Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-14592 | 1 Cwjoomla | 2 Cw Article Attachments Free, Cw Article Attachments Pro | 2018-11-09 | 7.5 HIGH | 9.8 CRITICAL |
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php. | |||||
CVE-2018-17129 | 1 Metinfo | 1 Metinfo | 2018-11-09 | 4.0 MEDIUM | 4.9 MEDIUM |
MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field. | |||||
CVE-2018-17110 | 1 Tecdiary | 1 Simple Pos | 2018-11-09 | 7.5 HIGH | 9.8 CRITICAL |
Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1. | |||||
CVE-2008-6124 | 2 Debian, Moodle | 2 Debian Linux, Moodle | 2018-11-08 | 7.5 HIGH | N/A |
SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers to execute arbitrary SQL commands via a crafted selected attempt. | |||||
CVE-2018-16822 | 1 Seacms | 1 Seacms | 2018-11-07 | 7.5 HIGH | 9.8 CRITICAL |
SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter. | |||||
CVE-2018-17035 | 1 Ucms Project | 1 Ucms | 2018-11-07 | 7.5 HIGH | 9.8 CRITICAL |
UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter. | |||||
CVE-2018-16436 | 1 Gxlcms | 1 Gxlcms | 2018-11-05 | 6.5 MEDIUM | 7.2 HIGH |
Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator. | |||||
CVE-2018-16389 | 1 E107 | 1 E107 | 2018-11-02 | 5.5 MEDIUM | 6.5 MEDIUM |
e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter. | |||||
CVE-2018-17136 | 1 Zzcms | 1 Zzcms | 2018-11-01 | 7.5 HIGH | 9.8 CRITICAL |
zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header. | |||||
CVE-2014-6045 | 1 Phpmyfaq | 1 Phpmyfaq | 2018-10-31 | 6.5 MEDIUM | 7.2 HIGH |
SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via vectors involving the restore function. | |||||
CVE-2018-16385 | 1 Thinkphp | 1 Thinkphp | 2018-10-31 | 7.5 HIGH | 9.8 CRITICAL |
ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string. | |||||
CVE-2008-3129 | 1 Catviz | 1 Catviz | 2018-10-30 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL commands via the (1) foreign_key_value parameter in the news page and (2) webpage parameter in the webpage_multi_edit form. | |||||
CVE-2012-2109 | 2 Buddypress, Wordpress | 2 Buddypress, Wordpress | 2018-10-30 | 7.5 HIGH | N/A |
SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL commands via the page parameter in an activity_widget_filter action. | |||||
CVE-2014-9220 | 3 Fedoraproject, Opensuse, Openvas | 3 Fedora, Opensuse, Openvas Manager | 2018-10-30 | 7.5 HIGH | N/A |
SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_schedule OMP command. | |||||
CVE-2016-5703 | 2 Opensuse, Phpmyadmin | 3 Leap, Opensuse, Phpmyadmin | 2018-10-30 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column query. | |||||
CVE-2013-5589 | 3 Cacti, Debian, Opensuse | 3 Cacti, Debian Linux, Opensuse | 2018-10-30 | 7.5 HIGH | N/A |
SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2014-8810 | 1 Wpsymposiumpro | 1 Wp Symposium | 2018-10-30 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tray parameter in a getMailMessage action. | |||||
CVE-2014-1636 | 1 Doug Poulin | 1 Command School Student Management System | 2018-10-30 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to execute arbitrary SQL commands via the id parameter in an edit action to (1) admin_school_names.php, (2) admin_subjects.php, (3) admin_grades.php, (4) admin_terms.php, (5) admin_school_years.php, (6) admin_sgrades.php, (7) admin_media_codes_1.php, (8) admin_infraction_codes.php, (9) admin_generations.php, (10) admin_relations.php, (11) admin_titles.php, or (12) health_allergies.php in sw/. | |||||
CVE-2013-7149 | 2 Openx, Revive-adserver | 2 Openx, Revive Adserver | 2018-10-30 | 7.5 HIGH | N/A |
SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method. | |||||
CVE-2013-5091 | 1 Vtiger | 1 Vtiger Crm | 2018-10-30 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php. NOTE: this issue might be a duplicate of CVE-2011-4559. |