Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-07-01 CVE-2024-38366 Injection vulnerability in Cocoapods Trunk.Cocoapods.Org
trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager.
network
low complexity
cocoapods CWE-74
critical
10.0
2024-07-01 CVE-2024-36420 Injection vulnerability in Flowiseai Flowise 1.4.3
Flowise is a drag & drop user interface to build a customized large language model flow.
network
low complexity
flowiseai CWE-74
7.5
2024-06-28 CVE-2024-39704 Injection vulnerability in Unknown-Corp Melty Blood Actress Again Current Code
Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev.
network
low complexity
unknown-corp CWE-74
critical
9.8
2024-06-05 CVE-2024-5184 Injection vulnerability in Emailgpt
The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct prompt and take over the service logic.
network
low complexity
emailgpt CWE-74
critical
9.1
2024-06-03 CVE-2023-23738 Injection vulnerability in Brainstormforce Spectra
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Brainstorm Force Spectra allows Content Spoofing, Phishing.This issue affects Spectra: from n/a through 2.3.0.
network
low complexity
brainstormforce CWE-74
5.3
2024-04-09 CVE-2024-28191 Injection vulnerability in Contao
Contao is an open source content management system.
network
low complexity
contao CWE-74
5.4
2024-03-22 CVE-2024-2777 Injection vulnerability in Campcodes Online Marriage Registration System 1.0
A vulnerability has been found in Campcodes/PHPGurukul Online Marriage Registration System 1.0 and classified as critical.
network
low complexity
campcodes CWE-74
6.5
2024-03-13 CVE-2024-28192 Injection vulnerability in Yooooomi Your Spotify
your_spotify is an open source, self hosted Spotify tracking dashboard.
network
low complexity
yooooomi CWE-74
5.3
2024-03-11 CVE-2024-0044 Injection vulnerability in Google Android
In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation.
local
low complexity
google CWE-74
6.7
2024-03-08 CVE-2024-23268 Injection vulnerability in Apple Macos
An injection issue was addressed with improved input validation.
local
low complexity
apple CWE-74
7.8