Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-20896 1 Webchess Project 1 Webchess 2020-07-09 7.5 HIGH 9.8 CRITICAL
WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.
CVE-2020-15540 1 We-com 1 Opendata Cms 2020-07-09 7.5 HIGH 9.8 CRITICAL
We-com OpenData CMS 2.0 allows SQL Injection via the username field on the administrator login page.
CVE-2020-14092 1 Ithemes 1 Paypal Pro 2020-07-08 7.5 HIGH 9.8 CRITICAL
The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.
CVE-2017-7410 1 Websitebaker 1 Websitebaker 2020-07-07 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username, (2) display_name parameter.
CVE-2020-15468 1 Persian Vip Download Script Project 1 Persian Vip Download Script 2020-07-07 7.5 HIGH 9.8 CRITICAL
Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.
CVE-2014-5387 2 Ellislab, Expressionengine 2 Expressionengine, Expressionengine 2020-07-06 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) column_filter or (2) category[] parameter to system/index.php or the (3) tbl_sort[0][] parameter in the comment module to system/index.php.
CVE-2018-6494 1 Microfocus 1 Service Manager 2020-07-06 5.5 MEDIUM 5.4 MEDIUM
Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, may lead to unauthorized disclosure of data.
CVE-2020-15308 1 Turnkeylinux 1 Support Incident Tracker 2020-07-06 6.5 MEDIUM 7.2 HIGH
Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parameter, or the report_qbe.php criteriafield parameter.
CVE-2020-14069 1 Mk-auth 1 Mk-auth 2020-07-02 4.6 MEDIUM 6.8 MEDIUM
An issue was discovered in MK-AUTH 19.01. There are SQL injection issues in mkt/ PHP scripts, as demonstrated by arp.php, dhcp.php, hotspot.php, ip.php, pgaviso.php, pgcorte.php, pppoe.php, queues.php, and wifi.php.
CVE-2019-4650 1 Ibm 1 Maximo Asset Management 2020-07-01 6.5 MEDIUM 6.3 MEDIUM
IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170961.
CVE-2017-18888 1 Mattermost 1 Mattermost Server 2020-06-26 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.
CVE-2020-14960 1 Php-fusion 1 Php-fusion 2020-06-26 6.5 MEDIUM 7.2 HIGH
A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype parameter,
CVE-2018-18755 1 K-iwi 1 K-iwi 2020-06-25 7.5 HIGH 9.8 CRITICAL
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/update user_id parameter.
CVE-2020-14443 1 Dolibarr 1 Dolibarr 2020-06-24 6.5 MEDIUM 8.8 HIGH
A SQL injection vulnerability in accountancy/customer/card.php in Dolibarr 11.0.3 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
CVE-2020-14159 1 Connectwise 1 Automate Api 2020-06-24 6.5 MEDIUM 8.8 HIGH
By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance by triggering an SQL injection vulnerability in /LabTech/agent.aspx. This affects versions before 2019.12.337, 2020 before 2020.1.53, 2020.2 before 2020.2.85, 2020.3 before 2020.3.114, 2020.4 before 2020.4.143, and 2020.5 before 2020.5.178.
CVE-2009-3337 1 S9y 1 Serendipity Event Freetag 2020-06-23 7.5 HIGH N/A
SQL injection vulnerability in the Freetag (serendipity_event_freetag) plugin before 3.09 for Serendipity (S9Y) allows remote attackers to execute arbitrary SQL commands via an unspecified parameter associated with Meta keywords in a blog entry.
CVE-2020-14054 1 Sokkia 2 Gnr5 Vanguard, Gnr5 Vanguard Firmware 2020-06-22 7.5 HIGH 9.8 CRITICAL
SOKKIA GNR5 Vanguard WEB version 1.2 (build: 91f2b2c3a04d203d79862f87e2440cb7cefc3cd3) and hardware version 212 allows remote attackers to bypass admin authentication via a SQL injection attack that uses the User Name or Password field on the login page.
CVE-2019-20842 1 Mattermost 1 Mattermost Server 2020-06-19 6.5 MEDIUM 7.2 HIGH
An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There is SQL injection by admins via SearchAllChannels.
CVE-2020-7471 1 Djangoproject 1 Django 2020-06-18 7.5 HIGH 9.8 CRITICAL
Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column delimiter). By passing a suitably crafted delimiter to a contrib.postgres.aggregates.StringAgg instance, it was possible to break escaping and inject malicious SQL.
CVE-2020-7493 1 Schneider-electric 1 Ecostruxure Operator Terminal Expert 2020-06-17 6.8 MEDIUM 7.8 HIGH
A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.