The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Volume of CVEs assigned to CWE-74 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
4,975 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-46169CRITICAL Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vu | Dec 5, 2022 | 9.8 | 99 | YES | YES |
CVE-2022-35914CRITICAL /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection. | Sep 19, 2022 | 9.8 | 99 | YES | YES |
CVE-2019-2725CRITICAL Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. | Apr 26, 2019 | 9.8 | 99 | YES | YES |
CVE-2013-2251CRITICAL Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: p | Jul 20, 2013 | 9.8 | 99 | YES | YES |
CVE-2025-20281CRITICAL A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as roo | Jun 25, 2025 | 10.0 | 98 | YES | YES |
CVE-2023-22527CRITICAL A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using | Jan 16, 2024 | 9.8 | 98 | YES | YES |
CVE-2022-43769HIGH Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring temp | Apr 3, 2023 | 7.2 | 98 | YES | YES |
CVE-2020-17496CRITICAL vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists becaus | Aug 12, 2020 | 9.8 | 98 | YES | YES |
CVE-2019-17558HIGH Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates | Dec 30, 2019 | 7.5 | 98 | YES | YES |
CVE-2019-11581CRITICAL There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely | Aug 9, 2019 | 9.8 | 97 | YES | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.