Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-11-16 CVE-2020-27627 Injection vulnerability in Jetbrains Teamcity
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
network
low complexity
jetbrains CWE-74
6.1
2020-11-13 CVE-2020-26222 Injection vulnerability in Dependabot Project Dependabot
Dependabot is a set of packages for automated dependency management for Ruby, JavaScript, Python, PHP, Elixir, Rust, Java, .NET, Elm and Go.
network
low complexity
dependabot-project CWE-74
8.8
2020-11-02 CVE-2020-28031 Injection vulnerability in Eramba 2.8.1
eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated users.
network
low complexity
eramba CWE-74
4.3
2020-10-21 CVE-2020-3561 Injection vulnerability in Cisco Firepower Threat Defense
A vulnerability in the Clientless SSL VPN (WebVPN) of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to inject arbitrary HTTP headers in the responses of the affected system.
network
low complexity
cisco CWE-74
4.7
2020-10-20 CVE-2020-7749 Injection vulnerability in Osm-Static-Maps Project Osm-Static-Maps
This affects all versions of package osm-static-maps.
network
low complexity
osm-static-maps-project CWE-74
7.6
2020-10-16 CVE-2020-15252 Injection vulnerability in Xwiki
In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet context which contains tools allowing to instantiate arbitrary Java objects and invoke methods that may lead to arbitrary code execution.
network
low complexity
xwiki CWE-74
8.8
2020-10-07 CVE-2020-25768 Injection vulnerability in Contao
Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation.
network
low complexity
contao CWE-74
5.3
2020-09-30 CVE-2020-26137 Injection vulnerability in multiple products
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest().
network
low complexity
python canonical debian oracle CWE-74
6.5
2020-09-30 CVE-2020-21523 Injection vulnerability in Halo 1.1.3
A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function.
network
low complexity
halo CWE-74
critical
9.8
2020-09-27 CVE-2020-26116 Injection vulnerability in multiple products
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
7.2