CWE-116 对输出编码和转义不恰当 类弱点 128 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-116 属于输出编码或转义不当漏洞,指产品在向其他组件发送结构化消息时,未正确编码或转义数据,导致消息结构被破坏。攻击者常借此注入恶意命令,篡改预期逻辑以执行非法操作。开发者应避免此风险,需严格遵循上下文相关的编码规范,对输出数据进行彻底验证与转义,确保特殊字符被正确隔离,从而维持消息结构的完整性与安全性。
<% String email = request.getParameter("email"); %> ... Email Address: <%= email %>$inputString = readLineFromFileHandle($serverFH); # generate an array of strings separated by the "|" character. @commands = split(/\|/, $inputString); foreach $cmd (@commands) { # separate the operator from its arguments based on a single whitespace ($operator, $args) = split(/ /, $cmd, 2); $args = UrlDecode($args); if ($operator eq "BAN") { ExecuteBan($args); } elsif ($operator eq "SAY") { ExecuteSay($args); } }$inputString = GetUntrustedArgument("command"); ($cmd, $argstr) = split(/\s+/, $inputString, 2); # removes extra whitespace and also changes CRLF's to spaces $argstr =~ s/\s+/ /gs; $argstr = UrlEncode($argstr); if (($cmd eq "BAN") && (! IsAdministrator($username))) { die "Error: you are not the admin.\n"; } # communicate with file server using a file handle $fh = GetServerFileHandle("myserver"); print $fh "$cmd $argstr\n";| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-42810 | Apache Polaris 通配符命名空间凭证泄露漏洞 — Apache Polaris | 9.9 | Critical | 2026-05-04 |
| CVE-2026-42040 | Axios 安全漏洞 — axios | 3.7 | Low | 2026-04-24 |
| CVE-2026-40567 | FreeScout 安全漏洞 — freescout | 5.8 | Medium | 2026-04-21 |
| CVE-2026-6058 | Zyxel WRE6505 安全漏洞 — WRE6505 v2 firmware | 4.5 | Medium | 2026-04-21 |
| CVE-2026-20136 | Cisco Identity Services Engine(Cisco ISE)和Cisco ISE Passive Identity Connector 安全漏洞 — Cisco Identity Services Engine Software | 6.0 | Medium | 2026-04-15 |
| CVE-2026-2404 | Schneider Electric PowerChute Serial Shutdown 安全漏洞 — PowerChute™ Serial Shutdown | 7.5 | - | 2026-04-14 |
| CVE-2026-40023 | Apache Log4cxx 安全漏洞 — Apache Log4cxx | 5.3 | - | 2026-04-10 |
| CVE-2026-40021 | Apache log4net 安全漏洞 — Apache Log4net | 9.1 | - | 2026-04-10 |
| CVE-2026-34481 | Apache Log4j 安全漏洞 — Apache Log4j JSON Template Layout | 4.8 | - | 2026-04-10 |
| CVE-2026-34480 | Apache Log4j 安全漏洞 — Apache Log4j Core | 5.8AI | MediumAI | 2026-04-10 |
| CVE-2026-34479 | Apache Log4j 安全漏洞 — Apache Log4j 1 to Log4j 2 bridge | 6.5AI | MediumAI | 2026-04-10 |
| CVE-2026-34483 | Apache Tomcat 安全漏洞 — Apache Tomcat | 9.8AI | CriticalAI | 2026-04-09 |
| CVE-2026-25932 | GLPI 安全漏洞 — glpi | 7.2 | High | 2026-04-06 |
| CVE-2026-32811 | Heimdall 安全漏洞 — heimdall | 8.2 | High | 2026-03-20 |
| CVE-2026-33301 | OpenEMR 安全漏洞 — openemr | 3.5 | - | 2026-03-19 |
| CVE-2026-31898 | jsPDF 安全漏洞 — jsPDF | 8.1 | High | 2026-03-18 |
| CVE-2025-12697 | GitLab 安全漏洞 — GitLab | 2.2 | Low | 2026-03-11 |
| CVE-2026-28350 | lxml_html_clean 安全漏洞 — lxml_html_clean | 6.1 | Medium | 2026-03-05 |
| CVE-2026-28348 | lxml_html_clean 安全漏洞 — lxml_html_clean | 6.1 | Medium | 2026-03-05 |
| CVE-2026-27812 | Sub2API 安全漏洞 — sub2api | 8.8AI | HighAI | 2026-02-26 |
| CVE-2026-21443 | OpenEMR 安全漏洞 — openemr | 6.1 | - | 2026-02-25 |
| CVE-2026-25940 | jsPDF 安全漏洞 — jsPDF | 8.1 | High | 2026-02-19 |
| CVE-2025-15312 | Tanium Appliance 安全漏洞 — Tanium Appliance | 6.6 | Medium | 2026-02-05 |
| CVE-2026-25543 | HTMLSanitizer 安全漏洞 — HtmlSanitizer | 6.1AI | MediumAI | 2026-02-04 |
| CVE-2026-24737 | jsPDF 安全漏洞 — jsPDF | 8.1 | High | 2026-02-02 |
| CVE-2025-66488 | Discourse 安全漏洞 — discourse | 4.6 | Medium | 2026-01-28 |
| CVE-2026-24439 | Tenda W30E 安全漏洞 — W30E V2 | 9.4AI | CriticalAI | 2026-01-26 |
| CVE-2026-22792 | 5ire 安全漏洞 — 5ire | 9.7 | Critical | 2026-01-21 |
| CVE-2026-22712 | Mediawiki - ApprovedRevs Extension 安全漏洞 — Mediawiki - ApprovedRevs Extension | 9.1 | - | 2026-01-09 |
| CVE-2025-59158 | Coolify 安全漏洞 — coolify | 5.4 | - | 2026-01-05 |
CWE-116(对输出编码和转义不恰当) 是常见的弱点类别,本平台收录该类弱点关联的 128 条 CVE 漏洞。