Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-06-13 CVE-2023-28599 Injection vulnerability in Zoom
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability.
network
low complexity
zoom CWE-74
4.3
2023-06-08 CVE-2023-29405 Injection vulnerability in multiple products
The go command may execute arbitrary code at build time when using cgo.
network
low complexity
golang fedoraproject CWE-74
critical
9.8
2023-06-07 CVE-2019-25150 Injection vulnerability in Wpexperts Email Templates
The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3.
network
low complexity
wpexperts CWE-74
8.8
2023-05-30 CVE-2022-47028 Injection vulnerability in Actionlauncher Action Launcher 50.5
An issue discovered in Action Launcher for Android v50.5 allows an attacker to cause a denial of service via arbitary data injection to function insert.
local
low complexity
actionlauncher CWE-74
5.5
2023-05-30 CVE-2023-2980 Injection vulnerability in Abstrium Pydio Cells 4.2.0
A vulnerability classified as critical was found in Abstrium Pydio Cells 4.2.0.
network
low complexity
abstrium CWE-74
8.8
2023-05-30 CVE-2023-26130 Injection vulnerability in Cpp-Httplib Project Cpp-Httplib
Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests.
network
low complexity
cpp-httplib-project CWE-74
8.8
2023-05-11 CVE-2023-24539 Injection vulnerability in Golang GO
Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts.
network
low complexity
golang CWE-74
7.3
2023-05-11 CVE-2023-29400 Injection vulnerability in Golang GO
Templates containing actions in unquoted HTML attributes (e.g.
network
low complexity
golang CWE-74
7.3
2023-05-04 CVE-2023-29827 Injection vulnerability in EJS 3.1.9
ejs v3.1.9 is vulnerable to server-side template injection.
network
low complexity
ejs CWE-74
critical
9.8
2023-04-25 CVE-2022-23721 Injection vulnerability in Pingidentity Pingid Integration for Windows Login
PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username collision when two people with the same username are provisioned onto the same machine at different times.
local
low complexity
pingidentity CWE-74
3.3