Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-01-27 CVE-2012-1496 Injection vulnerability in Webcalendar Project Webcalendar
Local file inclusion in WebCalendar before 1.2.5.
network
low complexity
webcalendar-project CWE-74
8.8
2020-01-27 CVE-2012-1495 Injection vulnerability in Webcalendar Project Webcalendar
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user_login parameter.
network
low complexity
webcalendar-project CWE-74
critical
9.8
2020-01-27 CVE-2011-4558 Injection vulnerability in Tiki
Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.
network
low complexity
tiki CWE-74
7.2
2020-01-24 CVE-2014-4172 Injection vulnerability in multiple products
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.
network
low complexity
apereo debian fedoraproject CWE-74
critical
9.8
2020-01-24 CVE-2020-5219 Injection vulnerability in Peerigon Angular-Expressions
Angular Expressions before version 1.0.1 has a remote code execution vulnerability if you call expressions.compile(userControlledInput) where userControlledInput is text that comes from user input.
network
low complexity
peerigon CWE-74
8.8
2020-01-23 CVE-2020-5217 Injection vulnerability in Twitter Secure Headers
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1.0, and 6.2.0.
network
low complexity
twitter CWE-74
5.8
2020-01-23 CVE-2020-5216 Injection vulnerability in Twitter Secure Headers
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0.
network
low complexity
twitter CWE-74
5.8
2020-01-15 CVE-2019-16468 Injection vulnerability in Adobe Experience Manager
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability.
network
low complexity
adobe CWE-74
7.5
2020-01-15 CVE-2012-0070 Injection vulnerability in Spamdyke
spamdyke prior to 4.2.1: STARTTLS reveals plaintext
network
low complexity
spamdyke CWE-74
7.5
2020-01-14 CVE-2014-7844 Injection vulnerability in multiple products
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
local
low complexity
redhat debian bsd-mailx-project CWE-74
7.8