CWE-74 输出中的特殊元素转义处理不恰当(注入) 类弱点 411 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-74指下游组件注入漏洞,属输入验证缺陷。攻击者通过构造包含特殊字符的恶意输入,干扰下游组件对命令或数据的解析逻辑,从而执行非预期操作或篡改数据结构。开发者应避免直接拼接用户输入,需实施严格的输入过滤与输出编码,确保特殊元素被正确转义或隔离,防止其被下游组件误解释为可执行指令或结构标记。
$userName = $_POST["user"]; $command = 'ls -l /home/' . $userName; system($command);;rm -rf /String author = request.getParameter(AUTHOR_PARAM); ... Cookie cookie = new Cookie("author", author); cookie.setMaxAge(cookieExpiration); response.addCookie(cookie);HTTP/1.1 200 OK ... Set-Cookie: author=Jane Smith ...| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-50107 | F5 nginx gateway fabric 输入验证错误漏洞 — NGINX Gateway Fabric | 8.1 | High | 2026-06-17 |
| CVE-2026-20220 | Cisco Crosswork Network Change Automation 输入验证错误漏洞 — Cisco Crosswork Network Change Automation | 6.3 | Medium | 2026-06-17 |
| CVE-2026-54231 | Redhat libreport 输入验证错误漏洞 — Red Hat Enterprise Linux 6 | 5.5 | Medium | 2026-06-13 |
| CVE-2026-47162 | Vim 注入漏洞 — vim | - | - | 2026-06-11 |
| CVE-2026-11859 | Canarytokens 注入漏洞 — Canarytokens | - | - | 2026-06-10 |
| CVE-2026-46546 | Frappe Learning Management System 注入漏洞 — lms | - | - | 2026-06-09 |
| CVE-2026-47634 | Microsoft Office SharePoint 注入漏洞 — Microsoft SharePoint Server 2019 | 7.3 | High | 2026-06-09 |
| CVE-2026-42835 | Microsoft Teams 注入漏洞 — Microsoft Teams for Android | 8.1 | High | 2026-06-09 |
| CVE-2026-8795 | Rapid7 Velociraptor 注入漏洞 — Velociraptor | 7.8 | High | 2026-06-09 |
| CVE-2026-11457 | JeeWMS 安全漏洞 — JeeWMS | 7.3 | High | 2026-06-07 |
| CVE-2026-47644 | Microsoft Copilot Chat 注入漏洞 — Copilot Chat (Microsoft Edge) | 6.5 | Medium | 2026-06-04 |
| CVE-2026-41237 | Froxlor 注入漏洞 — froxlor | - | - | 2026-06-04 |
| CVE-2026-41234 | Froxlor 安全漏洞 — froxlor | 7.6 | High | 2026-06-04 |
| CVE-2026-10729 | Canarytokens 安全漏洞 — Canarytokens | - | - | 2026-06-03 |
| CVE-2026-10661 | BlenderMCP 安全漏洞 — blender-mcp | 4.3 | Medium | 2026-06-02 |
| CVE-2026-8993 | DITEC D.Launcher 2 安全漏洞 — D.Launcher 2 | 6.5 | Medium | 2026-06-02 |
| CVE-2026-7770 | IBM i Access 注入漏洞 — i Access Family | 8.8 | High | 2026-06-01 |
| CVE-2026-10223 | Hermes Agent 安全漏洞 — hermes-agent | 6.3 | Medium | 2026-06-01 |
| CVE-2026-10222 | Hermes Agent 安全漏洞 — hermes-agent | 5.6 | Medium | 2026-06-01 |
| CVE-2026-10221 | Hermes Agent 安全漏洞 — hermes-agent | 7.3 | High | 2026-06-01 |
| CVE-2026-10220 | Hermes Agent 安全漏洞 — hermes-agent | 7.3 | High | 2026-06-01 |
| CVE-2026-10210 | AstrBot 安全漏洞 — AstrBot | 6.3 | Medium | 2026-06-01 |
| CVE-2026-45344 | LinkAce 注入漏洞 — LinkAce | 8.1 | High | 2026-05-28 |
| CVE-2026-9422 | KLiK SocialMediaWebsite 安全漏洞 — KLiK SocialMediaWebsite | 7.3 | High | 2026-05-25 |
| CVE-2026-9420 | KLiK SocialMediaWebsite 安全漏洞 — KLiK SocialMediaWebsite | 6.3 | Medium | 2026-05-25 |
| CVE-2026-9366 | Hermes Agent 安全漏洞 — hermes-agent | 7.3 | High | 2026-05-24 |
| CVE-2026-9353 | Hermes Agent 安全漏洞 — hermes-agent | 7.3 | High | 2026-05-24 |
| CVE-2026-6279 | WordPress plugin Avada (Fusion) Builder 注入漏洞 — Avada (Fusion) Builder | 9.8 | Critical | 2026-05-21 |
| CVE-2026-20199 | Cisco ThousandEyes Virtual Appliance 注入漏洞 — Cisco ThousandEyes Enterprise Agent | 4.7 | Medium | 2026-05-20 |
| CVE-2026-42334 | Mongoose 注入漏洞 — mongoose | 7.5 | High | 2026-05-14 |
CWE-74(输出中的特殊元素转义处理不恰当(注入)) 是常见的弱点类别,本平台收录该类弱点关联的 411 条 CVE 漏洞。