The product receives data from an upstream component, but does not filter or incorrectly filters special elements before sending it to a downstream component.
Volume of CVEs assigned to CWE-790 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-11331HIGH An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ proce | Jul 22, 2026 | 7.5 | 35 | NO | NO |
CVE-2023-22578CRITICAL Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections. | Feb 16, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-45239CRITICAL A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled, allows an attacker who can control the username, rem-addr, | Oct 6, 2023 | 9.8 | 29 | NO | NO |
CVE-2026-9658HIGH Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths.
The header injection rule was ineffective at blocking header | May 28, 2026 | 7.3 | 28 | NO | NO |
CVE-2021-43802HIGH Etherpad is a real-time collaborative editor. In versions prior to 1.8.16, an attacker can craft an `*.etherpad` file that, when imported, might allow the attacker to gain admin pr | Dec 9, 2021 | 8.8 | 27 | NO | NO |
CVE-2026-2328HIGH An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their intended scope via path traversal, resulting in exposure of s | Mar 30, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-15576HIGH If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the other, jailed processes may no | Mar 9, 2026 | 7.5 | 26 | NO | NO |
CVE-2024-42416HIGH The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory.
Malic | Sep 5, 2024 | 8.8 | 25 | NO | NO |
CVE-2025-27260HIGH Ericsson
Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special
Elements vulnerability which, if exploited, can lead to unauthorized
modification o | Mar 25, 2026 | 7.5 | 24 | NO | NO |
CVE-2024-31616HIGH An issue discovered in RG-RSR10-01G-T(W)-S and RG-RSR10-01G-T(WA)-S routers with firmware version RSR10-01G-T-S_RSR_3.0(1)B9P2, Release(07150910) allows attackers to execute arbitr | Apr 23, 2024 | 8.8 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.