Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-04-10 CVE-2020-11002 Injection vulnerability in Dropwizard Validation
dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability.
network
low complexity
dropwizard CWE-74
critical
9.0
2020-04-08 CVE-2018-21051 Injection vulnerability in Google Android
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software.
network
low complexity
google CWE-74
critical
10.0
2020-04-07 CVE-2017-18652 Injection vulnerability in Google Android
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software.
network
low complexity
google CWE-74
7.5
2020-04-07 CVE-2020-7613 Injection vulnerability in Clamscan Project Clamscan
clamscan through 1.2.0 is vulnerable to Command Injection.
6.8
2020-04-06 CVE-2020-11593 Injection vulnerability in Cipplanner Cipace 6.80
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801.
network
low complexity
cipplanner CWE-74
5.0
2020-04-06 CVE-2020-7636 Injection vulnerability in Adb-Driver Project Adb-Driver
adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function.
network
low complexity
adb-driver-project CWE-74
7.5
2020-04-06 CVE-2020-7635 Injection vulnerability in Compass-Compile Project Compass-Compile 0.0.1
compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.
network
low complexity
compass-compile-project CWE-74
7.5
2020-04-06 CVE-2020-7634 Injection vulnerability in Heroku-Addonpool Project Heroku-Addonpool
heroku-addonpool through 0.1.15 is vulnerable to Command Injection.
network
low complexity
heroku-addonpool-project CWE-74
7.5
2020-04-06 CVE-2020-7633 Injection vulnerability in Apiconnect-Cli-Plugins Project Apiconnect-Cli-Plugins
apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.
network
low complexity
apiconnect-cli-plugins-project CWE-74
7.5
2020-04-06 CVE-2020-7632 Injection vulnerability in Node-Mpv Project Node-Mpv
node-mpv through 1.4.3 is vulnerable to Command Injection.
network
low complexity
node-mpv-project CWE-74
7.5