Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-12-26 CVE-2021-45655 Injection vulnerability in Netgear R6400 Firmware
NETGEAR R6400 devices before 1.0.1.70 are affected by server-side injection.
low complexity
netgear CWE-74
6.8
2021-12-26 CVE-2021-45656 Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by server-side injection.
local
low complexity
netgear CWE-74
7.8
2021-12-26 CVE-2021-45657 Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by server-side injection.
local
low complexity
netgear CWE-74
7.8
2021-12-26 CVE-2021-45658 Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by server-side injection.
network
low complexity
netgear CWE-74
critical
9.8
2021-12-26 CVE-2021-45659 Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by server-side injection.
local
low complexity
netgear CWE-74
7.8
2021-12-26 CVE-2021-45660 Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by server-side injection.
local
low complexity
netgear CWE-74
7.8
2021-12-26 CVE-2021-45661 Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by server-side injection.
local
low complexity
netgear CWE-74
7.8
2021-12-20 CVE-2021-43437 Injection vulnerability in Engineers Online Portal Project Engineers Online Portal 1.0
In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the web application and cause the application to behave in unexpected ways.
network
low complexity
engineers-online-portal-project CWE-74
8.8
2021-12-17 CVE-2021-32499 Injection vulnerability in Sick Sopas Engineering Tool
SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the command line arguments to pass in any value to the Emulator executable.
network
low complexity
sick CWE-74
7.5
2021-12-16 CVE-2020-35213 Injection vulnerability in Atomix 3.1.5
An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node.
network
low complexity
atomix CWE-74
8.1