Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-5641 | 1 Basercms | 1 Basercms | 2021-07-15 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in baserCMS before 3.0.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2021-33578 | 1 Echobh | 1 Sharecare | 2021-07-15 | 7.5 HIGH | 9.8 CRITICAL |
Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticated and unauthenticated users, leading to the ability to bypass authentication, exfiltrate Structured Query Language (SQL) records, and manipulate data. | |||||
CVE-2020-18544 | 1 Wms Project | 1 Wms | 2021-07-14 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the component "chkuser.php". | |||||
CVE-2021-25427 | 1 Google | 1 Android | 2021-07-14 | 3.3 LOW | 6.5 MEDIUM |
SQL injection vulnerability in Bluetooth prior to SMR July-2021 Release 1 allows unauthorized access to paired device information | |||||
CVE-2020-21133 | 1 Metinfo | 1 Metinfo | 2021-07-12 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid. | |||||
CVE-2020-21132 | 1 Metinfo | 1 Metinfo | 2021-07-12 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection vulnerability in Metinfo 7.0.0beta in index.php. | |||||
CVE-2020-21131 | 1 Metinfo | 1 Metinfo | 2021-07-12 | 6.5 MEDIUM | 7.2 HIGH |
SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage. | |||||
CVE-2021-34609 | 1 Arubanetworks | 1 Clearpass Policy Manager | 2021-07-12 | 6.5 MEDIUM | 8.8 HIGH |
A remote SQL injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |||||
CVE-2021-24007 | 1 Fortinet | 1 Fortimail | 2021-07-12 | 7.5 HIGH | 9.8 CRITICAL |
Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | |||||
CVE-2020-20583 | 1 8cms | 1 Ljcms | 2021-07-12 | 5.0 MEDIUM | 7.5 HIGH |
A SQL injection vulnerability in /question.php of LJCMS Version v4.3.R60321 allows attackers to obtain sensitive database information. | |||||
CVE-2020-20585 | 1 Metinfo | 1 Metinfo | 2021-07-12 | 5.0 MEDIUM | 7.5 HIGH |
A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database information. | |||||
CVE-2021-24451 | 1 Export Users With Meta Project | 1 Export Users With Meta | 2021-07-09 | 6.5 MEDIUM | 7.2 HIGH |
The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in a SQL statement in the export functionality, available to admins, leading to an authenticated SQL Injection. | |||||
CVE-2021-32704 | 1 Dhis2 | 1 Dhis 2 | 2021-07-08 | 6.5 MEDIUM | 8.8 HIGH |
DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability has been found in specific versions of DHIS2. This vulnerability affects the /api/trackedEntityInstances API endpoint in DHIS2 versions 2.34.4, 2.35.2, 2.35.3, 2.35.4, and 2.36.0. Earlier versions, such as 2.34.3 and 2.35.1 and all versions 2.33 and older are unaffected. The system is vulnerable to attack only from users that are logged in to DHIS2, and there is no known way of exploiting the vulnerability without first being logged in as a DHIS2 user. A successful exploit of this vulnerability could allow the malicious user to read, edit and delete data in the DHIS2 instance. There are no known exploits of the security vulnerabilities addressed by these patch releases. However, we strongly recommend that all DHIS2 implementations using versions 2.34, 2.35 and 2.36 install these patches as soon as possible. There is no straightforward known workaround for DHIS2 instances using the Tracker functionality other than upgrading the affected DHIS2 server to one of the patches in which this vulnerability has been fixed. For implementations which do NOT use Tracker functionality, it may be possible to block all network access to POST to the /api/trackedEntityInstance endpoint as a temporary workaround while waiting to upgrade. | |||||
CVE-2020-4902 | 2 Ibm, Microsoft | 2 Datacap Navigator, Windows | 2021-07-07 | 6.5 MEDIUM | 8.8 HIGH |
IBM Datacap Taskmaster Capture (IBM Datacap Navigator 9.1.7) is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191045. | |||||
CVE-2021-28423 | 1 Teachers Record Management System Project | 1 Teachers Record Management System | 2021-07-07 | 6.5 MEDIUM | 8.8 HIGH |
Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in search.php. | |||||
CVE-2021-27950 | 1 Sitasoftware | 1 Azurcms | 2021-07-06 | 6.5 MEDIUM | 8.8 HIGH |
A SQL injection vulnerability in azurWebEngine in Sita AzurCMS through 1.2.3.12 allows an authenticated attacker to execute arbitrary SQL commands via the id parameter to mesdocs.ajax.php in azurWebEngine/eShop. By default, the query is executed as DBA. | |||||
CVE-2021-28993 | 1 Plixer | 1 Scrutinizer | 2021-07-06 | 5.0 MEDIUM | 7.5 HIGH |
Plixer Scrutinizer 19.0.2 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). | |||||
CVE-2020-21394 | 1 Crmeb | 1 Crmeb | 2021-07-02 | 6.5 MEDIUM | 8.8 HIGH |
SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php. | |||||
CVE-2021-35456 | 1 Online Pet Shop Web Application Project | 1 Online Pet Shop Web Application | 2021-07-01 | 7.5 HIGH | 9.8 CRITICAL |
Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload | |||||
CVE-2021-34187 | 1 Chamilo | 1 Chamilo | 2021-07-01 | 7.5 HIGH | 9.8 CRITICAL |
main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter. |