CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,829 vulnerabilities with CWE-74
CVE-2021-21580 MEDIUM
Dell EMC iDRAC8 < 2.80.80.80 and iDRAC9 < 5.00.00.00 - Content Spoofing via URL Injection
CVSS 4.3
CVE-2021-35450 HIGH
Entando Admin Console <6.3.9 - SSRF
CVSS 7.2
CVE-2021-33195 HIGH
Go <1.15.13-1.16.5 - Info Disclosure
CVSS 7.3
CVE-2021-32558 HIGH
Asterisk DoS via IAX2 Unsupported Media Format Packet
CVSS 7.5
CVE-2021-3169 CRITICAL
Jumpserver < 2.4.5 - Unauthenticated Connection Token Generation and Asset Access
CVSS 9.8
CVE-2021-32756 HIGH
ManageIQ <jansa-4,kasparov-2,lasker-1 - RCE
CVSS 8.8
CVE-2021-0594 HIGH
Android - Remote Privilege Escalation via Bluetooth ConfirmConnectActivity Input Validation Bypass
CVSS 8.0
CVE-2021-36381 MEDIUM
Edifecs Transaction Management - XSS
CVSS 5.3
CVE-2021-22232 LOW
GitLab 9.5.0-13.11.5 - HTML Injection via Full Name Field
CVSS 3.5
CVE-2021-20101 MEDIUM
Machform < 16 - HTTP Host Header Injection
CVSS 6.1
CVE-2021-23400 MEDIUM
nodemailer < 6.6.1 - HTTP Header Injection via Address Object
CVSS 6.3
CVE-2021-20574 HIGH
IBM Security Identity Manager Adapters <7.0 - Command Injection
CVSS 8.8
CVE-2021-29676 MEDIUM
IBM Security Verify < 10.9.66 - Link Injection via Crafted URL
CVSS 5.4
CVE-2021-29955 MEDIUM
Firefox < 87.0 and Firefox ESR < 78.9 - Memory Address Leak via Floating Point Value Injection
CVSS 5.3
CVE-2021-24002 HIGH
Firefox < 88.0 and Firefox ESR < 78.10 - Command Injection via FTP URL Newline Encoding
CVSS 8.8
CVE-2021-29085 HIGH
Synology DiskStation Manager 6.2-6.2.3-25426-3 - Arbitrary File Read via File Sharing Management Component
CVSS 8.6
CVE-2021-29084 HIGH
Synology DSM <6.2.3-25426-3 & DSM UC <3.1-23033 Arbitrary File Read
CVSS 7.5
CVE-2021-0553 HIGH
Android 11 - Local Privilege Escalation via AppSwitchPreference UI Bypass
CVSS 7.3
CVE-2021-0551 MEDIUM
Android 11 - Denial of Service via Malicious Media File in MediaControlPanel
CVSS 6.5
CVE-2021-0567 HIGH
Android - Local Privilege Escalation via Font File Injection in RemoteViews
CVSS 7.8
CVE-2021-20736 CRITICAL
GROWI < 4.2.20 - NoSQL Injection
CVSS 9.1
CVE-2021-29702 HIGH
IBM Db2 11.1-11.1.4 - Denial of Service via Crafted SELECT Statement
CVSS 7.5
CVE-2021-28979 MEDIUM
SafeNet KeySecure < 8.12.0 - HTTP Response Splitting via Crafted URL
CVSS 6.5
CVE-2021-25682 HIGH
Apport 2.20.1-0ubuntu1-2.20.1-0ubuntu2.30 - Information Disclosure via /proc/pid/status Parsing
CVSS 8.8
CVE-2021-33668 HIGH
SAP InfraBox < 1.2.1 - Unauthenticated LDAP Injection
CVSS 7.5
Details
Vulnerabilities 4,829
Exploit Likelihood High