Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-12-22 CVE-2022-46873 Injection vulnerability in Mozilla Firefox
Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script.
network
low complexity
mozilla CWE-74
8.8
2022-12-16 CVE-2022-42544 Injection vulnerability in Google Android 13.0
In getView of AddAppNetworksFragment.java, there is a possible way to mislead the user about network add requests due to improper input validation.
local
low complexity
google CWE-74
7.8
2022-12-07 CVE-2022-45910 Injection vulnerability in Apache Manifoldcf
Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory authority connectors of Apache ManifoldCF allows an attacker to manipulate the LDAP search queries (DoS, additional queries, filter manipulation) during user lookup, if the username or the domain string are passed to the UserACLs servlet without validation. This issue affects Apache ManifoldCF version 2.23 and prior versions.
network
low complexity
apache CWE-74
5.3
2022-12-07 CVE-2022-3643 Injection vulnerability in multiple products
Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets.
local
low complexity
linux debian CWE-74
6.5
2022-12-04 CVE-2022-35507 Injection vulnerability in Proxmox products
A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS.
network
low complexity
proxmox CWE-74
7.1
2022-11-30 CVE-2022-4188 Injection vulnerability in Google Chrome
Insufficient validation of untrusted input in CORS in Google Chrome on Android prior to 108.0.5359.71 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
network
low complexity
google CWE-74
4.3
2022-11-22 CVE-2022-33012 Injection vulnerability in Microweber 1.2.15
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
network
low complexity
microweber CWE-74
8.8
2022-11-19 CVE-2022-4064 Injection vulnerability in Dalli Project Dalli
A vulnerability was found in Dalli.
network
high complexity
dalli-project CWE-74
3.7
2022-11-18 CVE-2021-33621 Injection vulnerability in multiple products
The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting.
network
low complexity
ruby-lang fedoraproject CWE-74
8.8
2022-11-04 CVE-2022-43562 Injection vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could let a remote authenticated user conduct various attacks against the system, including cross-site scripting and cache poisoning.
network
low complexity
splunk CWE-74
5.4