Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-7107 1 Hpe 1 Device Entitlement Gateway 2018-11-21 6.5 MEDIUM 8.8 HIGH
A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. The vulnerability could be remotely exploited to allow local SQL injection and elevation of privilege.
CVE-2018-18200 1 Redaxo 1 Redaxo 2018-11-21 7.5 HIGH 9.8 CRITICAL
There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4.
CVE-2018-18242 1 Youke365 1 Youke 365 2018-11-21 7.5 HIGH 9.8 CRITICAL
youke365 v1.1.5 has SQL injection via admin/login.html, as demonstrated by username=admin&pass=123456&code=9823&act=login&submit=%E7%99%BB+%E9%99%86.
CVE-2018-17566 1 Thinkphp 1 Thinkphp 2018-11-20 7.5 HIGH 9.8 CRITICAL
In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's request.
CVE-2018-17552 1 Naviwebs 1 Navigate Cms 2018-11-19 7.5 HIGH 9.8 CRITICAL
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie.
CVE-2018-17379 1 Thephpfactory 1 Raffle Factory 2018-11-15 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
CVE-2018-17380 1 Thephpfactory 1 Article Factory Manager 2018-11-15 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.
CVE-2018-17382 1 Thephpfactory 1 Jobs Factory 2018-11-15 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
CVE-2018-17383 1 Thephpfactory 1 Collection Factory 2018-11-15 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.
CVE-2018-17394 1 Osthemeclub 1 Timetable Schedule 2018-11-14 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.
CVE-2018-17391 1 Super Cms Blog Pro Project 1 Super Cms Blog Pro 2018-11-14 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.
CVE-2018-17385 1 Thephpfactory 1 Social Factory 2018-11-14 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.
CVE-2018-17397 1 Multiplanet 1 Alphaindex Dictionaries 2018-11-14 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.
CVE-2018-17377 1 Extensiondeveloper 1 Questions 2018-11-14 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
CVE-2018-17376 1 Thephpfactory 1 Reverse Auction Factory 2018-11-14 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.
CVE-2018-17384 1 Thephpfactory 1 Swap Factory 2018-11-14 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
CVE-2018-17378 1 Thephpfactory 1 Penny Auction Factory 2018-11-14 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.
CVE-2018-17375 1 Joomlathat 1 Music Collection 2018-11-14 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
CVE-2015-8298 1 Rxtec 1 Rxadmin 2018-11-13 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to execute arbitrary SQL commands via the (1) loginpassword, (2) loginusername, (3) zusatzlicher, or (4) groupid parameter to index.htm, or the (5) rxtec cookie to index.htm.
CVE-2018-15904 1 A10networks 1 Acos Web Application Firewall 2018-11-09 7.5 HIGH 9.8 CRITICAL
A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8, and 4.1.2 before 4.1.2-P4 mishandles the configured rules for blocking SQL injection attacks, aka A10-2017-0008.