Vulnerabilities > Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DATE CVE VULNERABILITY TITLE RISK
2017-09-20 CVE-2015-4075 Injection vulnerability in Helpdeskpro Helpdesk PRO 1.1.1/1.2.0/1.3.0
The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task.
network
high complexity
helpdeskpro CWE-74
8.1
2017-09-12 CVE-2017-14397 Injection vulnerability in Anydesk
AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability.
network
low complexity
anydesk CWE-74
critical
9.8
2017-08-29 CVE-2016-2980 Injection vulnerability in IBM Sametime
The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerability in the way that the WebPlayer works.
network
low complexity
ibm CWE-74
6.3
2017-08-05 CVE-2017-9861 Injection vulnerability in SMA products
An issue was discovered in SMA Solar Technology products.
network
low complexity
sma CWE-74
critical
9.8
2017-07-25 CVE-2017-6748 Injection vulnerability in Cisco products
A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root.
local
low complexity
cisco CWE-74
6.7
2017-07-18 CVE-2017-5246 Injection vulnerability in Biscom Secure File Transfer
Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field.
network
low complexity
biscom CWE-74
4.3
2017-07-17 CVE-2017-1000052 Injection vulnerability in Plug Project Plug
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions.
local
low complexity
plug-project CWE-74
7.8
2017-06-26 CVE-2017-7459 Injection vulnerability in Ntop Ntopng
ntopng before 3.0 allows HTTP Response Splitting.
network
low complexity
ntop CWE-74
7.5
2017-05-21 CVE-2017-9135 Injection vulnerability in Mimosa Backhaul Radios and Client Radios
An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4.
network
low complexity
mimosa CWE-74
8.8
2017-05-21 CVE-2017-9133 Injection vulnerability in Mimosa Backhaul Radios and Client Radios
An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3.
network
low complexity
mimosa CWE-74
8.8