Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-10-23 CVE-2019-11282 Injection vulnerability in multiple products
Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack.
network
low complexity
cloudfoundry pivotal-software CWE-74
4.3
2019-10-18 CVE-2019-17513 Injection vulnerability in Ratpack Project Ratpack
An issue was discovered in Ratpack before 1.7.5.
network
low complexity
ratpack-project CWE-74
7.5
2019-10-09 CVE-2019-9535 Injection vulnerability in Iterm2
A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by providing malicious output to the terminal.
network
low complexity
iterm2 CWE-74
critical
9.8
2019-10-09 CVE-2019-4558 Injection vulnerability in IBM Spectrum Scale
A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spectrum Scale V4.2.0.0 through V4.2.3.17 that could allow a local attacker to obtain root privilege by injecting parameters into setuid files.
local
low complexity
ibm CWE-74
7.8
2019-10-02 CVE-2019-15259 Injection vulnerability in Cisco Unified Contact Center Express
A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack.
network
low complexity
cisco CWE-74
6.1
2019-10-01 CVE-2019-17068 Injection vulnerability in multiple products
PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content.
network
low complexity
putty opensuse CWE-74
7.5
2019-09-26 CVE-2019-16532 Injection vulnerability in Yzmcms 5.3
An HTTP Host header injection vulnerability exists in YzmCMS V5.3.
network
low complexity
yzmcms CWE-74
6.1
2019-09-23 CVE-2019-11277 Injection vulnerability in Cloudfoundry Cf-Deployment and NFS Volume Release
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection.
network
low complexity
cloudfoundry CWE-74
8.1
2019-09-16 CVE-2017-18634 Injection vulnerability in Tagdiv Newspaper 6.7.0/6.7.1
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
network
low complexity
tagdiv CWE-74
critical
9.8
2019-09-13 CVE-2019-5314 Injection vulnerability in Arubanetworks Arubaos
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS.
network
low complexity
arubanetworks CWE-74
6.1