Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could cause an authentic
ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in
A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write pat
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.1
Sylius is an Open Source eCommerce Framework on Symfony. Sylius API filters ProductPriceOrderFilter and TranslationOrder
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the searchCustomPages() method in phpmyfaq/src/p
Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (
There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded,
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an imprope
RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values w
Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri
PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection vulnerability in the
Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to f
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and
The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the syste
The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syn
Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attack
Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who s
An Improper Neutralization of Special Elements in Query vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera
Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 thr
Frequently Asked Questions
What is CWE-943?
CWE-943 (CWE-943) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-943?
There are 72 CVE records associated with CWE-943 in our database. Of these, 10 are critical severity, 25 are high severity, and 28 are medium severity.
How can I protect against CWE-943 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-943 using AI-powered security agents.
Detect CWE-943 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-943 vulnerabilities across your infrastructure.
Get Started