Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-03-23 CVE-2021-27908 Injection vulnerability in Acquia Mautic
In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in Mautic’s configuration that are used in publicly facing parts of the application.
local
low complexity
acquia CWE-74
4.4
2021-03-22 CVE-2021-28963 Injection vulnerability in multiple products
Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
network
low complexity
shibboleth debian CWE-74
5.3
2021-03-22 CVE-2021-26069 Injection vulnerability in Atlassian products
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project keys via an Information Disclosure vulnerability in the /rest/api/1.0/issues/{id}/ActionsAndOperations API endpoint.
network
low complexity
atlassian CWE-74
5.3
2021-03-18 CVE-2020-36144 Injection vulnerability in Redash 8.0.0
Redash 8.0.0 is affected by LDAP Injection.
network
low complexity
redash CWE-74
5.3
2021-03-16 CVE-2020-4851 Injection vulnerability in IBM Spectrum Scale
IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which could impact support and development efforts.
local
low complexity
ibm CWE-74
5.5
2021-03-15 CVE-2021-22191 Injection vulnerability in multiple products
Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file.
network
low complexity
wireshark oracle debian CWE-74
8.8
2021-03-08 CVE-2021-21510 Injection vulnerability in Dell Idrac8 Firmware
Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability.
network
low complexity
dell CWE-74
6.1
2021-03-02 CVE-2021-27730 Injection vulnerability in Accellion FTA
Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint.
network
low complexity
accellion CWE-74
critical
9.8
2021-02-27 CVE-2021-27132 Injection vulnerability in Sercomm Agcombo Vd625 Firmware Agsot2.1.0
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
network
low complexity
sercomm CWE-74
critical
9.8
2021-02-27 CVE-2021-3197 Injection vulnerability in multiple products
An issue was discovered in SaltStack Salt before 3002.5.
network
low complexity
saltstack fedoraproject debian CWE-74
critical
9.8