Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-04-21 CVE-2022-27924 Injection vulnerability in Zimbra Collaboration 8.8.15/9.0.0
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance.
network
low complexity
zimbra CWE-74
7.5
2022-04-15 CVE-2022-28345 Injection vulnerability in Signal
The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection.
network
low complexity
signal CWE-74
7.5
2022-04-11 CVE-2022-24832 Injection vulnerability in Thoughtworks Gocd
GoCD is an open source a continuous delivery server.
network
high complexity
thoughtworks CWE-74
6.8
2022-04-11 CVE-2022-24838 Injection vulnerability in Nextcloud Calendar
Nextcloud Calendar is a calendar application for the nextcloud framework.
network
low complexity
nextcloud CWE-74
critical
9.8
2022-04-11 CVE-2021-22055 Injection vulnerability in VMWare Photon OS
The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter.
network
low complexity
vmware CWE-74
5.3
2022-04-09 CVE-2022-1287 Injection vulnerability in School Club Application System Project School Club Application System 1.0
A vulnerability classified as critical was found in School Club Application System 1.0.
network
low complexity
school-club-application-system-project CWE-74
critical
9.8
2022-03-29 CVE-2022-25420 Injection vulnerability in Nttr GOO Blog 1.0
NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection.
network
low complexity
nttr CWE-74
critical
9.8
2022-03-27 CVE-2022-26205 Injection vulnerability in Marky Project Marky
Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields.
network
low complexity
marky-project CWE-74
critical
9.8
2022-03-14 CVE-2022-20001 Injection vulnerability in multiple products
fish is a command line shell.
local
low complexity
fishshell fedoraproject debian CWE-74
7.8
2022-03-14 CVE-2022-22344 Injection vulnerability in IBM Spectrum Copy Data Management
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.
network
low complexity
ibm CWE-74
6.1