Vulnerabilities > Improper Encoding or Escaping of Output

DATE CVE VULNERABILITY TITLE RISK
2023-06-13 CVE-2023-32301 Improper Encoding or Escaping of Output vulnerability in Discourse
Discourse is an open source discussion platform.
network
low complexity
discourse CWE-116
5.3
2023-06-10 CVE-2023-3190 Improper Encoding or Escaping of Output vulnerability in Teampass
Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
network
low complexity
teampass CWE-116
4.6
2023-06-02 CVE-2023-23599 Improper Encoding or Escaping of Output vulnerability in Mozilla Firefox
When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within.
network
low complexity
mozilla CWE-116
6.5
2023-06-02 CVE-2023-29541 Improper Encoding or Escaping of Output vulnerability in Mozilla products
Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands.
network
low complexity
mozilla CWE-116
8.8
2023-06-01 CVE-2023-32712 Improper Encoding or Escaping of Output vulnerability in Splunk
In Splunk Enterprise versions below 9.1.0.2, 9.0.5.1, and 8.2.11.2, an attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files that, when a vulnerable terminal application reads them, can potentially, at worst, result in possible code execution in the vulnerable application.
network
high complexity
splunk CWE-116
3.1
2023-05-30 CVE-2023-1711 Improper Encoding or Escaping of Output vulnerability in Hitachienergy Foxman UN and Unem
A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that use remote authentication to the network elements.
local
low complexity
hitachienergy CWE-116
4.4
2023-05-23 CVE-2023-31669 Improper Encoding or Escaping of Output vulnerability in Webassembly Binary Toolkit 1.0.32
WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote (").
local
low complexity
webassembly CWE-116
5.5
2023-05-08 CVE-2023-30844 Improper Encoding or Escaping of Output vulnerability in Mutagen and Mutagen Compose
Mutagen provides real-time file synchronization and flexible network forwarding for developers.
network
low complexity
mutagen CWE-116
8.8
2023-03-24 CVE-2022-42948 Improper Encoding or Escaping of Output vulnerability in Helpsystems Cobalt Strike 4.7.1
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components.
network
low complexity
helpsystems CWE-116
critical
9.8
2023-03-16 CVE-2023-28101 Improper Encoding or Escaping of Output vulnerability in Flatpak
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.
network
low complexity
flatpak CWE-116
4.3