The product does not adequately filter user-controlled input for special elements with control implications.
Volume of CVEs assigned to CWE-75 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22911CRITICAL A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE. | May 27, 2021 | 9.8 | 91 | NO | YES |
CVE-2024-0801HIGH A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll. | Mar 13, 2024 | 7.5 | 57 | NO | YES |
CVE-2024-58362HIGH SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non | Jul 18, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-54771HIGH Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid application exposing a chat interface to untrusted users may all | Jul 10, 2026 | 8.1 | 37 | NO | NO |
CVE-2024-27708CRITICAL Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via the src parameter. | Dec 22, 2025 | 9.6 | 34 | NO | NO |
CVE-2026-29042CRITICAL Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell Runtime component contains a command injection vulnerability | Mar 6, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-31908CRITICAL Header injection vulnerability in Apache APISIX.
The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers.
This issue affects Ap | Apr 14, 2026 | 9.1 | 30 | NO | NO |
CVE-2021-39174HIGH Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration en | Aug 28, 2021 | 8.8 | 30 | NO | NO |
CVE-2023-40743CRITICAL ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allow | Sep 5, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-27533HIGH A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet op | Mar 30, 2023 | 8.8 | 29 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.