Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-23214 | 3 Fedoraproject, Postgresql, Redhat | 6 Fedora, Postgresql, Enterprise Linux and 3 more | 2023-01-31 | 5.1 MEDIUM | 8.1 HIGH |
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. | |||||
CVE-2022-1691 | 1 Realtyworkstation | 1 Realty Workstation | 2023-01-31 | 4.0 MEDIUM | 4.9 MEDIUM |
The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection | |||||
CVE-2021-37589 | 1 Virtuasoftware | 1 Cobranca | 2023-01-31 | 5.0 MEDIUM | 7.5 HIGH |
Virtua Cobranca before 12R allows SQL Injection on the login page. | |||||
CVE-2018-16384 | 1 Owasp | 1 Owasp Modsecurity Core Rule Set | 2023-01-30 | 5.0 MEDIUM | 7.5 HIGH |
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed. | |||||
CVE-2019-19650 | 1 Zohocorp | 1 Manageengine Applications Manager | 2023-01-30 | 6.5 MEDIUM | 8.8 HIGH |
Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function. | |||||
CVE-2019-11821 | 1 Synology | 1 Photo Station | 2023-01-30 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to execute arbitrary SQL command via the type parameter. | |||||
CVE-2019-13413 | 1 Boiteasite | 1 Rencontre | 2023-01-30 | 7.5 HIGH | 9.8 CRITICAL |
The Rencontre plugin before 3.1.3 for WordPress allows SQL Injection via inc/rencontre_widget.php. | |||||
CVE-2022-29411 | 1 Hermit Project | 1 Hermit | 2023-01-30 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection (SQLi) vulnerability in Mufeng's Hermit ????? plugin <= 3.1.6 on WordPress allows attackers to execute SQLi attack via (&id). | |||||
CVE-2022-29410 | 1 Hermit Project | 1 Hermit | 2023-01-30 | 6.5 MEDIUM | 8.8 HIGH |
Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit ????? plugin <= 3.1.6 on WordPress allows attackers with Subscriber or higher user roles to execute SQLi attack via (&ids). | |||||
CVE-2022-4383 | 1 Codeboxr | 1 Cbx Petition For Wordpress | 2023-01-30 | N/A | 9.8 CRITICAL |
The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |||||
CVE-2022-46071 | 1 Helmet Store Showroom Site Project | 1 Helmet Store Showroom Site | 2023-01-30 | N/A | 9.8 CRITICAL |
There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access. | |||||
CVE-2022-46072 | 1 Helmet Store Showroom Project | 1 Helmet Store Showroom | 2023-01-30 | N/A | 9.8 CRITICAL |
Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection. | |||||
CVE-2018-20469 | 1 Sahipro | 1 Sahi Pro | 2023-01-30 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to h2 SQL injection. This can be exploited to inject SQL queries and run standard h2 system functions. | |||||
CVE-2022-38492 | 1 Easyvista | 1 Service Manager | 2023-01-30 | N/A | 8.8 HIGH |
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes the vulnerability. | |||||
CVE-2022-38490 | 1 Easyvista | 1 Service Manager | 2023-01-30 | N/A | 8.8 HIGH |
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue. | |||||
CVE-2022-4230 | 1 Veronalabs | 1 Wp Statistics | 2023-01-30 | N/A | 8.8 HIGH |
The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well. | |||||
CVE-2019-19740 | 1 Octeth | 1 Oempro | 2023-01-27 | 7.5 HIGH | 9.8 CRITICAL |
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable. | |||||
CVE-2020-13640 | 1 Gvectors | 1 Wpdiscuz | 2023-01-27 | 7.5 HIGH | 9.8 CRITICAL |
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.) | |||||
CVE-2013-10014 | 1 2moons Project | 1 2moons | 2023-01-27 | N/A | 9.8 CRITICAL |
A vulnerability classified as critical has been found in oktora24 2moons. Affected is an unknown function. The manipulation leads to sql injection. The name of the patch is 1b09cf7672eb85b5b0c8a4de321f7a4ad87b09a7. It is recommended to apply a patch to fix this issue. VDB-218898 is the identifier assigned to this vulnerability. | |||||
CVE-2015-10070 | 1 Twiddit Project | 1 Twiddit | 2023-01-27 | N/A | 9.8 CRITICAL |
A vulnerability was found in copperwall Twiddit. It has been rated as critical. This issue affects some unknown processing of the file index.php. The manipulation leads to sql injection. The name of the patch is 2203d4ce9810bdaccece5c48ff4888658a01acfc. It is recommended to apply a patch to fix this issue. The identifier VDB-218897 was assigned to this vulnerability. |