Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-38284 | 1 Jflyfox | 1 Jfinal Cms | 2022-09-13 | N/A | 7.2 HIGH |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/department/list. | |||||
CVE-2022-38282 | 1 Jflyfox | 1 Jfinal Cms | 2022-09-13 | N/A | 7.2 HIGH |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list. | |||||
CVE-2022-38283 | 1 Jflyfox | 1 Jfinal Cms | 2022-09-13 | N/A | 7.2 HIGH |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/video/list. | |||||
CVE-2022-38277 | 1 Jflyfox | 1 Jfinal Cms | 2022-09-13 | N/A | 7.2 HIGH |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list. | |||||
CVE-2022-38279 | 1 Jflyfox | 1 Jfinal Cms | 2022-09-13 | N/A | 7.2 HIGH |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list. | |||||
CVE-2022-38278 | 1 Jflyfox | 1 Jfinal Cms | 2022-09-13 | N/A | 7.2 HIGH |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list. | |||||
CVE-2022-38280 | 1 Jflyfox | 1 Jfinal Cms | 2022-09-13 | N/A | 7.2 HIGH |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list. | |||||
CVE-2022-38281 | 1 Jflyfox | 1 Jfinal Cms | 2022-09-13 | N/A | 7.2 HIGH |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list. | |||||
CVE-2022-38272 | 1 Jflyfox | 1 Jfinal Cms | 2022-09-13 | N/A | 7.2 HIGH |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list. | |||||
CVE-2022-38273 | 1 Jflyfox | 1 Jfinal Cms | 2022-09-13 | N/A | 7.2 HIGH |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve. | |||||
CVE-2022-38274 | 1 Jflyfox | 1 Jfinal Cms | 2022-09-13 | N/A | 7.2 HIGH |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list. | |||||
CVE-2022-38275 | 1 Jflyfox | 1 Jfinal Cms | 2022-09-13 | N/A | 7.2 HIGH |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list. | |||||
CVE-2022-38276 | 1 Jflyfox | 1 Jfinal Cms | 2022-09-13 | N/A | 7.2 HIGH |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list. | |||||
CVE-2022-2718 | 1 Beardev | 1 Joomsport | 2022-09-13 | N/A | 4.9 MEDIUM |
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-page-extrafields page in versions up to, and including, 5.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrative privileges, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | |||||
CVE-2022-2717 | 1 Beardev | 1 Joomsport | 2022-09-13 | N/A | 4.9 MEDIUM |
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-events-form page in versions up to, and including, 5.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrative privileges, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | |||||
CVE-2022-1807 | 1 Sophos | 1 Firewall | 2022-09-12 | N/A | 7.2 HIGH |
Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1. | |||||
CVE-2022-3130 | 1 Online Driving School Project Project | 1 Online Driving School Project | 2022-09-12 | N/A | 9.8 CRITICAL |
A vulnerability classified as critical has been found in codeprojects Online Driving School. This affects an unknown part of the file /login.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-207873 was assigned to this vulnerability. | |||||
CVE-2019-5114 | 1 Youphptube | 1 Youphptube | 2022-09-09 | 9.3 HIGH | 9.9 CRITICAL |
An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and,in certain configuration, access the underlying operating system. | |||||
CVE-2021-43481 | 1 Webtareas Project | 1 Webtareas | 2022-09-09 | 7.5 HIGH | 9.8 CRITICAL |
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php. | |||||
CVE-2022-27927 | 1 Microfinance Management System Project | 1 Microfinance Management System | 2022-09-09 | 7.5 HIGH | 9.8 CRITICAL |
A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter. |