Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-10-30 CVE-2023-4393 Injection vulnerability in Liquidfiles
HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attacks against an organization.
network
low complexity
liquidfiles CWE-74
6.1
2023-10-28 CVE-2023-46468 Injection vulnerability in Juzaweb CMS
An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the custom plugin function.
local
low complexity
juzaweb CWE-74
7.8
2023-10-25 CVE-2023-5043 Injection vulnerability in Kubernetes Ingress-Nginx
Ingress nginx annotation injection causes arbitrary command execution.
network
low complexity
kubernetes CWE-74
8.8
2023-10-20 CVE-2023-32786 Injection vulnerability in Langchain
In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks.
network
low complexity
langchain CWE-74
7.5
2023-10-19 CVE-2022-47583 Injection vulnerability in Mintty Project Mintty
Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal.
network
low complexity
mintty-project CWE-74
critical
9.8
2023-10-16 CVE-2023-45540 Injection vulnerability in Jorani Leave Management System 1.0.3
An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of the List of Leave requests page.
network
low complexity
jorani CWE-74
6.5
2023-10-11 CVE-2023-43661 Injection vulnerability in All-Three Cachet
Cachet, the open-source status page system.
network
low complexity
all-three CWE-74
8.8
2023-10-06 CVE-2023-45303 Injection vulnerability in Thingsboard
ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).
network
low complexity
thingsboard CWE-74
8.8
2023-10-05 CVE-2022-4145 Injection vulnerability in Redhat Openshift Container Platform 4.0
A content spoofing flaw was found in OpenShift's OAuth endpoint.
network
low complexity
redhat CWE-74
5.3
2023-10-02 CVE-2023-43835 Injection vulnerability in Superstorefinder Super Store Finder
Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote Code Execution when settings overwrite config.inc.php content.
network
low complexity
superstorefinder CWE-74
8.8