Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-03-23 | CVE-2021-27908 | Injection vulnerability in Acquia Mautic In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an authorized admin user through leveraging Symfony parameter syntax in any of the free text fields in Mautic’s configuration that are used in publicly facing parts of the application. | 4.4 |
2021-03-22 | CVE-2021-28963 | Injection vulnerability in multiple products Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters. | 5.3 |
2021-03-22 | CVE-2021-26069 | Injection vulnerability in Atlassian products Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project keys via an Information Disclosure vulnerability in the /rest/api/1.0/issues/{id}/ActionsAndOperations API endpoint. | 5.3 |
2021-03-18 | CVE-2020-36144 | Injection vulnerability in Redash 8.0.0 Redash 8.0.0 is affected by LDAP Injection. | 5.3 |
2021-03-16 | CVE-2020-4851 | Injection vulnerability in IBM Spectrum Scale IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 could allow a local user to poison log files which could impact support and development efforts. | 5.5 |
2021-03-15 | CVE-2021-22191 | Injection vulnerability in multiple products Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file. | 8.8 |
2021-03-08 | CVE-2021-21510 | Injection vulnerability in Dell Idrac8 Firmware Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. | 6.1 |
2021-03-02 | CVE-2021-27730 | Injection vulnerability in Accellion FTA Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. | 9.8 |
2021-02-27 | CVE-2021-27132 | Injection vulnerability in Sercomm Agcombo Vd625 Firmware Agsot2.1.0 SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header. | 9.8 |
2021-02-27 | CVE-2021-3197 | Injection vulnerability in multiple products An issue was discovered in SaltStack Salt before 3002.5. | 9.8 |