Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-15989 | 1 Online Exam Test Application Project | 1 Online Exam Test Application | 2017-11-17 | 7.5 HIGH | 9.8 CRITICAL |
Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action. | |||||
CVE-2017-15978 | 1 Arox | 1 School Erp Php Script | 2017-11-17 | 7.5 HIGH | 9.8 CRITICAL |
AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter. | |||||
CVE-2017-15977 | 1 Protectedlinks | 1 Expiring Download Links | 2017-11-17 | 7.5 HIGH | 9.8 CRITICAL |
Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter. | |||||
CVE-2017-15992 | 1 Website Broker Script Project | 1 Website Broker Script | 2017-11-17 | 7.5 HIGH | 9.8 CRITICAL |
Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php. | |||||
CVE-2017-15993 | 1 Zomato Clone Script Project | 1 Zomato Clone Script | 2017-11-17 | 7.5 HIGH | 9.8 CRITICAL |
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter. | |||||
CVE-2017-15967 | 1 Mailing-manager | 1 Mailing List Manager Pro | 2017-11-17 | 7.5 HIGH | 9.8 CRITICAL |
Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template. | |||||
CVE-2017-15966 | 1 Zh Yandexmap Project | 1 Zh Yandexmap | 2017-11-17 | 7.5 HIGH | 9.8 CRITICAL |
The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php. | |||||
CVE-2017-15965 | 1 Nswd | 1 Ns Download Shop | 2017-11-17 | 7.5 HIGH | 9.8 CRITICAL |
The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action. | |||||
CVE-2017-15968 | 1 Contractorscripts | 1 Mybuildersite | 2017-11-16 | 7.5 HIGH | 9.8 CRITICAL |
MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter. | |||||
CVE-2017-15969 | 1 Pilotgroup | 1 Allsharevideo | 2017-11-16 | 7.5 HIGH | 9.8 CRITICAL |
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category. | |||||
CVE-2017-15970 | 1 Phpcityportal | 1 Phpcityportal | 2017-11-16 | 7.5 HIGH | 9.8 CRITICAL |
PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter. | |||||
CVE-2017-15963 | 1 Itechscripts | 1 Gigs Script | 2017-11-16 | 7.5 HIGH | 9.8 CRITICAL |
iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter. | |||||
CVE-2008-3604 | 1 Zeescripts | 1 Zeebuddy | 2017-11-16 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in bannerclick.php in ZeeBuddy 2.1 allows remote attackers to execute arbitrary SQL commands via the adid parameter. | |||||
CVE-2017-15959 | 1 Adultscriptpro | 1 Adultscriptpro | 2017-11-16 | 7.5 HIGH | 9.8 CRITICAL |
Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-2007-6576. | |||||
CVE-2017-15974 | 1 Datacomponents | 1 Tpanel | 2017-11-16 | 7.5 HIGH | 9.8 CRITICAL |
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php. | |||||
CVE-2017-15973 | 1 Sokial | 1 Sokial | 2017-11-16 | 7.5 HIGH | 9.8 CRITICAL |
Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php. | |||||
CVE-2017-15972 | 1 Softdatepro | 1 Dating Software | 2017-11-16 | 7.5 HIGH | 9.8 CRITICAL |
SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15971. | |||||
CVE-2013-0140 | 1 Mcafee | 1 Epolicy Orchestrator | 2017-11-15 | 7.9 HIGH | N/A |
SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to execute arbitrary SQL commands via a crafted request over the Agent-Server communication channel. | |||||
CVE-2012-4570 | 1 Letodms Project | 1 Letodms | 2017-11-15 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2014-2023 | 1 Tapatalk | 1 Tapatalk | 2017-11-15 | 7.5 HIGH | 9.8 CRITICAL |
Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2) unsubscribe_topic.php in mobiquo/functions/. |