An issue was discovered in Mattermost Server before 5.1. It allows attackers to cause a denial of service via the invite
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE
beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with crede
An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108. Accessing Main_Login.asp?flag=1&productn
In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields
In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this v
LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affe
PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbi
Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and re
A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execut
A server side injection vulnerability exists which could allow an authenticated administrative user to achieve Remote Co
Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF inj
Certain NETGEAR devices are affected by command execution via a PHP form. This affects WN604 3.3.3 and earlier, WNAP210v
Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-me
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.44,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.44,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 5.0.5.4 a
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WNDR3700v4 before 1.0.2
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34,
In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could cha
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D8500 through 1.0.3.28,
Certain NETGEAR devices are affected by command injection. This affects R6220 before 1.1.0.46, R6700v2 before 1.1.0.38,
Certain NETGEAR devices are affected by command injection. This affects WAC510 before 1.3.0.10, WAC120 before 2.1.4, WND
Certain NETGEAR devices are affected by command injection. This affects R6100 before 1.0.1.14, R7500 before 1.0.0.110, R
Certain NETGEAR devices are affected by command injection. This affects R7800 before 1.0.2.16 and R9000 before 1.0.2.4.
Certain NETGEAR devices are affected by command injection. This affects WAC510 before 1.3.0.10, WAC120 before 2.1.4, WND
NETGEAR R7800 devices before 1.0.2.36 are affected by command injection.
Certain NETGEAR devices are affected by command injection. This affects D6220 before 1.0.0.28 and D6100 before 1.0.0.50_
Certain NETGEAR devices are affected by command injection. This affects R6400 before 1.0.1.24, R6700 before 1.0.1.26, R6
Certain NETGEAR devices are affected by command injection. This affects R6220 before 1.1.0.50, R6700v2 before 1.1.0.38,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.67,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6100 before V1.0.0.55,
NETGEAR ReadyNAS 6.6.1 and earlier is affected by command injection.
NETGEAR ReadyNAS devices before 6.6.1 are affected by command injection.
SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to i
In XWiki before versions 11.10.5 or 12.2.1, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to
In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response head
In Puma (RubyGem) before 4.3.3 and 3.12.4, if an application using Puma allows untrusted input in an early-hints header,
Hotels Styx through 1.0.0.beta8 allows HTTP response splitting due to CRLF Injection. This is exploitable if untrusted u
When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials c
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is poss
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserti
BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a
bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifyin
Frequently Asked Questions
What is CWE-74?
CWE-74 (CWE-74) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-74?
There are 5,318 CVE records associated with CWE-74 in our database. Of these, 265 are critical severity, 2613 are high severity, and 2203 are medium severity.
How can I protect against CWE-74 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-74 using AI-powered security agents.
Detect CWE-74 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-74 vulnerabilities across your infrastructure.
Get Started