CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Description
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-105 · CAPEC-108 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-14 · CAPEC-24 · CAPEC-250 · CAPEC-267 · CAPEC-273 · CAPEC-28 · CAPEC-3 · CAPEC-34 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-51 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-83 · CAPEC-84 · CAPEC-9
CVEs mapped to this weakness (5,475)
page 15 of 274| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-27194 | Cri | 0.57 | 9.8 | 0.01 | Feb 21, 2026 | D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the… | ||
| CVE-2025-14659 | Hig | 0.57 | 8.8 | 0.04 | Dec 14, 2025 | A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the component DHCP Daemon. The manipulation of the argument Hostname results in command injection. It is possible to launch the attack remotely. The exploit is now… | ||
| CVE-2024-56835 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2025 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400 (All versions < V2.17.0), RUGGEDCOM ROX RX1500 (All versions < V2.17.0), RUGGEDCOM ROX RX1501 (All versions < V2.17.0),… | ||
| CVE-2025-62697 | Hig | 0.57 | — | 0.00 | Oct 20, 2025 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The Wikimedia Foundation Mediawiki - LanguageSelector Extension allows Code Injection.This issue affects Mediawiki - LanguageSelector Extension: from master before… | ||
| CVE-2025-4350 | Hig | 0.57 | 8.8 | 0.04 | May 6, 2025 | A vulnerability classified as critical was found in D-Link DIR-600L up to 2.07B01. This vulnerability affects the function wake_on_lan. The manipulation of the argument host leads to command injection. The attack can be initiated remotely. This vulnerability only affects… | ||
| CVE-2025-4349 | Hig | 0.57 | 8.8 | 0.04 | May 6, 2025 | A vulnerability classified as critical has been found in D-Link DIR-600L up to 2.07B01. This affects the function formSysCmd. The manipulation of the argument host leads to command injection. It is possible to initiate the attack remotely. This vulnerability only affects… | ||
| CVE-2024-46983 | Cri | 0.57 | 9.8 | 0.01 | Sep 19, 2024 | sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the… | ||
| CVE-2024-26020 | Cri | 0.57 | 9.6 | 0.15 | Jul 22, 2024 | An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability. | ||
| CVE-2024-1773 | Hig | 0.57 | 8.8 | 0.01 | Mar 7, 2024 | The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.7 via deserialization of untrusted input via the order_id parameter. This makes it possible for authenticated attackers, with… | ||
| CVE-2023-51939 | Hig | 0.57 | 8.8 | 0.01 | Feb 1, 2024 | An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker to obtain sensitive information and escalate privileges via the cp_bbs_sig function. | ||
| CVE-2023-43364 | Cri | 0.57 | 9.8 | 0.03 | Dec 12, 2023 | main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution. | ||
| CVE-2023-48841 | Hig | 0.57 | 8.8 | 0.01 | Dec 7, 2023 | Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. | ||
| CVE-2023-48835 | Hig | 0.57 | 8.8 | 0.01 | Dec 7, 2023 | Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action. | ||
| CVE-2023-48830 | Hig | 0.57 | 8.8 | 0.01 | Dec 7, 2023 | Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export. | ||
| CVE-2023-48826 | Hig | 0.57 | 8.8 | 0.01 | Dec 7, 2023 | Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List. | ||
| CVE-2023-43835 | Hig | 0.57 | 8.8 | 0.01 | Oct 2, 2023 | Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote Code Execution when settings overwrite config.inc.php content. | ||
| CVE-2023-39662 | Cri | 0.57 | 9.8 | 0.01 | Aug 15, 2023 | An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function. | ||
| CVE-2023-39659 | Cri | 0.57 | 9.8 | 0.02 | Aug 15, 2023 | An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component. | ||
| CVE-2023-38896 | Cri | 0.57 | 9.8 | 0.02 | Aug 15, 2023 | An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colored_object_prompt functions. | ||
| CVE-2020-28848 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2023 | CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file. |
- risk 0.57cvss 9.8epss 0.01
D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the…
- risk 0.57cvss 8.8epss 0.04
A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the component DHCP Daemon. The manipulation of the argument Hostname results in command injection. It is possible to launch the attack remotely. The exploit is now…
- risk 0.57cvss 8.8epss 0.01
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400 (All versions < V2.17.0), RUGGEDCOM ROX RX1500 (All versions < V2.17.0), RUGGEDCOM ROX RX1501 (All versions < V2.17.0),…
- risk 0.57cvss —epss 0.00
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The Wikimedia Foundation Mediawiki - LanguageSelector Extension allows Code Injection.This issue affects Mediawiki - LanguageSelector Extension: from master before…
- risk 0.57cvss 8.8epss 0.04
A vulnerability classified as critical was found in D-Link DIR-600L up to 2.07B01. This vulnerability affects the function wake_on_lan. The manipulation of the argument host leads to command injection. The attack can be initiated remotely. This vulnerability only affects…
- risk 0.57cvss 8.8epss 0.04
A vulnerability classified as critical has been found in D-Link DIR-600L up to 2.07B01. This affects the function formSysCmd. The manipulation of the argument host leads to command injection. It is possible to initiate the attack remotely. This vulnerability only affects…
- risk 0.57cvss 9.8epss 0.01
sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the…
- risk 0.57cvss 9.6epss 0.15
An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. An attacker can send malicious flashcard to trigger this vulnerability.
- risk 0.57cvss 8.8epss 0.01
The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.7 via deserialization of untrusted input via the order_id parameter. This makes it possible for authenticated attackers, with…
- risk 0.57cvss 8.8epss 0.01
An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker to obtain sensitive information and escalate privileges via the cp_bbs_sig function.
- risk 0.57cvss 9.8epss 0.03
main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.
- risk 0.57cvss 8.8epss 0.01
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
- risk 0.57cvss 8.8epss 0.01
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
- risk 0.57cvss 8.8epss 0.01
Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.
- risk 0.57cvss 8.8epss 0.01
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
- risk 0.57cvss 8.8epss 0.01
Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote Code Execution when settings overwrite config.inc.php content.
- risk 0.57cvss 9.8epss 0.01
An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.
- risk 0.57cvss 9.8epss 0.02
An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component.
- risk 0.57cvss 9.8epss 0.02
An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colored_object_prompt functions.
- risk 0.57cvss 8.8epss 0.01
CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file.