cwe-74
Safeguard articles tagged "cwe-74" — guides, analysis, and best practices for software supply chain and application security.
12 articles
CVE-2019-17558: Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability
CVE-2019-17558 affects Apache Solr and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2019-2725: Oracle WebLogic Server, Injection
CVE-2019-2725 affects Oracle WebLogic Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-01-10.
CVE-2020-17496: vBulletin PHP Module Remote Code Execution Vulnerability
CVE-2020-17496 affects vBulletin vBulletin and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2020-8468: Trend Micro Multiple Products Content Validation Escape Vulnerability
CVE-2020-8468 affects Trend Micro Apex One, OfficeScan and Worry-Free Business Security Agents and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2019-11581: Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability
CVE-2019-11581 affects Atlassian Jira Server and Data Center and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-03-07.
CVE-2020-28949: PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability
CVE-2020-28949 affects PEAR Archive_Tar and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-08-25.
CVE-2022-46169: Cacti Command Injection Vulnerability
CVE-2022-46169 affects Cacti Cacti and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-02-16.
CVE-2022-35914: Teclib GLPI Remote Code Execution Vulnerability
CVE-2022-35914 affects Teclib GLPI and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-03-07.
CVE-2023-22527: Atlassian Confluence Data Center and Server Template Injection Vulnerability
CVE-2023-22527 affects Atlassian Confluence Data Center and Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-01-24.
CVE-2022-43769: Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability
CVE-2022-43769 affects Hitachi Vantara Pentaho Business Analytics (BA) Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-03-03.
CVE-2025-20281: Cisco Identity Services Engine Injection Vulnerability
CVE-2025-20281 affects Cisco Identity Services Engine and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-28.
CVE-2025-20337: Cisco Identity Services Engine Injection Vulnerability
CVE-2025-20337 affects Cisco Identity Services Engine and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-28.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.