CWE-74: Improper Neutralization of Special Elements (Injection) — known CVE vulnerabilities
CVEs classified under CWE-74 (Improper Neutralization of Special Elements (Injection)), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-54159 — CVSS 10.0 (critical): PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds…
CVE-2026-44182 — CVSS 10.0 (critical): Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker…
CVE-2026-25586 — CVSS 10.0 (critical): SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty on a sandbox…
CVE-2026-25520 — CVSS 10.0 (critical): SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, The return values of functions aren't wrapped. Object.values/Object.entries…
CVE-2025-20265 — CVSS 10.0 (critical): A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an…
CVE-2024-42472 — CVSS 10.0 (critical): Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised…
CVE-2024-42489 — CVSS 10.0 (critical): Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the…
CVE-2024-38366 — CVSS 10.0 (critical): trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies whether a user has…
CVE-2023-1523 — CVSS 10.0 (critical): Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it…
CVE-2022-31126 — CVSS 10.0 (critical): Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a…
CVE-2021-41163 — CVSS 10.0 (critical): Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code…
CVE-2020-26282 — CVSS 10.0 (critical): BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data as a HAR file…
CVE-2020-15164 — CVSS 10.0 (critical): in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username with leading…
CVE-2018-21268 — CVSS 10.0 (critical): The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs…
CVE-2014-8423 — CVSS 10.0 (critical): Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands…
CVE-2026-77683 — CVSS 9.9 (critical): A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file…
CVE-2026-20231 — CVSS 9.9 (critical): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a…
CVE-2026-54680 — CVSS 9.9 (critical): Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration…
CVE-2026-0284 — CVSS 9.9 (critical): An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an…
CVE-2025-55343 — CVSS 9.9 (critical): Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_depe_codi…
CVE-2023-37462 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document…
CVE-2023-36470 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By either creating a new or…
CVE-2023-36469 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own…
CVE-2023-29527 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions a user…
CVE-2023-29526 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible…
CVE-2023-29525 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versions of xwiki are…
CVE-2023-29524 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute anything…
CVE-2023-29523 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own…
CVE-2023-29522 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can…
CVE-2023-29518 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can…
CVE-2023-29516 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on…
CVE-2023-29514 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on any…
CVE-2023-29512 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a…
CVE-2023-29510 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In XWiki, every user can add…
CVE-2023-25616 — CVSS 9.9 (critical): In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code…
CVE-2023-27479 — CVSS 9.9 (critical): XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with…
CVE-2022-2992 — CVSS 9.9 (critical): A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated…
CVE-2022-36084 — CVSS 9.9 (critical): cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl starting with version…
CVE-2016-9832 — CVSS 9.9 (critical): PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and…
CVE-2026-19747 — CVSS 9.8 (critical): A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This…
CVE-2026-19348 — CVSS 9.8 (critical): A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file…
CVE-2026-20272 — CVSS 9.8 (critical): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a…
CVE-2026-18686 — CVSS 9.8 (critical): A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file…
CVE-2026-18685 — CVSS 9.8 (critical): A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc…
CVE-2026-18684 — CVSS 9.8 (critical): A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of…
CVE-2026-18616 — CVSS 9.8 (critical): A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file…
CVE-2026-18615 — CVSS 9.8 (critical): A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the…