Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2018-03-06 CVE-2015-5377 Injection vulnerability in Elastic Elasticsearch
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol.
network
low complexity
elastic CWE-74
critical
9.8
2018-02-20 CVE-2017-10963 Injection vulnerability in Samsung products
In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's knowledge) by inspecting network traffic from a Samsung server and injecting content at a certain point in the update sequence.
network
high complexity
samsung CWE-74
5.9
2018-02-15 CVE-2017-5799 Injection vulnerability in HP Opencall Media Platform 3.0.0/4.0.0
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found.
network
low complexity
hp CWE-74
8.8
2018-02-14 CVE-2018-7032 Injection vulnerability in Myrepos Project Myrepos
webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for arbitrary code execution, as demonstrated by an "ext::sh -c" attack or an option injection attack.
network
high complexity
myrepos-project CWE-74
7.5
2018-02-07 CVE-2018-6603 Injection vulnerability in Promise Webpam Proe
Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injection attacks via JavaScript code in a PHPSESSID cookie.
network
low complexity
promise CWE-74
6.1
2018-02-06 CVE-2018-6289 Injection vulnerability in Kaspersky Secure Mail Gateway 1.1
Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
network
low complexity
kaspersky CWE-74
critical
9.8
2018-02-02 CVE-2018-6519 Injection vulnerability in multiple products
The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.
network
low complexity
simplesamlphp debian CWE-74
7.5
2018-01-26 CVE-2017-14523 Injection vulnerability in Wondercms 2.3.1
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack.
network
low complexity
wondercms CWE-74
7.5
2018-01-23 CVE-2017-18049 Injection vulnerability in Silverstripe
In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel).
local
low complexity
silverstripe CWE-74
5.5
2018-01-19 CVE-2017-14094 Injection vulnerability in Trendmicro Smart Protection Server
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a cron job injection on a vulnerable system.
network
low complexity
trendmicro CWE-74
critical
9.8