Vulnerabilities > Improper Encoding or Escaping of Output

DATE CVE VULNERABILITY TITLE RISK
2022-09-20 CVE-2022-39957 Improper Encoding or Escaping of Output vulnerability in multiple products
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass.
network
low complexity
owasp fedoraproject debian CWE-116
7.5
2022-09-20 CVE-2022-39958 Improper Encoding or Escaping of Output vulnerability in multiple products
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte range.
network
low complexity
owasp fedoraproject debian CWE-116
7.5
2022-09-08 CVE-2022-36099 Improper Encoding or Escaping of Output vulnerability in Xwiki
XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform.
network
low complexity
xwiki CWE-116
8.8
2022-09-08 CVE-2022-36100 Improper Encoding or Escaping of Output vulnerability in Xwiki
XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform.
network
low complexity
xwiki CWE-116
8.8
2022-08-24 CVE-2021-4041 Improper Encoding or Escaping of Output vulnerability in Redhat Ansible Runner
A flaw was found in ansible-runner.
local
low complexity
redhat CWE-116
7.8
2022-08-18 CVE-2020-36599 Improper Encoding or Escaping of Output vulnerability in Omniauth
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.
network
low complexity
omniauth CWE-116
critical
9.8
2022-08-18 CVE-2022-35153 Improper Encoding or Escaping of Output vulnerability in Fusionpbx 5.0.1
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
network
low complexity
fusionpbx CWE-116
critical
9.8
2022-08-12 CVE-2022-2619 Improper Encoding or Escaping of Output vulnerability in multiple products
Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted HTML page.
network
low complexity
google fedoraproject CWE-116
4.3
2022-08-01 CVE-2022-2241 Improper Encoding or Escaping of Output vulnerability in Fifu Featured Image From URL
The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
network
low complexity
fifu CWE-116
6.1
2022-07-25 CVE-2022-36446 Improper Encoding or Escaping of Output vulnerability in Webmin
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
network
low complexity
webmin CWE-116
critical
9.8