Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-5971 | 1 Newsbee Project | 1 Newsbee | 2018-02-01 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in NewsBee CMS allow remote attackers to execute arbitrary SQL commands. | |||||
CVE-2018-5695 | 1 Wpjobboard | 1 Wpjobboard | 2018-02-01 | 6.5 MEDIUM | 7.2 HIGH |
The WpJobBoard plugin 4.4.4 for WordPress allows SQL injection via the order or sort parameter to the wpjb-job or wpjb-alerts module, with a request to wp-admin/admin.php. | |||||
CVE-2018-5697 | 1 Icyphoenix | 1 Icyphoenix | 2018-02-01 | 6.5 MEDIUM | 7.2 HIGH |
Icy Phoenix 2.2.0.105 allows SQL injection via an unapprove request to admin_kb_art.php or the order parameter to admin_jr_admin.php, related to functions_kb.php. | |||||
CVE-2017-17970 | 1 Muvikoscript | 1 Muviko | 2018-01-31 | 7.5 HIGH | 9.8 CRITICAL |
Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to login.php; the (2) season_id parameter to themes/flixer/ajax/load_season.php; the (3) movie_id parameter to themes/flixer/ajax/get_rating.php; the (4) rating or (5) movie_id parameter to themes/flixer/ajax/update_rating.php; or the (6) id parameter to themes/flixer/ajax/set_player_source.php. | |||||
CVE-2017-1670 | 1 Ibm | 1 Security Key Lifecycle Manager | 2018-01-31 | 7.5 HIGH | 9.8 CRITICAL |
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 133637. | |||||
CVE-2018-5211 | 1 Phpsugar | 1 Php Melody | 2018-01-31 | 7.5 HIGH | 9.8 CRITICAL |
PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist. | |||||
CVE-2018-5315 | 1 Wp Events Calendar Project | 1 Wp Events Calendar | 2018-01-29 | 7.5 HIGH | 9.8 CRITICAL |
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php. | |||||
CVE-2018-5374 | 1 Slidervilla | 1 Dbox Slider | 2018-01-24 | 6.5 MEDIUM | 8.8 HIGH |
The Dbox 3D Slider Lite plugin through 1.2.2 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter). | |||||
CVE-2018-5373 | 1 Slidervilla | 1 Smooth Slider | 2018-01-24 | 6.5 MEDIUM | 8.8 HIGH |
The Smooth Slider plugin through 2.8.6 for WordPress has SQL Injection via smooth-slider.php (trid parameter). | |||||
CVE-2018-5372 | 1 Slidervilla | 1 Testimonial Slider | 2018-01-24 | 6.5 MEDIUM | 8.8 HIGH |
The Testimonial Slider plugin through 1.2.4 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter). | |||||
CVE-2015-9249 | 1 Skyboxsecurity | 1 Skybox Platform | 2018-01-24 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in Skybox Platform before 7.5.201. SQL Injection exists in /skyboxview/webservice/services/VersionWebService via a soapenv:Body element. | |||||
CVE-2012-0805 | 1 Sqlalchemy | 1 Sqlalchemy | 2018-01-17 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function. | |||||
CVE-2017-14960 | 1 Opentext | 1 Document Sciences Xpression | 2018-01-17 | 5.0 MEDIUM | 7.5 HIGH |
xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection. | |||||
CVE-2014-4914 | 2 Debian, Zend | 2 Debian Linux, Zend Framework | 2018-01-17 | 7.5 HIGH | 9.8 CRITICAL |
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors. | |||||
CVE-2017-17875 | 1 Jextn | 1 Jextn Faq Pro | 2018-01-17 | 7.5 HIGH | 9.8 CRITICAL |
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action. | |||||
CVE-2017-17872 | 1 Jextn | 1 Jextn Video Gallery | 2018-01-17 | 7.5 HIGH | 9.8 CRITICAL |
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action. | |||||
CVE-2018-3811 | 1 Oturia | 1 Smart Google Code Inserter | 2018-01-16 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL queries in the context of the web server. The saveGoogleAdWords() function in smartgooglecode.php did not use prepared statements and did not sanitize the $_POST["oId"] variable before passing it as input into the SQL query. | |||||
CVE-2017-5663 | 1 Apache | 1 Fineract | 2018-01-12 | 6.5 MEDIUM | 8.8 HIGH |
In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious SQL into SELECT queries. The 'sqlSearch' parameter on a number of endpoints is not sanitized and appended directly to the query. | |||||
CVE-2017-1000444 | 1 Openhacker Project | 1 Openhacker | 2018-01-11 | 7.5 HIGH | 9.8 CRITICAL |
Eleix Openhacker version 0.1.47 is vulnerable to an SQL injection in the account registration and login component resulting in information disclosure and remote code execution | |||||
CVE-2015-3637 | 1 Phpmybackuppro | 1 Phpmybackuppro | 2018-01-11 | 6.8 MEDIUM | 8.1 HIGH |
SQL injection vulnerability in phpMyBackupPro when run in multi-user mode before 2.5 allows remote attackers to execute arbitrary SQL commands via the username and password parameters. |