Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2012-5698 | 1 Babygekko | 1 Babygekko | 2020-01-29 | 6.8 MEDIUM | 8.8 HIGH |
BabyGekko before 1.2.4 has SQL injection. | |||||
CVE-2020-7229 | 1 Simplejobscript | 1 Simplejobscript | 2020-01-29 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landing_location. The function is countSearchedJobs(). The file is _lib/class.Job.php. | |||||
CVE-2019-12619 | 1 Cisco | 8 Sd-wan Firmware, Vedge-100, Vedge-1000 and 5 more | 2020-01-29 | 4.0 MEDIUM | 6.5 MEDIUM |
A vulnerability in the web interface for Cisco SD-WAN Solution vManage could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input that includes SQL statements to an affected system. A successful exploit could allow the attacker to modify entries in some database tables, affecting the integrity of the data. | |||||
CVE-2020-7981 | 1 Rubygeocoder | 1 Geocoder | 2020-01-27 | 7.5 HIGH | 9.8 CRITICAL |
sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data. | |||||
CVE-2020-7939 | 1 Plone | 1 Plone | 2020-01-24 | 6.5 MEDIUM | 8.8 HIGH |
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.) | |||||
CVE-2012-1259 | 1 Plixer | 1 Scrutinizer Netflow \& Sflow Analyzer | 2020-01-24 | 7.5 HIGH | 9.8 CRITICAL |
Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands via the (1) addip parameter to cgi-bin/scrut_fa_exclusions.cgi, (2) getPermissionsAndPreferences parameter to cgi-bin/login.cgi, or (3) possibly certain parameters to d4d/alarms.php as demonstrated by the search_str parameter. | |||||
CVE-2011-0467 | 1 Suse | 2 Studio Onsite, Studio Onsite Appliance | 2020-01-24 | 6.5 MEDIUM | 8.8 HIGH |
A vulnerability in the listing of available software of SUSE Studio Onsite, SUSE Studio Onsite 1.1 Appliance allows authenticated users to execute arbitrary SQL statements via SQL injection. Affected releases are SUSE Studio Onsite: versions prior to 1.0.3-0.18.1, SUSE Studio Onsite 1.1 Appliance: versions prior to 1.1.2-0.25.1. | |||||
CVE-2011-2715 | 1 Drupal | 2 Data, Drupal | 2020-01-24 | 7.5 HIGH | 9.8 CRITICAL |
An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names. | |||||
CVE-2011-4094 | 1 Jara Project | 1 Jara | 2020-01-23 | 7.5 HIGH | 9.8 CRITICAL |
Jara 1.6 has a SQL injection vulnerability. | |||||
CVE-2005-4891 | 1 Simplemachines | 1 Simple Machine Forum | 2020-01-21 | 7.5 HIGH | 9.8 CRITICAL |
Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements. | |||||
CVE-2018-16803 | 1 Cimtechniques | 1 Cimscan | 2020-01-16 | 10.0 HIGH | 9.8 CRITICAL |
In CIMTechniques CIMScan 6.x through 6.2, the SOAP WSDL parser allows attackers to execute SQL code. | |||||
CVE-2020-5841 | 1 Opservices | 1 Opmon | 2020-01-16 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL injection without authentication. | |||||
CVE-2011-5266 | 1 Imperva | 1 Securesphere Web Application Firewall | 2020-01-15 | 7.5 HIGH | 9.8 CRITICAL |
Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass. | |||||
CVE-2019-20179 | 1 Soplanning | 1 Soplanning | 2020-01-15 | 6.5 MEDIUM | 8.8 HIGH |
SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter. | |||||
CVE-2019-18622 | 3 Fedoraproject, Opensuse, Phpmyadmin | 4 Fedora, Backports Sle, Leap and 1 more | 2020-01-14 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature. | |||||
CVE-2014-5140 | 1 Loadedcommerce | 1 Loaded7 | 2020-01-14 | 6.5 MEDIUM | 8.8 HIGH |
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks via the First name and Last name fields in the address book. | |||||
CVE-2019-4651 | 1 Ibm | 1 Jazz Reporting Service | 2020-01-14 | 7.5 HIGH | 9.8 CRITICAL |
IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962. | |||||
CVE-2011-5020 | 1 Online Tv Database Project | 1 Online Tv Database | 2020-01-14 | 7.5 HIGH | 9.8 CRITICAL |
An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011. | |||||
CVE-2020-5192 | 1 Phpgurukul | 1 Hospital Management System In Php | 2020-01-13 | 6.5 MEDIUM | 8.8 HIGH |
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised. | |||||
CVE-2011-1933 | 1 Jifty\ | 1 \ | 2020-01-13 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in Jifty::DBI before 0.68. |