Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-24137 | 1 Adenion | 1 Blog2social | 2021-03-23 | 6.5 MEDIUM | 8.8 HIGH |
Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authenticated users to inject arbitrary SQL commands. | |||||
CVE-2021-24149 | 1 Webnus | 1 Modern Events Calendar Lite | 2021-03-23 | 6.5 MEDIUM | 8.8 HIGH |
Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue. | |||||
CVE-2020-5579 | 1 Strangerstudios | 1 Paid Memberships Pro | 2021-03-23 | 6.5 MEDIUM | 7.2 HIGH |
SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2021-22848 | 1 Hgiga | 4 Msr45 Isherlock-antispam, Msr45 Isherlock-user, Ssr45 Isherlock-antispam and 1 more | 2021-03-23 | 7.5 HIGH | 9.8 CRITICAL |
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege. | |||||
CVE-2021-22859 | 1 Eic | 1 E-document System | 2021-03-23 | 7.5 HIGH | 9.8 CRITICAL |
The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary commands without privilege. | |||||
CVE-2021-20678 | 1 Paidmembershipspro | 1 Paid Memberships Pro | 2021-03-23 | 6.5 MEDIUM | 8.8 HIGH |
SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2021-24139 | 1 10web | 1 Photo Gallery | 2021-03-22 | 7.5 HIGH | 9.8 CRITICAL |
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter. | |||||
CVE-2021-24140 | 1 Connekthq | 1 Ajax Load More | 2021-03-22 | 6.5 MEDIUM | 7.2 HIGH |
Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test. | |||||
CVE-2021-24141 | 1 Sigmaplugin | 1 Advanced Database Cleaner | 2021-03-22 | 6.5 MEDIUM | 7.2 HIGH |
Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high privilege users (admin+) to perform SQL attacks. | |||||
CVE-2021-24143 | 1 Accesspressthemes | 1 Accesspress Social Icons | 2021-03-22 | 6.5 MEDIUM | 8.8 HIGH |
Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections. | |||||
CVE-2021-24142 | 1 Premiumwpsuite | 1 Easy Redirect Manager | 2021-03-22 | 6.5 MEDIUM | 7.2 HIGH |
Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections. | |||||
CVE-2021-28381 | 1 Vhs Project | 1 Vhs | 2021-03-22 | 7.5 HIGH | 9.8 CRITICAL |
The vhs (aka VHS: Fluid ViewHelpers) extension before 5.1.1 for TYPO3 allows SQL injection via isLanguageViewHelper. | |||||
CVE-2020-24913 | 1 Qcubed | 1 Qcubed | 2021-03-22 | 7.5 HIGH | 9.8 CRITICAL |
A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request. | |||||
CVE-2021-28295 | 1 Online Ordering System Project | 1 Online Ordering System | 2021-03-22 | 5.0 MEDIUM | 7.5 HIGH |
Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure. | |||||
CVE-2018-17254 | 1 Arkextensions | 1 Jck Editor | 2021-03-17 | 7.5 HIGH | 9.8 CRITICAL |
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter. | |||||
CVE-2021-27947 | 1 Mybb | 1 Mybb | 2021-03-16 | 6.5 MEDIUM | 7.2 HIGH |
SQL Injection vulnerability in MyBB before 1.8.26 via the Copy Forum feature in Forum Management. (issue 2 of 3). | |||||
CVE-2021-27948 | 1 Mybb | 1 Mybb | 2021-03-16 | 6.5 MEDIUM | 7.2 HIGH |
SQL Injection vulnerability in MyBB before 1.8.26 via User Groups. (issue 3 of 3). | |||||
CVE-2020-24877 | 1 Zzzcms | 1 Zzzphp | 2021-03-15 | 7.5 HIGH | 9.8 CRITICAL |
A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass. | |||||
CVE-2021-27581 | 1 Kentico | 1 Kentico Cms | 2021-03-15 | 7.5 HIGH | 9.8 CRITICAL |
The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter. | |||||
CVE-2021-23352 | 1 Madge Project | 1 Madge | 2021-03-12 | 7.5 HIGH | 9.8 CRITICAL |
This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image(), .svg() or .dot() functions are called, is executed by the childprocess.exec function. |