Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2014-2736 | 1 Modx | 1 Modx Revolution | 2019-10-22 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in MODX Revolution before 2.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) session ID (PHPSESSID) to index.php or remote authenticated users to execute arbitrary SQL commands via the (2) user parameter to connectors/security/message.php or (3) id parameter to manager/index.php. | |||||
CVE-2019-17117 | 1 Wikidsystems | 1 2fa Enterprise Server | 2019-10-22 | 6.5 MEDIUM | 8.8 HIGH |
A SQL injection vulnerability in processPref.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows an authenticated user to execute arbitrary SQL commands via the processPref.jsp key parameter. | |||||
CVE-2019-16404 | 1 Open-emr | 1 Openemr | 2019-10-22 | 6.5 MEDIUM | 8.8 HIGH |
Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO statement, as demonstrated by the providerID parameter. | |||||
CVE-2019-13409 | 1 Topmeeting | 1 Topmeeting | 2019-10-22 | 5.0 MEDIUM | 9.8 CRITICAL |
A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and username/password. | |||||
CVE-2019-16682 | 1 Url Redirect Project | 1 Url Redirect | 2019-10-21 | 7.5 HIGH | 7.3 HIGH |
The url_redirect (aka URL redirect) extension through 1.2.1 for TYPO3 fails to properly sanitize user input and is susceptible to SQL Injection. | |||||
CVE-2019-10752 | 1 Sequelizejs | 1 Sequelize | 2019-10-21 | 7.5 HIGH | 9.8 CRITICAL |
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite. | |||||
CVE-2019-17612 | 1 74cms | 1 74cms | 2019-10-17 | 6.5 MEDIUM | 7.2 HIGH |
An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter. | |||||
CVE-2015-9466 | 1 Webtechideas | 1 Wti Like Post | 2019-10-17 | 7.5 HIGH | 9.8 CRITICAL |
The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable. | |||||
CVE-2019-17553 | 1 Metinfo | 1 Metinfo | 2019-10-17 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI. | |||||
CVE-2019-17552 | 1 Idreamsoft | 1 Icms | 2019-10-16 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload. | |||||
CVE-2019-17580 | 1 Dormsystem Project | 1 Dormsystem | 2019-10-16 | 7.5 HIGH | 9.8 CRITICAL |
tonyy dormsystem through 1.3 allows SQL Injection in admin.php. | |||||
CVE-2015-9457 | 1 Caseproof | 1 Pretty Link | 2019-10-16 | 6.5 MEDIUM | 7.2 HIGH |
The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter. | |||||
CVE-2015-9465 | 1 Yet Another Stars Rating Project | 1 Yet Another Stars Rating | 2019-10-15 | 6.5 MEDIUM | 8.8 HIGH |
The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via the set_id parameter. | |||||
CVE-2019-10757 | 1 Knexjs | 1 Knex | 2019-10-15 | 7.5 HIGH | 9.8 CRITICAL |
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB. | |||||
CVE-2015-9460 | 1 Pinpoint | 1 Pinpoint Booking System | 2019-10-15 | 6.5 MEDIUM | 8.8 HIGH |
The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter. | |||||
CVE-2015-9462 | 1 Awesome Filterable Portfolio Project | 1 Awesome Filterable Portfolio | 2019-10-15 | 6.5 MEDIUM | 7.2 HIGH |
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat_id parameter. | |||||
CVE-2019-17429 | 1 Adhouma Cms Project | 1 Adhouma Cms | 2019-10-11 | 7.5 HIGH | 9.8 CRITICAL |
Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter. | |||||
CVE-2019-17128 | 1 Netreo | 1 Omnicenter | 2019-10-11 | 5.0 MEDIUM | 7.5 HIGH |
Netreo OmniCenter through 12.1.1 allows unauthenticated SQL Injection (Boolean Based Blind) in the redirect parameters and parameter name of the login page through a GET request. The injection allows an attacker to read sensitive information from the database used by the application. | |||||
CVE-2015-9467 | 1 K-78 | 1 Broken Link Manager | 2019-10-11 | 7.5 HIGH | 9.8 CRITICAL |
The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter. | |||||
CVE-2015-9461 | 1 Brinidesigner | 1 Awesome Filterable Portfolio | 2019-10-11 | 6.5 MEDIUM | 7.2 HIGH |
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_portfolio_item_page SQL injection via the item_id parameter. |