Vulnerabilities > Improper Encoding or Escaping of Output

DATE CVE VULNERABILITY TITLE RISK
2023-01-02 CVE-2015-10011 Improper Encoding or Escaping of Output vulnerability in Cisco Openresolve
A vulnerability classified as problematic has been found in OpenDNS OpenResolve.
network
low complexity
cisco CWE-116
critical
9.8
2022-12-27 CVE-2020-36567 Improper Encoding or Escaping of Output vulnerability in Gin-Gonic GIN
Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines.
network
low complexity
gin-gonic CWE-116
7.5
2022-12-22 CVE-2022-22744 Improper Encoding or Escaping of Output vulnerability in Mozilla Firefox
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell.
network
low complexity
mozilla CWE-116
8.8
2022-12-19 CVE-2022-43883 Improper Encoding or Escaping of Output vulnerability in IBM Cognos Analytics
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data.
network
low complexity
ibm CWE-116
7.5
2022-12-12 CVE-2021-38997 Improper Encoding or Escaping of Output vulnerability in IBM API Connect
IBM API Connect V10.0.0.0 through V10.0.5.0, V10.0.1.0 through V10.0.1.7, and V2018.4.1.0 through 2018.4.1.19 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.
network
low complexity
ibm CWE-116
5.4
2022-11-23 CVE-2022-41934 Improper Encoding or Escaping of Output vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-116
8.8
2022-11-23 CVE-2022-40870 Improper Encoding or Escaping of Output vulnerability in Parallels Remote Application Server 18.0
The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks.
network
high complexity
parallels CWE-116
8.1
2022-11-21 CVE-2022-0421 Improper Encoding or Escaping of Output vulnerability in Fivestarplugins Five Star Restaurant Reservations
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings.
network
low complexity
fivestarplugins CWE-116
6.1
2022-11-16 CVE-2022-4011 Improper Encoding or Escaping of Output vulnerability in Simple History Project Simple History
A vulnerability was found in Simple History Plugin.
network
low complexity
simple-history-project CWE-116
critical
9.8
2022-11-14 CVE-2022-34316 Improper Encoding or Escaping of Output vulnerability in IBM Cics TX 11.1
IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers.
network
low complexity
ibm CWE-116
5.3