Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-06-23 CVE-2023-3380 Injection vulnerability in Wavlink Wn579X3 Firmware 20200515
A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615.
network
low complexity
wavlink CWE-74
critical
9.8
2023-06-22 CVE-2023-28016 Injection vulnerability in Hcltech Bigfix OSD Bare Metal Server 311.12
Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to supply invalid input to cause the OSD Bare Metal Server to perform a redirect to an attacker-controlled domain.
network
low complexity
hcltech CWE-74
6.1
2023-06-17 CVE-2023-35810 Injection vulnerability in Sugarcrm 11.0.0/12.0.0
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3.
network
low complexity
sugarcrm CWE-74
7.2
2023-06-16 CVE-2023-2797 Injection vulnerability in Mattermost
Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink on a channel.
network
low complexity
mattermost CWE-74
6.5
2023-06-13 CVE-2023-28598 Injection vulnerability in Zoom
Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability.
network
low complexity
zoom CWE-74
6.5
2023-06-13 CVE-2023-28599 Injection vulnerability in Zoom
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability.
network
low complexity
zoom CWE-74
4.3
2023-06-08 CVE-2023-29405 Injection vulnerability in multiple products
The go command may execute arbitrary code at build time when using cgo.
network
low complexity
golang fedoraproject CWE-74
critical
9.8
2023-06-07 CVE-2019-25150 Injection vulnerability in Wpexperts Email Templates
The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3.
network
low complexity
wpexperts CWE-74
8.8
2023-05-30 CVE-2022-47028 Injection vulnerability in Actionlauncher Action Launcher 50.5
An issue discovered in Action Launcher for Android v50.5 allows an attacker to cause a denial of service via arbitary data injection to function insert.
local
low complexity
actionlauncher CWE-74
5.5
2023-05-30 CVE-2023-2980 Injection vulnerability in Abstrium Pydio Cells 4.2.0
A vulnerability classified as critical was found in Abstrium Pydio Cells 4.2.0.
network
low complexity
abstrium CWE-74
8.8