Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-06-11 CVE-2021-25682 Injection vulnerability in Canonical Apport
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.
local
low complexity
canonical CWE-74
7.8
2021-06-09 CVE-2021-33668 Injection vulnerability in SAP Infrabox
Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user.
network
low complexity
sap CWE-74
7.5
2021-06-07 CVE-2021-30540 Injection vulnerability in multiple products
Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
network
low complexity
google fedoraproject CWE-74
6.5
2021-06-04 CVE-2021-31249 Injection vulnerability in Chiyu-Tech Bf-430 Firmware, Bf-431 Firmware and Bf-450M Firmware
A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validation on the parameter redirect= available on multiple CGI components.
network
low complexity
chiyu-tech CWE-74
6.5
2021-06-04 CVE-2021-30506 Injection vulnerability in multiple products
Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who convinced a user to install a web application to inject scripts or HTML into a privileged page via a crafted HTML page.
network
low complexity
google fedoraproject CWE-74
8.8
2021-05-28 CVE-2021-32642 Injection vulnerability in multiple products
radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports.
network
low complexity
uninett fedoraproject CWE-74
critical
9.4
2021-05-25 CVE-2021-29208 Injection vulnerability in HP Integrated Lights-Out 4 and Integrated Lights-Out 5
A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s): Prior to version 2.78.
network
low complexity
hp CWE-74
4.8
2021-05-25 CVE-2021-29209 Injection vulnerability in HP Integrated Lights-Out 4 and Integrated Lights-Out 5
A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s): Prior to version 2.78.
network
low complexity
hp CWE-74
4.8
2021-05-25 CVE-2021-29210 Injection vulnerability in HP Integrated Lights-Out 4 and Integrated Lights-Out 5
A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s): Prior to version 2.78.
network
low complexity
hp CWE-74
4.8
2021-05-21 CVE-2020-27212 Injection vulnerability in ST Stm32Cubel4 Firmware
STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control.
local
high complexity
st CWE-74
7.0