CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,818 vulnerabilities with CWE-74
CVE-2021-41392
CRITICAL
Boostnote < 0.22.0 - Injection
CVSS 9.8
CVE-2021-41390
HIGH
Ericsson Enterprise Content Management < 18.0 - CSV Injection via Security Provider Endpoint
CVSS 8.0
CVE-2021-41314
HIGH
NETGEAR Smart Switches - Unauthenticated Admin Session Crafting via Web UI Password Field Injection
CVSS 8.8
CVE-2021-39213
MEDIUM
GLPI 9.1-9.5.5 - API Bypass via Custom Header Injection
CVSS 6.8
CVE-2021-30777
HIGH
macOS 10.14-10.14.4 and 11.0-11.4 - Privilege Escalation via Injection
CVSS 7.8
CVE-2021-40143
HIGH
Sonatype Nexus Repository Manager 3 3.0.0-3.33.1-01 - HTTP Header Injection
CVSS 8.2
CVE-2021-39187
HIGH
parse-server < 4.10.3 - Denial of Service via Invalid Explain Query Option
CVSS 7.5
CVE-2021-39175
HIGH
HedgeDoc < 1.9.0 - Unauthenticated Cross-Site Scripting via Slide Mode Speaker Notes
CVSS 8.1
CVE-2021-32827
MEDIUM
MockServer - Code Execution via Overbroad CORS and Script Injection
CVSS 6.1
CVE-2021-20509
CRITICAL
IBM Maximo Asset Mgmt <7.6.1 - Code Injection
CVSS 9.8
CVE-2021-38371
HIGH
Exim < 4.94.2 - Response Injection via STARTTLS Feature
CVSS 7.5
CVE-2021-38290
HIGH
FUEL CMS < 1.5.0 - Host Header Injection
CVSS 8.1
CVE-2021-37541
MEDIUM
JetBrains Hub < 2021.1.13402 - HTML Injection in Password Reset Email
CVSS 6.1
CVE-2021-38084
HIGH
Courier Mail Server <1.1.5 - Info Disclosure
CVSS 8.1
CVE-2021-21580
MEDIUM
Dell EMC iDRAC8 < 2.80.80.80 and iDRAC9 < 5.00.00.00 - Content Spoofing via URL Injection
CVSS 4.3
CVE-2021-35450
HIGH
Entando Admin Console <6.3.9 - SSRF
CVSS 7.2
CVE-2021-33195
HIGH
Go <1.15.13-1.16.5 - Info Disclosure
CVSS 7.3
CVE-2021-32558
HIGH
Asterisk DoS via IAX2 Unsupported Media Format Packet
CVSS 7.5
CVE-2021-3169
CRITICAL
Jumpserver < 2.4.5 - Unauthenticated Connection Token Generation and Asset Access
CVSS 9.8
CVE-2021-32756
HIGH
ManageIQ <jansa-4,kasparov-2,lasker-1 - RCE
CVSS 8.8
CVE-2021-0594
HIGH
Android - Remote Privilege Escalation via Bluetooth ConfirmConnectActivity Input Validation Bypass
CVSS 8.0
CVE-2021-36381
MEDIUM
Edifecs Transaction Management - XSS
CVSS 5.3
CVE-2021-22232
LOW
GitLab 9.5.0-13.11.5 - HTML Injection via Full Name Field
CVSS 3.5
CVE-2021-20101
MEDIUM
Machform < 16 - HTTP Host Header Injection
CVSS 6.1
CVE-2021-23400
MEDIUM
nodemailer < 6.6.1 - HTTP Header Injection via Address Object
CVSS 6.3
Details
Vulnerabilities
4,818
Exploit Likelihood
High