploit has been discovered in the Trivia module: this exploit allows Di
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote atta
Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers
The SAS portal of Mitel MiCollab before 9.1.3 could allow an attacker to access user data by performing a header injecti
dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template
In Magento (rubygems openmage/magento-lts package) before versions 19.4.8 and 20.0.4, an admin user can generate soap cr
Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privilege
Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. In c
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
Certain NETGEAR devices are affected by command injection. This affects D6220 before 1.0.0.26, D6400 before 1.0.0.60, D8
Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.4
Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.4
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead to
A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Spher
Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used. This can be
In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution
Certain NETGEAR devices are affected by debugging command execution. This affects FS752TP 5.4.2.19 and earlier, GS108Tv2
Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerability. It occurs when user input is being us
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expressio
This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template w
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a v
spamdyke prior to 4.2.1: STARTTLS reveals plaintext
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Succe
An issue was discovered in Halvotec RAQuest 10.23.10801.0. The login page is vulnerable to wildcard injection, allowing
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST req
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response
cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, whic
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.
In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This lea
Frequently Asked Questions
What is CWE-74?
CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-74?
There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.
How can I protect against CWE-74 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.
Detect CWE-74 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.
Get Started