Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-29282 1 Bloodx Project 1 Bloodx 2020-12-03 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication.
CVE-2020-25700 2 Fedoraproject, Moodle 2 Fedora, Moodle 2020-12-03 4.0 MEDIUM 6.5 MEDIUM
In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.
CVE-2020-25839 1 Microfocus 1 Identity Manager 2020-12-03 7.5 HIGH 9.8 CRITICAL
NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected by an injection vulnerability. This vulnerability is fixed in NetIQ IdM 4.8 SP2 HF1.
CVE-2020-29280 1 Victor Cms Project 1 Victor Cms 2020-12-02 7.5 HIGH 9.8 CRITICAL
The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.
CVE-2020-29288 1 Gym Management System Project 1 Gym Management System 2020-12-02 7.5 HIGH 9.8 CRITICAL
An SQL injection vulnerability was discovered in Gym Management System In manage_user.php file, GET parameter 'id' is vulnerable.
CVE-2020-29287 1 Car Rental Management System Project 1 Car Rental Management System 2020-12-02 7.5 HIGH 9.8 CRITICAL
An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter in view_car.php or the car_id parameter in booking.php.
CVE-2020-28091 1 Cxuu 1 Cxuucms 2020-12-01 5.0 MEDIUM 7.5 HIGH
cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php.
CVE-2020-21667 1 Fastadmin-tp6 Project 1 Fastadmin-tp6 2020-12-01 6.5 MEDIUM 7.2 HIGH
In fastadmin-tp6 v1.0, in the file app/admin/controller/Ajax.php the 'table' parameter passed is not filtered so a malicious parameter can be passed for SQL injection.
CVE-2020-28133 1 Simple Grocery Store Sales And Inventory Sales Project 1 Simple Grocery Store Sales And Inventory System 2020-12-01 7.5 HIGH 9.8 CRITICAL
An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in sales_inventory/login.php.
CVE-2020-28183 1 Water Billing System Project 1 Water Billing System 2020-12-01 10.0 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php.
CVE-2013-4313 1 Moodle 1 Moodle 2020-12-01 7.5 HIGH N/A
Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.
CVE-2010-1615 1 Moodle 1 Moodle 2020-12-01 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the add_to_log function in mod/wiki/view.php in the wiki module, or (2) "data validation in some forms elements" related to lib/form/selectgroups.php.
CVE-2012-3395 1 Moodle 1 Moodle 2020-12-01 6.5 MEDIUM N/A
SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.
CVE-2012-2363 1 Moodle 1 Moodle 2020-12-01 6.5 MEDIUM N/A
SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.
CVE-2009-4305 1 Moodle 1 Moodle 2020-12-01 6.5 MEDIUM N/A
SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."
CVE-2011-4292 1 Moodle 1 Moodle 2020-12-01 4.0 MEDIUM N/A
Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted comments operations.
CVE-2020-21665 1 Fastadmin 1 Fastadmin 2020-11-30 6.5 MEDIUM 7.2 HIGH
In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be passed for SQL injection in URL /admin/ajax/weigh.
CVE-2019-19876 1 Br-automation 1 Industrial Automation Aprol 2020-11-30 7.5 HIGH 9.8 CRITICAL
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006.
CVE-2020-28994 1 Karenderia Multiple Restaurant System Project 1 Karenderia Multiple Restaurant System 2020-11-30 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifying and leaking all contents of the database.
CVE-2014-9519 1 Infinitewp 1 Infinitewp 2020-11-30 7.5 HIGH N/A
SQL injection vulnerability in login.php in InfiniteWP Admin Panel before 2.4.3 allows remote attackers to execute arbitrary SQL commands via the email parameter.