Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-06-22 CVE-2021-0551 Injection vulnerability in Google Android 11.0
In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation.
network
low complexity
google CWE-74
6.5
2021-06-22 CVE-2021-0553 Injection vulnerability in Google Android 11.0
In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI.
local
low complexity
google CWE-74
7.3
2021-06-22 CVE-2021-0567 Injection vulnerability in Google Android 11.0
In isRestricted of RemoteViews.java, there is a possible way to inject font files due to a permissions bypass.
local
low complexity
google CWE-74
7.8
2021-06-22 CVE-2021-20736 Injection vulnerability in Weseek Growi
NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors.
network
low complexity
weseek CWE-74
critical
9.1
2021-06-21 CVE-2018-25016 Injection vulnerability in Greenbone OS and Greenbone Security Assistant
Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.
network
low complexity
greenbone CWE-74
critical
9.8
2021-06-16 CVE-2021-29702 Injection vulnerability in IBM DB2
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement.
network
low complexity
ibm CWE-74
7.5
2021-06-16 CVE-2021-28979 Injection vulnerability in Thalesgroup Safenet Keysecure 8.12.0
SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks.
network
low complexity
thalesgroup CWE-74
6.5
2021-06-11 CVE-2021-25682 Injection vulnerability in Canonical Apport
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.
local
low complexity
canonical CWE-74
7.8
2021-06-09 CVE-2021-33668 Injection vulnerability in SAP Infrabox
Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user.
network
low complexity
sap CWE-74
7.5
2021-06-07 CVE-2021-30540 Injection vulnerability in multiple products
Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
network
low complexity
google fedoraproject CWE-74
6.5