Vulnerabilities (CVE)

Filtered by CWE-89
Total 17786 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-16851 1 Zohocorp 1 Manageengine Applications Manager 2025-04-20 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.
CVE-2016-7783 1 Exponentcms 1 Exponent Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in framework/core/models/expRecord.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.
CVE-2017-10898 1 Ark-web 1 A-member 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the A-Member and A-Member for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-17624 1 Php Multivendor Ecommerce Project 1 Php Multivendor Ecommerce 2025-04-20 7.5 HIGH 9.8 CRITICAL
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
CVE-2017-17640 1 Advanced World Database Project 1 Advanced World Database 2025-04-20 7.5 HIGH 9.8 CRITICAL
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.
CVE-2017-17594 1 Domainsale Php Script Project 1 Domainsale Php Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.
CVE-2017-3221 1 Inmarsat 1 Amosconnect 8 2025-04-20 5.0 MEDIUM 9.8 CRITICAL
Blind SQL injection in Inmarsat AmosConnect 8 login form allows remote attackers to access user credentials, including user names and passwords.
CVE-2017-1311 1 Ibm 1 Insights Foundation For Energy 2025-04-20 6.5 MEDIUM 8.8 HIGH
IBM Insights Foundation for Energy 2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 125719.
CVE-2017-15970 1 Phpcityportal 1 Phpcityportal 2025-04-20 7.5 HIGH 9.8 CRITICAL
PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.
CVE-2017-15976 1 Zeescripts 1 Zeebuddy 2025-04-20 7.5 HIGH 9.8 CRITICAL
ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604.
CVE-2017-17619 1 Laundry Booking Script Project 1 Laundry Booking Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-7991 1 Exponentcms 1 Exponent Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php.
CVE-2017-3835 1 Cisco 1 Identity Services Engine Software 2025-04-20 6.5 MEDIUM 8.8 HIGH
A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned by other users, because of SQL Injection. More Information: CSCvb15627. Known Affected Releases: 1.4(0.908).
CVE-2017-11384 1 Trendmicro 1 Control Manager 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation in mdHandlerLicenseManager.dll. Formerly ZDI-CAN-4561.
CVE-2017-17641 1 Resume Clone Script Project 1 Resume Clone Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
CVE-2016-6818 1 Sap 1 Business Intelligence Platform 2025-04-20 10.0 HIGH 9.8 CRITICAL
SQL injection vulnerability in SAP Business Intelligence platform before January 2017 allows remote attackers to obtain sensitive information, modify data, cause a denial of service (data deletion), or launch administrative operations or possibly OS commands via a crafted SQL query. The vendor response is SAP Security Note 2361633.
CVE-2017-11582 1 Finecms 1 Finecms 2025-04-20 7.5 HIGH 9.8 CRITICAL
dayrui FineCms 5.0.9 has SQL Injection via the num parameter in an action=related or action=tags request to libraries/Template.php.
CVE-2017-1175 1 Ibm 1 Maximo Asset Management 2025-04-20 7.5 HIGH 9.8 CRITICAL
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297.
CVE-2017-14403 1 Eyesofnetwork 1 Eyesofnetwork 2025-04-20 7.5 HIGH 9.8 CRITICAL
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the term parameter to module/admin_group/search.php.
CVE-2017-17581 1 Quibids Clone Project 1 Quibids Clone 2025-04-20 7.5 HIGH 9.8 CRITICAL
FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.