Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-05-04 CVE-2021-31164 Injection vulnerability in Apache Unomi
Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.
network
low complexity
apache CWE-74
7.5
2021-04-28 CVE-2021-22331 Injection vulnerability in Huawei P30 Firmware
There is a JavaScript injection vulnerability in certain Huawei smartphones.
network
low complexity
huawei CWE-74
7.5
2021-04-27 CVE-2019-25031 Injection vulnerability in multiple products
Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session.
network
high complexity
nlnetlabs debian CWE-74
5.9
2021-04-22 CVE-2021-0268 Injection vulnerability in Juniper Junos
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buffer overflows, segment faults, or other impacts, which allows an attacker to modify the integrity of the device and exfiltration information from the device without authentication.
network
low complexity
juniper CWE-74
critical
9.3
2021-04-20 CVE-2021-28829 Injection vulnerability in Tibco Administrator
The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition for z/Linux, and TIBCO Administrator - Enterprise Edition for z/Linux contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a persistent CSV injection attack from the affected system.
network
low complexity
tibco CWE-74
8.0
2021-04-15 CVE-2021-31402 Injection vulnerability in Flutterchina DIO 4.0.0
The dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.
network
low complexity
flutterchina CWE-74
7.5
2021-04-14 CVE-2021-27182 Injection vulnerability in Altn Mdaemon
An issue was discovered in MDaemon before 20.0.4.
network
low complexity
altn CWE-74
8.8
2021-04-14 CVE-2021-22879 Injection vulnerability in multiple products
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands.
network
low complexity
nextcloud fedoraproject CWE-74
8.8
2021-04-06 CVE-2020-36308 Injection vulnerability in multiple products
Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.
network
low complexity
redmine debian CWE-74
5.3
2021-04-05 CVE-2021-30057 Injection vulnerability in ENG Knowage
A stored HTML injection vulnerability exists in Knowage Suite version 7.1.
network
low complexity
eng CWE-74
4.8