CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,829 vulnerabilities with CWE-74
CVE-2021-21303
MEDIUM
Helm 3.0.0-3.5.1 - Terminal Injection via Unsanitized Chart and Repository Metadata
CVSS 5.9
CVE-2021-1221
MEDIUM
Cisco Webex Meetings <41.1.0 & Webex Meetings Server <3.0 - Authenticated Hyperlink Injection
CVSS 4.1
CVE-2021-21277
HIGH
angular-expressions < 1.1.2 - Remote Code Execution via Constructor Bypass
CVSS 8.5
CVE-2021-21278
HIGH
RSSHub < 2021-01-25 - Remote Code Execution via Unsafe Eval in Route Handlers
CVSS 8.6
CVE-2021-21263
HIGH
Laravel <6.20.11, 7.30.2, 8.22.1 - SQL Injection
CVSS 7.2
CVE-2021-21249
CRITICAL
OneDev < 4.0.3 - Authenticated Remote Code Execution via SnakeYAML Deserialization
CVSS 9.6
CVE-2021-21248
CRITICAL
OneDev < 4.0.3 - Remote Code Execution via Build Endpoint Parameter Injection
CVSS 9.6
CVE-2021-21247
CRITICAL
OneDev < 4.0.3 - Authenticated Remote Code Execution via AJAX Event Listener Deserialization
CVSS 9.6
CVE-2021-21242
CRITICAL
OneDev < 4.0.3 - Unauthenticated Remote Code Execution via Attachment-Support Header Deserialization
CVSS 10.0
CVE-2021-21244
CRITICAL
OneDev <4.0.3 - Server Side Template Injection
CVSS 10.0
CVE-2021-21243
CRITICAL
OneDev <4.0.3 - Pre-Auth Code Injection
CVSS 10.0
CVE-2021-21261
HIGH
flatpak 0.11.4-1.8.4 - Sandbox Escape via Environment Variable Injection in flatpak-portal
CVSS 7.3
CVE-2020-28848
HIGH
ChurchCRM 4.2.0 - CSV Injection via Crafted File
CVSS 8.8
CVE-2020-24275
MEDIUM
Swoole 4.5.2 - HTTP Response Header Injection via Crafted URL
CVSS 6.5
CVE-2020-36618
MEDIUM
Furqan node-whois - Prototype Pollution
CVSS 6.3
CVE-2020-27602
CRITICAL
BigBlueButton <2.2.7 - Command Injection
CVSS 9.8
CVE-2020-36531
MEDIUM
SevOne Network Performance Management 5.7.2.0-5.7.2.22 - Privilege Escalation via Device Manager Page Injection
CVSS 6.3
CVE-2020-28246
CRITICAL
Form.io 2.0.0 - Authenticated Server-Side Template Injection via Email Template Deletion
CVSS 9.8
CVE-2020-12965
HIGH
AMD Ryzen PRO Firmware - Data Leakage via Non-Canonical Address Handling
CVSS 7.5
CVE-2020-35213
HIGH
Atomix 3.1.5 - Denial of Service via False Link Event Messages
CVSS 8.1
CVE-2020-23050
HIGH
TAO Open Source Assessment Platform <3.3.0 RC02 - XSS
CVSS 8.0
CVE-2020-18875
HIGH
dotcms < 5.1.0 - Remote Privilege Escalation via VTL File Client Configuration Injection
CVSS 8.8
CVE-2020-23148
HIGH
rconfig 3.9.5 - LDAP Injection via userLogin Parameter
CVSS 7.5
CVE-2020-24826
MEDIUM
Libelfin v0.3 - Denial of Service via Crafted ELF File in elf::section::as_strtab
CVSS 5.5
CVE-2020-24825
MEDIUM
libelfin v0.3 - Denial of Service via Crafted ELF File
CVSS 5.5
Details
Vulnerabilities
4,829
Exploit Likelihood
High