Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-23214 3 Fedoraproject, Postgresql, Redhat 6 Fedora, Postgresql, Enterprise Linux and 3 more 2023-01-31 5.1 MEDIUM 8.1 HIGH
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.
CVE-2022-1691 1 Realtyworkstation 1 Realty Workstation 2023-01-31 4.0 MEDIUM 4.9 MEDIUM
The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection
CVE-2021-37589 1 Virtuasoftware 1 Cobranca 2023-01-31 5.0 MEDIUM 7.5 HIGH
Virtua Cobranca before 12R allows SQL Injection on the login page.
CVE-2018-16384 1 Owasp 1 Owasp Modsecurity Core Rule Set 2023-01-30 5.0 MEDIUM 7.5 HIGH
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed.
CVE-2019-19650 1 Zohocorp 1 Manageengine Applications Manager 2023-01-30 6.5 MEDIUM 8.8 HIGH
Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.
CVE-2019-11821 1 Synology 1 Photo Station 2023-01-30 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to execute arbitrary SQL command via the type parameter.
CVE-2019-13413 1 Boiteasite 1 Rencontre 2023-01-30 7.5 HIGH 9.8 CRITICAL
The Rencontre plugin before 3.1.3 for WordPress allows SQL Injection via inc/rencontre_widget.php.
CVE-2022-29411 1 Hermit Project 1 Hermit 2023-01-30 7.5 HIGH 9.8 CRITICAL
SQL Injection (SQLi) vulnerability in Mufeng's Hermit ????? plugin <= 3.1.6 on WordPress allows attackers to execute SQLi attack via (&id).
CVE-2022-29410 1 Hermit Project 1 Hermit 2023-01-30 6.5 MEDIUM 8.8 HIGH
Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit ????? plugin <= 3.1.6 on WordPress allows attackers with Subscriber or higher user roles to execute SQLi attack via (&ids).
CVE-2022-4383 1 Codeboxr 1 Cbx Petition For Wordpress 2023-01-30 N/A 9.8 CRITICAL
The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
CVE-2022-46071 1 Helmet Store Showroom Site Project 1 Helmet Store Showroom Site 2023-01-30 N/A 9.8 CRITICAL
There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.
CVE-2022-46072 1 Helmet Store Showroom Project 1 Helmet Store Showroom 2023-01-30 N/A 9.8 CRITICAL
Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection.
CVE-2018-20469 1 Sahipro 1 Sahi Pro 2023-01-30 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to h2 SQL injection. This can be exploited to inject SQL queries and run standard h2 system functions.
CVE-2022-38492 1 Easyvista 1 Service Manager 2023-01-30 N/A 8.8 HIGH
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes the vulnerability.
CVE-2022-38490 1 Easyvista 1 Service Manager 2023-01-30 N/A 8.8 HIGH
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue.
CVE-2022-4230 1 Veronalabs 1 Wp Statistics 2023-01-30 N/A 8.8 HIGH
The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well.
CVE-2019-19740 1 Octeth 1 Oempro 2023-01-27 7.5 HIGH 9.8 CRITICAL
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
CVE-2020-13640 1 Gvectors 1 Wpdiscuz 2023-01-27 7.5 HIGH 9.8 CRITICAL
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)
CVE-2013-10014 1 2moons Project 1 2moons 2023-01-27 N/A 9.8 CRITICAL
A vulnerability classified as critical has been found in oktora24 2moons. Affected is an unknown function. The manipulation leads to sql injection. The name of the patch is 1b09cf7672eb85b5b0c8a4de321f7a4ad87b09a7. It is recommended to apply a patch to fix this issue. VDB-218898 is the identifier assigned to this vulnerability.
CVE-2015-10070 1 Twiddit Project 1 Twiddit 2023-01-27 N/A 9.8 CRITICAL
A vulnerability was found in copperwall Twiddit. It has been rated as critical. This issue affects some unknown processing of the file index.php. The manipulation leads to sql injection. The name of the patch is 2203d4ce9810bdaccece5c48ff4888658a01acfc. It is recommended to apply a patch to fix this issue. The identifier VDB-218897 was assigned to this vulnerability.