Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-74
Total 803 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-10761 1 Logitech 10 K360, K360 Firmware, K400r and 7 more 2019-07-08 3.3 LOW 6.5 MEDIUM
Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.
CVE-2019-6800 1 Titanhq 1 Spamtitan 2019-06-06 8.5 HIGH 7.5 HIGH
In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network position is trivially able to inject arbitrary commands.
CVE-2016-8900 1 Exponentcms 1 Exponent Cms 2019-05-28 7.5 HIGH 9.8 CRITICAL
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related to change_tags.
CVE-2016-8901 1 B2evolution 1 B2evolution 2019-05-28 7.5 HIGH 9.8 CRITICAL
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.
CVE-2016-8899 1 Exponentcms 1 Exponent Cms 2019-05-24 7.5 HIGH 9.8 CRITICAL
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change_cats.
CVE-2017-1000493 1 Rocket.chat 1 Rocket.chat 2019-05-01 7.5 HIGH 9.8 CRITICAL
Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover
CVE-2017-14523 1 Wondercms 1 Wondercms 2019-04-30 5.0 MEDIUM 7.5 HIGH
** DISPUTED ** WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as a self attack.
CVE-2017-1000217 1 Opencast 1 Opencast 2019-04-29 6.8 MEDIUM 8.8 HIGH
Opencast 2.3.2 and older versions are vulnerable to script injections through media and metadata in the player and media module resulting in arbitrary code execution, fixed in 2.3.3 and 3.0.
CVE-2017-17511 2 Debian, Kildclient 2 Debian Linux, Kildclient 2019-04-26 6.8 MEDIUM 8.8 HIGH
KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to prefs.c and worldgui.c.
CVE-2015-5462 1 Axiomsl 1 Axiom 2019-04-08 4.3 MEDIUM 6.1 MEDIUM
AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier allows remote attackers to inject HTML into the scoping dashboard features.
CVE-2018-4153 1 Apple 1 Mac Os X 2019-04-04 4.3 MEDIUM 5.9 MEDIUM
An injection issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14.
CVE-2018-1000130 1 Jolokia 1 Webarchive Agent 2019-03-08 6.8 MEDIUM 8.1 HIGH
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
CVE-2017-7703 2 Debian, Wireshark 2 Debian Linux, Wireshark 2019-03-01 5.0 MEDIUM 7.5 HIGH
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-imap.c by calculating a line's end correctly.
CVE-2018-16627 1 Getkirby 1 Kirby 2019-02-26 5.8 MEDIUM 6.1 MEDIUM
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
CVE-2019-8948 1 Papercut 2 Papercut Mf, Papercut Ng 2019-02-21 7.5 HIGH 9.8 CRITICAL
PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.
CVE-2015-3013 1 Owncloud 1 Owncloud 2019-02-07 6.0 MEDIUM N/A
ownCloud Server before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allows remote authenticated users to bypass the file blacklist and upload arbitrary files via a file path with UTF-8 encoding, as demonstrated by uploading a .htaccess file.
CVE-2019-7351 1 Zoneminder 1 Zoneminder 2019-02-04 4.3 MEDIUM 6.5 MEDIUM
Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject a custom Log message provided by the attacker in the 'log' view page, as demonstrated by the message=User%20'admin'%20Logged%20in value.
CVE-2018-1000854 1 Esigate 1 Esigate 2019-01-07 7.5 HIGH 9.8 CRITICAL
esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in ESI directive with user specified XSLT that can result in Remote Code Execution. This attack appear to be exploitable via Use of another weakness in backend application to reflect ESI directives. This vulnerability appears to have been fixed in 5.3.
CVE-2018-18207 1 Virtualmin 1 Virtualmin 2018-11-27 4.3 MEDIUM 6.1 MEDIUM
Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.
CVE-2015-2180 1 Roundcube 1 Webmail 2018-10-30 9.0 HIGH 8.8 HIGH
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.