Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-07-06 CVE-2022-31126 Injection vulnerability in Roxy-Wi
Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers.
network
low complexity
roxy-wi CWE-74
critical
9.8
2022-07-05 CVE-2022-31014 Injection vulnerability in Nextcloud Server
Nextcloud server is an open source personal cloud server.
network
low complexity
nextcloud CWE-74
3.5
2022-07-01 CVE-2022-34903 Injection vulnerability in multiple products
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
network
high complexity
gnupg fedoraproject debian netapp CWE-74
6.5
2022-06-30 CVE-2013-4144 Injection vulnerability in Swfupload Project Swfupload 3.5.2
There is an object injection vulnerability in swfupload plugin for wordpress.
network
low complexity
swfupload-project CWE-74
critical
9.8
2022-06-27 CVE-2022-31088 Injection vulnerability in multiple products
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g.
network
low complexity
ldap-account-manager debian CWE-74
5.3
2022-06-06 CVE-2022-29631 Injection vulnerability in Jodd Http
Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send.
network
low complexity
jodd CWE-74
7.5
2022-06-02 CVE-2020-28246 Injection vulnerability in Form Form.Io 2.0.0
A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0.
network
low complexity
form CWE-74
critical
9.8
2022-05-11 CVE-2022-22975 Injection vulnerability in VMWare Pinniped
An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider resources.
network
high complexity
vmware CWE-74
6.6
2022-05-05 CVE-2022-29166 Injection vulnerability in Matrix IRC Bridge
matrix-appservice-irc is a Node.js IRC bridge for Matrix.
network
low complexity
matrix CWE-74
8.8
2022-05-02 CVE-2022-23064 Injection vulnerability in Snipeitapp Snipe-It
In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection.
network
low complexity
snipeitapp CWE-74
8.8