CWE-917
CWE-917
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 11 of 11- CVE-2022-26134Critical· 9.8KEVEXPLOITEPSS 94%23 h ago
Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability
- CVE-2020-17530Critical· 9.8KEVEXPLOITEPSS 94%23 h ago
Apache Struts Remote Code Execution Vulnerability
- CVE-2020-10199High· 8.8KEVEXPLOITEPSS 94%23 h ago
Sonatype Nexus Repository Remote Code Execution Vulnerability
- CVE-2021-26084Critical· 9.8KEVEXPLOITEPSS 94%23 h ago
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
- CVE-2021-45046Critical· 9.0KEVEXPLOITEPSS 94%23 h ago
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
- CVE-2026-11561Critical· 9.8EPSS 0%1 d ago
Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue
- CVE-2026-40985Medium· 6.4EPSS 0%2 d ago
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
- CVE-2026-41719Medium· 6.4EPSS 0%2 d ago
A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator. Affected versions: Spring Data KeyValue /
- CVE-2026-41729High· 8.1EPSS 0%2 d ago
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment
- CVE-2026-41717High· 8.1EPSS 0%2 d ago
Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repository query method is annotated with @Query and utilizes a capture-all p
- CVE-2026-8888High· 7.5EPSS 0%7 d ago
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific pa
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.