Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-07-22 CVE-2024-26020 An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04.
network
low complexity
CWE-74
critical
9.6
2024-07-03 CVE-2024-6469 Injection vulnerability in Playsms 1.4.3
A vulnerability was found in playSMS 1.4.3.
network
low complexity
playsms CWE-74
8.8
2024-07-01 CVE-2024-36420 Injection vulnerability in Flowiseai Flowise 1.4.3
Flowise is a drag & drop user interface to build a customized large language model flow.
network
low complexity
flowiseai CWE-74
7.5
2024-06-28 CVE-2024-39704 Injection vulnerability in Unknown-Corp Melty Blood Actress Again Current Code
Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev.
network
low complexity
unknown-corp CWE-74
critical
9.8
2024-06-10 CVE-2024-35728 Injection vulnerability in Themeisle Product Addons & Fields for Woocommerce
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Themeisle PPOM for WooCommerce allows Code Inclusion.This issue affects PPOM for WooCommerce: from n/a through 32.0.20.
network
low complexity
themeisle CWE-74
5.3
2024-06-10 CVE-2024-35680 Injection vulnerability in Yithemes Yith Woocommerce Product Add-Ons
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Code Injection.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.9.2.
network
low complexity
yithemes CWE-74
5.3
2024-06-05 CVE-2024-5184 Injection vulnerability in Emailgpt
The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct prompt and take over the service logic.
network
low complexity
emailgpt CWE-74
critical
9.1
2024-03-08 CVE-2024-21900 Injection vulnerability in Qnap QTS and Quts Hero
An injection vulnerability has been reported to affect several QNAP operating system versions.
network
low complexity
qnap CWE-74
6.5
2024-03-08 CVE-2024-23268 Injection vulnerability in Apple Macos
An injection issue was addressed with improved input validation.
local
low complexity
apple CWE-74
7.8
2024-03-08 CVE-2024-23274 Injection vulnerability in Apple Macos
An injection issue was addressed with improved input validation.
local
low complexity
apple CWE-74
7.8