Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-05-04 | CVE-2021-31164 | Injection vulnerability in Apache Unomi Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements. | 7.5 |
2021-04-28 | CVE-2021-22331 | Injection vulnerability in Huawei P30 Firmware There is a JavaScript injection vulnerability in certain Huawei smartphones. | 7.5 |
2021-04-27 | CVE-2019-25031 | Injection vulnerability in multiple products Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. | 5.9 |
2021-04-22 | CVE-2021-0268 | Injection vulnerability in Juniper Junos An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buffer overflows, segment faults, or other impacts, which allows an attacker to modify the integrity of the device and exfiltration information from the device without authentication. | 9.3 |
2021-04-20 | CVE-2021-28829 | Injection vulnerability in Tibco Administrator The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition for z/Linux, and TIBCO Administrator - Enterprise Edition for z/Linux contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a persistent CSV injection attack from the affected system. | 8.0 |
2021-04-15 | CVE-2021-31402 | Injection vulnerability in Flutterchina DIO 4.0.0 The dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. | 7.5 |
2021-04-14 | CVE-2021-27182 | Injection vulnerability in Altn Mdaemon An issue was discovered in MDaemon before 20.0.4. | 8.8 |
2021-04-14 | CVE-2021-22879 | Injection vulnerability in multiple products Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. | 8.8 |
2021-04-06 | CVE-2020-36308 | Injection vulnerability in multiple products Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries. | 5.3 |
2021-04-05 | CVE-2021-30057 | Injection vulnerability in ENG Knowage A stored HTML injection vulnerability exists in Knowage Suite version 7.1. | 4.8 |