Vulnerabilities (CVE)

Filtered by CWE-89
Total 14188 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-32099 1 Artica 1 Pandora Fms 2021-05-11 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.
CVE-2021-32104 1 Open-emr 1 Openemr 2021-05-11 6.5 MEDIUM 8.8 HIGH
A SQL injection vulnerability exists (with user privileges) in interface/forms/eye_mag/save.php in OpenEMR 5.0.2.1.
CVE-2021-32102 1 Open-emr 1 Openemr 2021-05-11 6.5 MEDIUM 8.8 HIGH
A SQL injection vulnerability exists (with user privileges) in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1.
CVE-2020-15153 1 Ampache 1 Ampache 2021-05-09 7.5 HIGH 9.8 CRITICAL
Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch.
CVE-2020-19108 1 Projectworlds 1 Online Book Store Project In Php 2021-05-07 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user execute arbitrary code.
CVE-2020-19109 1 Projectworlds 1 Online Book Store Project In Php 2021-05-07 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a remote malicious user execute arbitrary code.
CVE-2020-19107 1 Projectworlds 1 Online Book Store Project In Php 2021-05-07 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote malicious user execute arbitrary code.
CVE-2020-19114 1 Projectworlds 1 Online Book Store Project In Php 2021-05-07 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to edit_book.php, which could let a remote malicious user execute arbitrary code.
CVE-2020-19112 1 Projectworlds 1 Online Book Store Project In Php 2021-05-07 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a remote malicious user execute arbitrary code.
CVE-2020-19110 1 Projectworlds 1 Online Book Store Project In Php 2021-05-07 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let a remote malicious user execute arbitrary code.
CVE-2021-31856 1 Layer5 1 Meshery 2021-05-06 7.5 HIGH 9.8 CRITICAL
A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/meshery_pattern_persister.go).
CVE-2021-25153 1 Arubanetworks 1 Airwave 2021-05-05 5.5 MEDIUM 8.1 HIGH
A remote SQL injection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
CVE-2020-18020 1 Phpshe 1 Mall System 2021-05-05 7.5 HIGH 9.8 CRITICAL
SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafted HTTP request to the "admin.php" component.
CVE-2020-18019 1 Xinfu 1 Oa System 2021-05-05 5.0 MEDIUM 7.5 HIGH
SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary commands into the "typeid" variable of the "createfolderAjax" function in the "mode_worcAction.php" component.
CVE-2020-22781 1 Etherpad 1 Etherpad 2021-05-05 5.0 MEDIUM 7.5 HIGH
In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash the instance).
CVE-2020-15160 1 Prestashop 1 Prestashop 2021-05-05 7.5 HIGH 9.8 CRITICAL
PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with location parameter. The problem is fixed in 1.7.6.8
CVE-2018-20338 1 Zohocorp 1 Manageengine Opmanager 2021-05-04 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section.
CVE-2018-18949 1 Zohocorp 1 Manageengine Opmanager 2021-05-04 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.
CVE-2018-20173 1 Zohocorp 1 Manageengine Opmanager 2021-05-04 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.
CVE-2019-17602 1 Zohocorp 1 Manageengine Opmanager 2021-05-04 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.