Vulnerabilities (CVE)

Filtered by CWE-89
Total 17787 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-11470 1 Idera 1 Uptime Infrastructure Monitor 2025-04-20 7.5 HIGH 9.8 CRITICAL
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the element parameter.
CVE-2016-1914 1 Blackberry 1 Blackberry Enterprise Service 2025-04-20 6.8 MEDIUM 8.8 HIGH
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevice/client/image, (2) admin/client/image, (3) myapps/client/image, (4) ssam/client/image, or (5) all/client/image.
CVE-2017-17829 1 Doditsolutions 1 Bus Booking Script 2025-04-20 6.5 MEDIUM 7.2 HIGH
Bus Booking Script has SQL Injection via the admin/view_seatseller.php sp_id parameter or the admin/view_member.php memid parameter.
CVE-2017-5154 1 Advantech 1 Webaccess 2025-04-20 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Advantech WebAccess Version 8.1. To be able to exploit the SQL injection vulnerability, an attacker must supply malformed input to the WebAccess software. Successful attack could result in administrative access to the application and its data files.
CVE-2017-8789 1 Accellion 1 File Transfer Appliance 2025-04-20 7.5 HIGH 9.8 CRITICAL
An issue was discovered on Accellion FTA devices before FTA_9_12_180. A report_error.php?year='payload SQL injection vector exists.
CVE-2017-17631 1 Multireligion Responsive Matrimonial Project 1 Multireligion Responsive Matrimonial 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
CVE-2017-16893 1 Piwigo 1 Piwigo 2025-04-20 4.0 MEDIUM 6.5 MEDIUM
The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database. tags.php is affected: values of the edit_list parameters are not sanitized; these are used to construct an SQL query and retrieve a list of registered users into the application.
CVE-2017-15983 1 Geniusocean 1 Mymagazine Magazine \& Blog Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
CVE-2016-10379 1 Virtuemart 1 Virtuemart 2025-04-20 6.5 MEDIUM 7.2 HIGH
The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmethod_id parameter to administrator/index.php.
CVE-2015-4669 1 Xceedium 1 Xsuite 2025-04-20 7.2 HIGH 7.8 HIGH
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.
CVE-2015-3313 1 Community Events Project 1 Community Events 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in WordPress Community Events plugin before 1.4.
CVE-2017-17602 1 Advance B2b Script Project 1 Advance B2b Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.
CVE-2016-7508 1 Glpi-project 1 Glpi 2025-04-20 6.0 MEDIUM 7.5 HIGH
Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a certain character when the database is configured to use Big5 Asian encoding.
CVE-2016-8928 1 Ibm 1 Kenexa Lms 2025-04-20 6.5 MEDIUM 7.6 HIGH
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2017-14843 1 Dasinfomedia 1 School Management System 2025-04-20 6.5 MEDIUM 8.8 HIGH
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
CVE-2017-17871 1 Jextn 1 Jextn Question And Answer 2025-04-20 7.5 HIGH 9.8 CRITICAL
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.
CVE-2017-6574 1 Mail-masta Project 1 Mail-masta 2025-04-20 6.5 MEDIUM 7.2 HIGH
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: filter_list.
CVE-2017-1269 1 Ibm 1 Security Guardium 2025-04-20 7.5 HIGH 9.8 CRITICAL
IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 124744
CVE-2017-2241 2 Apple, Hammock 2 Mac Os X, Assetview 2025-04-20 6.5 MEDIUM 6.3 MEDIUM
SQL injection vulnerability in the AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to execute arbitrary SQL commands via "File Transfer Web Service".
CVE-2015-5533 1 Count Per Day Project 1 Count Per Day 2025-04-20 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.