Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-09-28 CVE-2022-3215 Injection vulnerability in Apple Swiftnio
NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack.
network
low complexity
apple CWE-74
7.5
2022-09-26 CVE-2021-41437 Injection vulnerability in Asus Rt-Ax88U Firmware
An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.
network
low complexity
asus CWE-74
6.5
2022-09-19 CVE-2022-35914 Injection vulnerability in Glpi-Project Glpi
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
network
low complexity
glpi-project CWE-74
critical
9.8
2022-09-14 CVE-2022-38796 Injection vulnerability in Feehi CMS 2.1.1
A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header.
network
low complexity
feehi CWE-74
6.1
2022-09-09 CVE-2022-34165 Injection vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.9 are vulnerable to HTTP header injection, caused by improper validation.
network
low complexity
ibm CWE-74
5.4
2022-09-07 CVE-2022-37108 Injection vulnerability in Securonix Snypr 6.4
An injection vulnerability in the syslog-ng configuration wizard in Securonix Snypr 6.4 allows an application user with the "Manage Ingesters" permission to execute arbitrary code on remote ingesters by appending arbitrary text to text files that are executed by the system, such as users' crontab files.
network
low complexity
securonix CWE-74
7.2
2022-08-25 CVE-2022-37240 Injection vulnerability in Altn Security Gateway for Email Servers 8.5.2
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.
network
low complexity
altn CWE-74
critical
9.8
2022-08-25 CVE-2022-37242 Injection vulnerability in Altn Security Gateway for Email Servers 8.5.2
MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.
network
low complexity
altn CWE-74
critical
9.8
2022-08-22 CVE-2022-34773 Injection vulnerability in Tabit
Tabit - HTTP Method manipulation.
network
low complexity
tabit CWE-74
critical
9.8
2022-08-18 CVE-2022-32453 Injection vulnerability in Cybozu Office
HTTP header injection vulnerability in Cybozu Office 10.0.0 to 10.8.5 may allow a remote attacker to obtain and/or alter the data of the product via unspecified vectors.
network
low complexity
cybozu CWE-74
6.5