Vulnerabilities > Improper Encoding or Escaping of Output

DATE CVE VULNERABILITY TITLE RISK
2020-10-21 CVE-2020-27604 Improper Encoding or Escaping of Output vulnerability in Bigbluebutton
BigBlueButton before 2.3 does not implement LibreOffice sandboxing.
network
low complexity
bigbluebutton CWE-116
4.0
2020-10-16 CVE-2020-9862 Improper Encoding or Escaping of Output vulnerability in Apple products
A command injection issue existed in Web Inspector.
local
low complexity
apple CWE-116
7.8
2020-10-06 CVE-2019-4326 Improper Encoding or Escaping of Output vulnerability in Hcltech Appscan 10.0.0/9.0.3.14
"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."
network
low complexity
hcltech CWE-116
5.0
2020-09-25 CVE-2020-24592 Improper Encoding or Escaping of Output vulnerability in Mitel Micloud Management Portal 5.3/6.0/6.1
Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system information due to insufficient output sanitization.
network
low complexity
mitel CWE-116
5.0
2020-08-29 CVE-2020-24972 Improper Encoding or Escaping of Output vulnerability in multiple products
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options.
8.8
2020-08-20 CVE-2020-16281 Improper Encoding or Escaping of Output vulnerability in Rangee Rangeeos 8.0.4
The Kommbox component in Rangee GmbH RangeeOS 8.0.4 could allow a local authenticated attacker to escape from the restricted environment and execute arbitrary code due to unrestricted context menus being accessible.
local
low complexity
rangee CWE-116
4.6
2020-06-19 CVE-2017-18892 Improper Encoding or Escaping of Output vulnerability in Mattermost Server
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5.
4.3
2020-06-08 CVE-2020-5304 Improper Encoding or Escaping of Output vulnerability in Whitesourcesoftware Whitesource
The dashboard in WhiteSource Application Vulnerability Management (AVM) before version 20.4.1 allows Log Injection via a %0A%0D substring in the idp parameter to the /saml/login URI.
network
low complexity
whitesourcesoftware CWE-116
7.5
2020-06-08 CVE-2020-13625 Improper Encoding or Escaping of Output vulnerability in multiple products
PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character.
7.5
2020-04-03 CVE-2020-10960 Improper Encoding or Escaping of Output vulnerability in Mediawiki
In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page.
network
low complexity
mediawiki CWE-116
5.0