Threats Tagged 'cwe-74'
View all threats tagged with 'cwe-74'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-74'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-12888: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in Thinkst Applied Research CanarytokensCVE-2026-12888 0 An HTML injection vulnerability exists in the Google Chat webhook notification sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation in Google Chat. An attacker can insert limited HTML content including links. This issue affects Canarytokens: from Docker tag sha-4aef1db90 before sha-8ab4dccd, from Git commit 4aef1db90 before 8ab4dccd. Join the discussion | CVE Database V5 | 06/22/2026, 13:05:53 UTC Added: 06/22/2026, 13:54:17 UTC |
CVE-2025-27511: CWE-502: Deserialization of Untrusted Data in geoserver org.geoserver.extension:gs-db2CVE-2025-27511 0 GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue. Join the discussion | CVE Database V5 | 06/18/2026, 14:23:01 UTC Added: 06/18/2026, 15:20:12 UTC |
CVE-2026-50107: CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in F5 NGINX Gateway FabricCVE-2026-50107 0 When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition (CRD) access log format setting are rendered directly into NGINX configuration templates without sanitization or escaping. An authenticated attacker with permission to create or modify these CRDs may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure from the vulnerability trigger itself. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Join the discussion | CVE Database V5 | 06/17/2026, 20:04:44 UTC Added: 06/17/2026, 20:20:42 UTC |
CVE-2026-11859: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in Thinkst Applied Research CanarytokensCVE-2026-11859 0 CVE-2026-11859 is an HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens. This vulnerability allows interface manipulation and cross-site scripting (XSS) in email clients that render HTML emails. It affects Canarytokens versions from Docker tag sha-c0f3cf142 before sha-08c3f93d and Git commit c0f3cf142 before 08c3f93d. The vulnerability has a low severity score and no known exploits in the wild. Join the discussion | CVE Database V5 | 06/10/2026, 11:35:14 UTC Added: 06/10/2026, 12:13:03 UTC |
CVE-2026-46546: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in frappe lmsCVE-2026-46546 0 Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors' browsers to navigate to an attacker-chosen URL. This issue has been patched in version 2.53.0. Join the discussion | CVE Database V5 | 06/09/2026, 23:54:06 UTC Added: 06/10/2026, 00:25:44 UTC |
CVE-2026-47634: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in Microsoft Microsoft SharePoint Server 2019CVE-2026-47634 0 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Join the discussion | CVE Database V5 | 06/09/2026, 17:05:48 UTC Added: 06/09/2026, 17:27:12 UTC |
CVE-2026-42835: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in Microsoft Microsoft Teams for AndroidCVE-2026-42835 0 Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 06/09/2026, 17:05:20 UTC Added: 06/09/2026, 17:26:24 UTC |
CVE-2026-8795: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in Rapid7 VelociraptorCVE-2026-8795 0 CVE-2026-8795 is a YAML injection vulnerability in Rapid7 Velociraptor versions before 0.76.6. It arises from improper escaping of the hostname field in a YAML template, allowing crafted input to inject arbitrary VQL code. This can lead to execution of commands with full permissions on the analyst's machine when applying remapping files. Join the discussion | CVE Database V5 | 06/09/2026, 01:04:21 UTC Added: 06/09/2026, 01:18:40 UTC |
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security UpdateCVE-2025-13462 0 This update includes the following RPMs: python3.12: * python3.12-3.12.13-3.1.hum1 (aarch64, x86_64) * python3.12-debug-3.12.13-3.1.hum1 (aarch64, x86_64) * python3.12-devel-3.12.13-3.1.hum1 (aarch64, x86_64) * python3.12-idle-3.12.13-3.1.hum1 (aarch64, x86_64) * python3.12-libs-3.12.13-3.1.hum1 (aarch64, x86_64) * python3.12-test-3.12.13-3.1.hum1 (aarch64, x86_64) * python3.12-tkinter-3.12.13-3.1.hum1 (aarch64, x86_64) * python3.12-3.12.13-3.1.hum1.src (src) Security Fix(es): python3.12: * CVE-2025-13462 * CVE-2026-3446 * CVE-2026-3479 Join the discussion | GCVE Database | 04/23/2026, 11:34:58 UTC Added: 06/05/2026, 21:31:41 UTC |
CVE-2026-47644: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in Microsoft Copilot Chat (Microsoft Edge)CVE-2026-47644 0 Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 06/04/2026, 22:00:52 UTC Added: 06/04/2026, 22:48:37 UTC |
Showing 1 to 10 of 14 results