CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,829 vulnerabilities with CWE-74
CVE-2021-21372
HIGH
Nim < 1.2.10 - Remote Code Execution via Nimble doCmd Command Injection
CVSS 8.3
CVE-2021-21333
MEDIUM
Synapse < 1.27.0 - HTML Injection in Notification Emails
CVSS 6.1
CVE-2021-3027
MEDIUM
LibrIT PaSSHport <2.5 - Info Disclosure
CVSS 6.5
CVE-2021-29156
HIGH
ForgeRock OpenAM < 13.5.1 - Unauthenticated LDAP Injection via Webfinger Protocol
CVSS 7.5
CVE-2021-1432
HIGH
Cisco IOS XE SD-WAN - Authenticated Command Injection via CLI
CVSS 7.3
CVE-2021-27908
MEDIUM
Mautic < 3.3.2 - Authenticated Information Disclosure via Symfony Parameter Injection
CVSS 5.8
CVE-2021-28963
MEDIUM
Shibboleth Service Provider < 3.2.1 - Content Injection via Template Parameter
CVSS 5.3
CVE-2021-26069
MEDIUM
Atlassian Jira Server/Data Center <8.5.11, 8.6.0-8.13.2, 8.14.0-8.14.9 - Unauthenticated Info Disclosure via API
CVSS 5.3
CVE-2021-24144
HIGH
Contact Form 7 Database Addon <1.2.5.6 - Code Injection
CVSS 7.8
CVE-2021-22191
MEDIUM
Wireshark 3.2.0-3.2.11 and 3.4.0-3.4.3 - Remote Code Execution via Packet Injection or Crafted Capture File
CVSS 6.3
CVE-2021-21381
HIGH
Flatpak 0.9.4-1.10.1 - Unauthenticated Arbitrary File Access via Desktop File Token Injection
CVSS 7.1
CVE-2021-21510
MEDIUM
Dell iDRAC8 < 2.75.100.75 - Unauthenticated Host Header Injection
CVSS 6.1
CVE-2021-21313
MEDIUM
GLPI < 9.5.4 - Cross-Site Scripting via _target Parameter in common.tabs.php
CVSS 4.9
CVE-2021-21353
MEDIUM
pug < 3.0.1 - Remote Code Execution via Pretty Option Injection
CVSS 6.8
CVE-2021-27730
CRITICAL
Accellion FTA <9_12_444 - Command Injection
CVSS 9.8
CVE-2021-27132
CRITICAL
SerComm AG Combo VD625 AGSOT_2.1.0 - HTTP Header Injection via Content-Disposition Header
CVSS 9.8
CVE-2021-3197
CRITICAL
Salt < 2015.8.10 - Injection
CVSS 9.8
CVE-2021-26068
HIGH
Atlassian Jira Server for Slack 0.0.3-2.0.14 - Remote Code Execution via Template Injection
CVSS 8.8
CVE-2021-21316
MEDIUM
less-openui5 < 0.10.0 - Remote Code Execution via Inline JavaScript in Less Files
CVSS 6.3
CVE-2021-20644
MEDIUM
ELECOM WRC-1467GHBK-A Firmware - Stored Cross-Site Scripting via SSID Display
CVSS 6.1
CVE-2021-23335
HIGH
Package is-user-valid - LDAP Injection
CVSS 7.5
CVE-2021-21479
CRITICAL
SAP SCIMono < 0.0.19 - Remote Code Execution via Java Expression Injection
CVSS 9.1
CVE-2021-21141
MEDIUM
Google Chrome <88.0.4324.96 - Info Disclosure
CVSS 6.5
CVE-2021-21137
MEDIUM
Google Chrome <88.0.4324.96 - Info Disclosure
CVSS 6.5
CVE-2021-21305
HIGH
CarrierWave <2.1.1 - Code Injection
CVSS 7.4
Details
Vulnerabilities
4,829
Exploit Likelihood
High