Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-05-11 CVE-2020-26142 Injection vulnerability in Openbsd 6.6
An issue was discovered in the kernel in OpenBSD 6.6.
network
high complexity
openbsd CWE-74
5.3
2021-05-11 CVE-2021-27614 Injection vulnerability in SAP Business-One-Hana-Chef-Cookbook and Business ONE
SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to inject code that can be executed by the application.
local
low complexity
sap CWE-74
7.1
2021-05-04 CVE-2021-3154 Injection vulnerability in Solarwinds Serv-U
An issue was discovered in SolarWinds Serv-U before 15.2.2.
network
low complexity
solarwinds CWE-74
7.5
2021-05-04 CVE-2021-31164 Injection vulnerability in Apache Unomi
Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.
network
low complexity
apache CWE-74
7.5
2021-04-28 CVE-2021-22331 Injection vulnerability in Huawei P30 Firmware
There is a JavaScript injection vulnerability in certain Huawei smartphones.
network
low complexity
huawei CWE-74
7.5
2021-04-27 CVE-2019-25031 Injection vulnerability in multiple products
Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session.
network
high complexity
nlnetlabs debian CWE-74
5.9
2021-04-22 CVE-2021-0268 Injection vulnerability in Juniper Junos
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buffer overflows, segment faults, or other impacts, which allows an attacker to modify the integrity of the device and exfiltration information from the device without authentication.
network
low complexity
juniper CWE-74
critical
9.3
2021-04-20 CVE-2021-28829 Injection vulnerability in Tibco Administrator
The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition for z/Linux, and TIBCO Administrator - Enterprise Edition for z/Linux contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a persistent CSV injection attack from the affected system.
network
low complexity
tibco CWE-74
8.0
2021-04-15 CVE-2021-31402 Injection vulnerability in Flutterchina DIO 4.0.0
The dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.
network
low complexity
flutterchina CWE-74
7.5
2021-04-14 CVE-2021-27182 Injection vulnerability in Altn Mdaemon
An issue was discovered in MDaemon before 20.0.4.
network
low complexity
altn CWE-74
8.8