Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-11-10 CVE-2024-11058 Injection vulnerability in Surajkumarvishwakarma Real Estate Management System
A vulnerability was found in CodeAstro Real Estate Management System up to 1.0.
network
low complexity
surajkumarvishwakarma CWE-74
7.2
2024-11-02 CVE-2024-10697 Injection vulnerability in Tenda AC6 Firmware 15.03.05.19
A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical.
network
low complexity
tenda CWE-74
critical
9.8
2024-10-29 CVE-2024-7472 Injection vulnerability in Lunary 1.2.26
lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup).
network
low complexity
lunary CWE-74
6.5
2024-10-29 CVE-2024-8309 Injection vulnerability in Langchain 0.2.5
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection.
network
low complexity
langchain CWE-74
critical
9.8
2024-10-19 CVE-2024-10157 Injection vulnerability in PHPgurukul Boat Booking System 1.0
A vulnerability was found in PHPGurukul Boat Booking System 1.0.
network
low complexity
phpgurukul CWE-74
critical
9.8
2024-10-19 CVE-2024-10153 Injection vulnerability in PHPgurukul Boat Booking System 1.0
A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical.
network
low complexity
phpgurukul CWE-74
critical
9.8
2024-09-19 CVE-2024-25673 Injection vulnerability in Couchbase Server
Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
network
low complexity
couchbase CWE-74
6.1
2024-09-17 CVE-2024-45612 Injection vulnerability in Contao
Contao is an Open Source CMS.
network
low complexity
contao CWE-74
5.3
2024-09-03 CVE-2024-42903 Injection vulnerability in Limesurvey
A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.
network
low complexity
limesurvey CWE-74
6.5
2024-09-02 CVE-2024-45312 Injection vulnerability in Overleaf
Overleaf is a web-based collaborative LaTeX editor.
network
low complexity
overleaf CWE-74
5.3