Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-5698 1 Babygekko 1 Babygekko 2020-01-29 6.8 MEDIUM 8.8 HIGH
BabyGekko before 1.2.4 has SQL injection.
CVE-2020-7229 1 Simplejobscript 1 Simplejobscript 2020-01-29 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landing_location. The function is countSearchedJobs(). The file is _lib/class.Job.php.
CVE-2019-12619 1 Cisco 8 Sd-wan Firmware, Vedge-100, Vedge-1000 and 5 more 2020-01-29 4.0 MEDIUM 6.5 MEDIUM
A vulnerability in the web interface for Cisco SD-WAN Solution vManage could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input that includes SQL statements to an affected system. A successful exploit could allow the attacker to modify entries in some database tables, affecting the integrity of the data.
CVE-2020-7981 1 Rubygeocoder 1 Geocoder 2020-01-27 7.5 HIGH 9.8 CRITICAL
sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.
CVE-2020-7939 1 Plone 1 Plone 2020-01-24 6.5 MEDIUM 8.8 HIGH
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)
CVE-2012-1259 1 Plixer 1 Scrutinizer Netflow \& Sflow Analyzer 2020-01-24 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands via the (1) addip parameter to cgi-bin/scrut_fa_exclusions.cgi, (2) getPermissionsAndPreferences parameter to cgi-bin/login.cgi, or (3) possibly certain parameters to d4d/alarms.php as demonstrated by the search_str parameter.
CVE-2011-0467 1 Suse 2 Studio Onsite, Studio Onsite Appliance 2020-01-24 6.5 MEDIUM 8.8 HIGH
A vulnerability in the listing of available software of SUSE Studio Onsite, SUSE Studio Onsite 1.1 Appliance allows authenticated users to execute arbitrary SQL statements via SQL injection. Affected releases are SUSE Studio Onsite: versions prior to 1.0.3-0.18.1, SUSE Studio Onsite 1.1 Appliance: versions prior to 1.1.2-0.25.1.
CVE-2011-2715 1 Drupal 2 Data, Drupal 2020-01-24 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.
CVE-2011-4094 1 Jara Project 1 Jara 2020-01-23 7.5 HIGH 9.8 CRITICAL
Jara 1.6 has a SQL injection vulnerability.
CVE-2005-4891 1 Simplemachines 1 Simple Machine Forum 2020-01-21 7.5 HIGH 9.8 CRITICAL
Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.
CVE-2018-16803 1 Cimtechniques 1 Cimscan 2020-01-16 10.0 HIGH 9.8 CRITICAL
In CIMTechniques CIMScan 6.x through 6.2, the SOAP WSDL parser allows attackers to execute SQL code.
CVE-2020-5841 1 Opservices 1 Opmon 2020-01-16 7.5 HIGH 9.8 CRITICAL
An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL injection without authentication.
CVE-2011-5266 1 Imperva 1 Securesphere Web Application Firewall 2020-01-15 7.5 HIGH 9.8 CRITICAL
Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.
CVE-2019-20179 1 Soplanning 1 Soplanning 2020-01-15 6.5 MEDIUM 8.8 HIGH
SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.
CVE-2019-18622 3 Fedoraproject, Opensuse, Phpmyadmin 4 Fedora, Backports Sle, Leap and 1 more 2020-01-14 7.5 HIGH 9.8 CRITICAL
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.
CVE-2014-5140 1 Loadedcommerce 1 Loaded7 2020-01-14 6.5 MEDIUM 8.8 HIGH
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks via the First name and Last name fields in the address book.
CVE-2019-4651 1 Ibm 1 Jazz Reporting Service 2020-01-14 7.5 HIGH 9.8 CRITICAL
IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962.
CVE-2011-5020 1 Online Tv Database Project 1 Online Tv Database 2020-01-14 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011.
CVE-2020-5192 1 Phpgurukul 1 Hospital Management System In Php 2020-01-13 6.5 MEDIUM 8.8 HIGH
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.
CVE-2011-1933 1 Jifty\ 1 \ 2020-01-13 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Jifty::DBI before 0.68.