Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-12-18 CVE-2020-27687 Injection vulnerability in Thingsboard
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails.
network
low complexity
thingsboard CWE-74
8.8
2020-12-14 CVE-2020-8177 Injection vulnerability in multiple products
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.
local
low complexity
haxx debian fujitsu siemens splunk CWE-74
7.8
2020-12-10 CVE-2020-25967 Injection vulnerability in Fastadmin 1.0.0.20200506
The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerability.
network
low complexity
fastadmin CWE-74
8.8
2020-12-09 CVE-2020-26260 Injection vulnerability in Bookstackapp Bookstack
BookStack is a platform for storing and organising information and documentation.
network
low complexity
bookstackapp CWE-74
6.4
2020-12-09 CVE-2020-29655 Injection vulnerability in Asus Rt-Ac88U Firmware 3.0.0.4.386.46061
An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108.
network
low complexity
asus CWE-74
7.5
2020-11-30 CVE-2020-14193 Injection vulnerability in Atlassian Automation for Jira
Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF/classes & <jira-installation>/jira/bin directories via a template injection vulnerability in Jira smart values using mustache partials.
network
low complexity
atlassian CWE-74
5.4
2020-11-24 CVE-2020-13942 Injection vulnerability in Apache Unomi 1.5.0/1.5.1
It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint.
network
low complexity
apache CWE-74
critical
9.8
2020-11-18 CVE-2020-26081 Injection vulnerability in Cisco IOT Field Network Director
Multiple vulnerabilities in the web UI of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users on an affected system.
network
low complexity
cisco CWE-74
6.1
2020-11-18 CVE-2020-26884 Injection vulnerability in RSA Archer
RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability.
network
low complexity
rsa CWE-74
6.1
2020-11-16 CVE-2020-27627 Injection vulnerability in Jetbrains Teamcity
JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.
network
low complexity
jetbrains CWE-74
6.1