Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-2736 1 Modx 1 Modx Revolution 2019-10-22 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in MODX Revolution before 2.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) session ID (PHPSESSID) to index.php or remote authenticated users to execute arbitrary SQL commands via the (2) user parameter to connectors/security/message.php or (3) id parameter to manager/index.php.
CVE-2019-17117 1 Wikidsystems 1 2fa Enterprise Server 2019-10-22 6.5 MEDIUM 8.8 HIGH
A SQL injection vulnerability in processPref.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows an authenticated user to execute arbitrary SQL commands via the processPref.jsp key parameter.
CVE-2019-16404 1 Open-emr 1 Openemr 2019-10-22 6.5 MEDIUM 8.8 HIGH
Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO statement, as demonstrated by the providerID parameter.
CVE-2019-13409 1 Topmeeting 1 Topmeeting 2019-10-22 5.0 MEDIUM 9.8 CRITICAL
A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and username/password.
CVE-2019-16682 1 Url Redirect Project 1 Url Redirect 2019-10-21 7.5 HIGH 7.3 HIGH
The url_redirect (aka URL redirect) extension through 1.2.1 for TYPO3 fails to properly sanitize user input and is susceptible to SQL Injection.
CVE-2019-10752 1 Sequelizejs 1 Sequelize 2019-10-21 7.5 HIGH 9.8 CRITICAL
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.
CVE-2019-17612 1 74cms 1 74cms 2019-10-17 6.5 MEDIUM 7.2 HIGH
An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter.
CVE-2015-9466 1 Webtechideas 1 Wti Like Post 2019-10-17 7.5 HIGH 9.8 CRITICAL
The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable.
CVE-2019-17553 1 Metinfo 1 Metinfo 2019-10-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI.
CVE-2019-17552 1 Idreamsoft 1 Icms 2019-10-16 7.5 HIGH 9.8 CRITICAL
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.
CVE-2019-17580 1 Dormsystem Project 1 Dormsystem 2019-10-16 7.5 HIGH 9.8 CRITICAL
tonyy dormsystem through 1.3 allows SQL Injection in admin.php.
CVE-2015-9457 1 Caseproof 1 Pretty Link 2019-10-16 6.5 MEDIUM 7.2 HIGH
The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter.
CVE-2015-9465 1 Yet Another Stars Rating Project 1 Yet Another Stars Rating 2019-10-15 6.5 MEDIUM 8.8 HIGH
The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via the set_id parameter.
CVE-2019-10757 1 Knexjs 1 Knex 2019-10-15 7.5 HIGH 9.8 CRITICAL
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.
CVE-2015-9460 1 Pinpoint 1 Pinpoint Booking System 2019-10-15 6.5 MEDIUM 8.8 HIGH
The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter.
CVE-2015-9462 1 Awesome Filterable Portfolio Project 1 Awesome Filterable Portfolio 2019-10-15 6.5 MEDIUM 7.2 HIGH
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat_id parameter.
CVE-2019-17429 1 Adhouma Cms Project 1 Adhouma Cms 2019-10-11 7.5 HIGH 9.8 CRITICAL
Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter.
CVE-2019-17128 1 Netreo 1 Omnicenter 2019-10-11 5.0 MEDIUM 7.5 HIGH
Netreo OmniCenter through 12.1.1 allows unauthenticated SQL Injection (Boolean Based Blind) in the redirect parameters and parameter name of the login page through a GET request. The injection allows an attacker to read sensitive information from the database used by the application.
CVE-2015-9467 1 K-78 1 Broken Link Manager 2019-10-11 7.5 HIGH 9.8 CRITICAL
The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter.
CVE-2015-9461 1 Brinidesigner 1 Awesome Filterable Portfolio 2019-10-11 6.5 MEDIUM 7.2 HIGH
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_portfolio_item_page SQL injection via the item_id parameter.