Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-06-22 | CVE-2021-20736 | Injection vulnerability in Weseek Growi NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors. | 9.1 |
2021-06-21 | CVE-2018-25016 | Injection vulnerability in Greenbone OS and Greenbone Security Assistant Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection. | 9.8 |
2021-06-16 | CVE-2021-29702 | Injection vulnerability in IBM DB2 Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. | 7.5 |
2021-06-16 | CVE-2021-28979 | Injection vulnerability in Thalesgroup Safenet Keysecure 8.12.0 SafeNet KeySecure Management Console 8.12.0 is vulnerable to HTTP response splitting attacks. | 6.5 |
2021-06-11 | CVE-2021-25682 | Injection vulnerability in Canonical Apport It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel. | 7.8 |
2021-06-09 | CVE-2021-33668 | Injection vulnerability in SAP Infrabox Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. | 7.5 |
2021-06-07 | CVE-2021-30540 | Injection vulnerability in multiple products Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafted HTML page. | 6.5 |
2021-06-04 | CVE-2021-31249 | Injection vulnerability in Chiyu-Tech Bf-430 Firmware, Bf-431 Firmware and Bf-450M Firmware A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validation on the parameter redirect= available on multiple CGI components. | 6.5 |
2021-06-04 | CVE-2021-30506 | Injection vulnerability in multiple products Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who convinced a user to install a web application to inject scripts or HTML into a privileged page via a crafted HTML page. | 8.8 |
2021-05-28 | CVE-2021-32642 | Injection vulnerability in multiple products radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. | 9.4 |