Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-03-11 CVE-2021-21381 Injection vulnerability in multiple products
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.
local
low complexity
flatpak debian fedoraproject CWE-74
8.2
2021-03-08 CVE-2021-21510 Injection vulnerability in Dell Idrac8 Firmware
Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability.
network
low complexity
dell CWE-74
6.1
2021-03-03 CVE-2021-21353 Injection vulnerability in Pugjs PUG
Pug is an npm package which is a high-performance template engine.
network
high complexity
pugjs CWE-74
critical
9.0
2021-03-02 CVE-2021-27730 Injection vulnerability in Accellion FTA
Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint.
network
low complexity
accellion CWE-74
critical
9.8
2021-02-27 CVE-2021-27132 Injection vulnerability in Sercomm Agcombo Vd625 Firmware Agsot2.1.0
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
network
low complexity
sercomm CWE-74
critical
9.8
2021-02-27 CVE-2021-3197 Injection vulnerability in multiple products
An issue was discovered in SaltStack Salt before 3002.5.
network
low complexity
saltstack fedoraproject debian CWE-74
critical
9.8
2021-02-22 CVE-2021-26068 Injection vulnerability in Atlassian Jira Server for Slack
An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via a template injection vulnerability.
network
low complexity
atlassian CWE-74
8.8
2021-02-19 CVE-2020-12873 Injection vulnerability in Atlassian Alfresco Enterprise Content Management
An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1.
network
low complexity
atlassian CWE-74
8.8
2021-02-16 CVE-2021-21316 Injection vulnerability in Less-Openui5 Project Less-Openui5
less-openui5 is an npm package which enables building OpenUI5 themes with Less.js.
local
low complexity
less-openui5-project CWE-74
7.8
2021-02-16 CVE-2020-35564 Injection vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2.
network
low complexity
mbconnectline CWE-74
7.5