CWE-116 对输出编码和转义不恰当 类弱点 140 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-116 属于输出编码或转义不当漏洞,指产品在向其他组件发送结构化消息时,未正确编码或转义数据,导致消息结构被破坏。攻击者常借此注入恶意命令,篡改预期逻辑以执行非法操作。开发者应避免此风险,需严格遵循上下文相关的编码规范,对输出数据进行彻底验证与转义,确保特殊字符被正确隔离,从而维持消息结构的完整性与安全性。
<% String email = request.getParameter("email"); %> ... Email Address: <%= email %>$inputString = readLineFromFileHandle($serverFH); # generate an array of strings separated by the "|" character. @commands = split(/\|/, $inputString); foreach $cmd (@commands) { # separate the operator from its arguments based on a single whitespace ($operator, $args) = split(/ /, $cmd, 2); $args = UrlDecode($args); if ($operator eq "BAN") { ExecuteBan($args); } elsif ($operator eq "SAY") { ExecuteSay($args); } }$inputString = GetUntrustedArgument("command"); ($cmd, $argstr) = split(/\s+/, $inputString, 2); # removes extra whitespace and also changes CRLF's to spaces $argstr =~ s/\s+/ /gs; $argstr = UrlEncode($argstr); if (($cmd eq "BAN") && (! IsAdministrator($username))) { die "Error: you are not the admin.\n"; } # communicate with file server using a file handle $fh = GetServerFileHandle("myserver"); print $fh "$cmd $argstr\n";| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-48062 | Discourse 安全漏洞 — discourse | 7.1 | High | 2025-06-09 |
| CVE-2025-25029 | IBM Security Guardium 安全漏洞 — Security Guardium | 4.9 | Medium | 2025-05-28 |
| CVE-2021-25262 | Yandex Browser 安全漏洞 — Browser | 4.3AI | MediumAI | 2025-05-21 |
| CVE-2021-25254 | Yandex Browser 安全漏洞 — Browser Lite | 5.3AI | MediumAI | 2025-05-21 |
| CVE-2025-1308 | Portworx Backup 安全漏洞 — PX Backup | 6.5AI | MediumAI | 2025-05-19 |
| CVE-2025-47280 | Umbraco Forms 安全漏洞 — Umbraco.Forms.Issues | 4.7AI | MediumAI | 2025-05-13 |
| CVE-2025-32974 | XWiki Platform 安全漏洞 — xwiki-platform | 9.1 | Critical | 2025-04-30 |
| CVE-2025-24338 | Bosch Rexroth ctrlX OS 安全漏洞 — ctrlX OS - Solutions | 7.1 | High | 2025-04-30 |
| CVE-2025-46347 | YesWiki 安全漏洞 — yeswiki | 8.8AI | HighAI | 2025-04-29 |
| CVE-2025-31651 | Apache Tomcat 安全漏洞 — Apache Tomcat | 9.1AI | CriticalAI | 2025-04-28 |
| CVE-2025-23377 | Dell PowerProtect Data Manager Reporting 安全漏洞 — PowerProtect Data Manager | 4.2 | Medium | 2025-04-28 |
| CVE-2025-32078 | MediaWiki 安全漏洞 — Mediawiki - Version Compare Extension | 6.1AI | MediumAI | 2025-04-11 |
| CVE-2025-32072 | MediaWiki 安全漏洞 — Mediawiki Core - Feed Utils | 6.5AI | MediumAI | 2025-04-11 |
| CVE-2025-32074 | MediaWiki 安全漏洞 — Mediawiki - Confirm Account Extension | 6.1AI | MediumAI | 2025-04-11 |
| CVE-2025-30657 | Juniper Networks Junos OS 安全漏洞 — Junos OS | 5.3 | Medium | 2025-04-09 |
| CVE-2025-30345 | OpenSlides 安全漏洞 — OpenSlides | 3.5 | Low | 2025-03-21 |
| CVE-2024-50629 | Synology DiskStation Manager(DSM)和Synology BeeStation Manager 安全漏洞 — DiskStation Manager (DSM) | 5.3 | Medium | 2025-03-19 |
| CVE-2024-10441 | Synology DiskStation Manager(DSM)和Synology BeeStation Manager 安全漏洞 — DiskStation Manager (DSM) | 9.8 | Critical | 2025-03-19 |
| CVE-2025-27109 | solid 安全漏洞 — solid | 7.3 | High | 2025-02-21 |
| CVE-2025-24025 | Coolify 安全漏洞 — coolify | 5.4 | - | 2025-01-24 |
| CVE-2024-56277 | WordPress plugin Poll Maker 安全漏洞 — Poll Maker | 5.3 | Medium | 2025-01-21 |
| CVE-2025-23207 | KaTeX 安全漏洞 — KaTeX | 6.3 | Medium | 2025-01-17 |
| CVE-2024-52005 | Git 安全漏洞 — git | 8.2 | - | 2025-01-15 |
| CVE-2024-50349 | Git 安全漏洞 — git | 8.8 | - | 2025-01-14 |
| CVE-2024-52006 | Git 安全漏洞 — git | 8.8 | - | 2025-01-14 |
| CVE-2024-9427 | Koji 安全漏洞 | 5.4 | Medium | 2024-12-24 |
| CVE-2024-55663 | XWiki Platform 安全漏洞 — xwiki-platform | 8.8 | - | 2024-12-12 |
| CVE-2024-47845 | MediaWiki 安全漏洞 — Mediawiki - CSS Extension | 9.4 | - | 2024-10-05 |
| CVE-2024-47528 | LibreNMS 代码问题漏洞 — librenms | 4.8 | - | 2024-10-01 |
| CVE-2024-47531 | Scout 安全漏洞 — scout | 4.6 | Medium | 2024-09-30 |
CWE-116(对输出编码和转义不恰当) 是常见的弱点类别,本平台收录该类弱点关联的 140 条 CVE 漏洞。