Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-02-07 CVE-2010-4658 Injection vulnerability in Status Statusnet 2010
statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.
network
low complexity
status CWE-74
5.3
2020-02-07 CVE-2013-3628 Injection vulnerability in Zabbix 2.0.9
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
network
low complexity
zabbix CWE-74
8.8
2020-02-04 CVE-2019-15616 Injection vulnerability in Nextcloud Server
Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.
network
low complexity
nextcloud CWE-74
4.3
2020-02-04 CVE-2013-2678 Injection vulnerability in Cisco Linksys E4200 Firmware 1.0.05
Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type parameter.
network
high complexity
cisco CWE-74
8.1
2020-01-30 CVE-2020-5230 Injection vulnerability in Apereo Opencast
Opencast before 8.1 and 7.6 allows almost arbitrary identifiers for media packages and elements to be used.
network
low complexity
apereo CWE-74
7.5
2020-01-30 CVE-2020-8093 Injection vulnerability in Bitdefender Antivirus
A vulnerability in the AntivirusforMac binary as used in Bitdefender Antivirus for Mac allows an attacker to inject a library using DYLD environment variable to cause third-party code execution
local
low complexity
bitdefender CWE-74
7.8
2020-01-28 CVE-2013-3214 Injection vulnerability in Vtiger CRM
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
network
low complexity
vtiger CWE-74
critical
9.8
2020-01-28 CVE-2013-3212 Injection vulnerability in Vtiger CRM
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.
network
high complexity
vtiger CWE-74
8.1
2020-01-28 CVE-2013-1437 Injection vulnerability in multiple products
Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.
network
low complexity
module-metadata-project fedoraproject CWE-74
critical
9.8
2020-01-27 CVE-2015-3154 Injection vulnerability in Zend Framework
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
network
low complexity
zend CWE-74
6.1