Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-20300 1 Weiphp 1 Weiphp 2020-12-21 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the wp_where function in WeiPHP 5.0.
CVE-2020-35545 1 Spotweb Project 1 Spotweb 2020-12-21 7.5 HIGH 9.8 CRITICAL
Time-based SQL injection exists in Spotweb 1.4.9 via the query string.
CVE-2020-35122 1 Keysight 1 Keysight Database Connector 2020-12-16 4.0 MEDIUM 7.5 HIGH
An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could bypass the access controls for using a saved database connection profile to submit arbitrary SQL against a saved database connection.
CVE-2020-16104 1 Gallagher 1 Command Centre 2020-12-16 6.5 MEDIUM 7.2 HIGH
SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Interfaces' privilege to execute arbitrary SQL against a third party database if EDI is configured to import data from this database. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1236(MR1); 8.20 versions prior to 8.20.1166(MR3); 8.10 versions prior to 8.10.1211(MR5); 8.00 versions prior to 8.00.1228(MR6); version 7.90 and prior versions.
CVE-2018-12636 1 Ithemes 1 Security 2020-12-15 6.5 MEDIUM 7.2 HIGH
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.
CVE-2020-25889 1 Online Bus Booking System Project 1 Online Bus Booking System 2020-12-15 7.5 HIGH 9.8 CRITICAL
Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege.
CVE-2020-28860 1 Openasset 1 Digital Asset Management 2020-12-15 6.5 MEDIUM 8.8 HIGH
OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.
CVE-2020-20189 1 Newpk Project 1 Newpk 2020-12-15 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\newpost.php.
CVE-2019-19286 1 Siemens 1 Xhq 2020-12-15 6.5 MEDIUM 7.2 HIGH
A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow SQL injection attacks if an attacker is able to modify content of particular web pages.
CVE-2020-35382 1 Classroombookings 1 Classroombookings 2020-12-14 6.5 MEDIUM 7.2 HIGH
SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user.
CVE-2020-35378 1 Online Bus Ticket Reservation Project 1 Online Bus Ticket Reservation 2020-12-14 7.5 HIGH 9.8 CRITICAL
SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.
CVE-2020-29574 1 Sophos 1 Cyberoamos 2020-12-14 7.5 HIGH 9.8 CRITICAL
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
CVE-2020-19165 1 Phpshe 1 Phpshe 2020-12-14 7.5 HIGH 9.8 CRITICAL
PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.
CVE-2020-14207 1 Divebook Project 1 Divebook 2020-12-10 5.0 MEDIUM 5.3 MEDIUM
The DiveBook plugin 1.1.4 for WordPress was prone to a SQL injection within divelog.php, allowing unauthenticated users to retrieve data from the database via the divelog.php filter_diver parameter.
CVE-2020-3984 1 Vmware 1 Sd-wan Orchestrator 2020-12-07 4.0 MEDIUM 6.5 MEDIUM
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection. An authenticated SD-WAN Orchestrator user may exploit a vulnerable API call using specially crafted SQL queries which may lead to unauthorized data access.
CVE-2020-4003 1 Vmware 1 Sd-wan Orchestrator 2020-12-07 4.0 MEDIUM 6.5 MEDIUM
VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulnerable to SQL-injection attacks allowing for potential information disclosure. An authenticated SD-WAN Orchestrator user may inject code into SQL queries which may lead to information disclosure.
CVE-2020-6880 1 Zte 2 Zxv10 W908, Zxv10 W908 Firmware 2020-12-04 7.5 HIGH 9.8 CRITICAL
A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can obtain management rights. This affects: ZXV10 W908 all versions before MIPS_A_1022IPV6R3T6P7Y20.
CVE-2020-29283 1 Online Doctor Appointment Booking System Php And Mysql Project 1 Online Doctor Appointment Booking System Php And Mysql 2020-12-04 7.5 HIGH 9.8 CRITICAL
An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.
CVE-2020-29284 1 Multi Restaurant Table Reservation System Project 1 Multi Restaurant Table Reservation System 2020-12-04 7.5 HIGH 9.8 CRITICAL
The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.
CVE-2020-29285 1 Point Of Sales In Php\/pdo Project 1 Point Of Sales In Php\/pdo 2020-12-04 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter to edit_category.php.