Total
14188 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-28970 | 1 Fireeye | 2 Email Malware Protection System, Ex 3500 | 2021-04-07 | 4.0 MEDIUM | 6.5 MEDIUM |
eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the job_id parameter to the email search feature. According to the vendor, the issue is fixed in 9.0.3. | |||||
CVE-2012-1255 | 1 Segue Project | 1 Segue | 2021-04-06 | 7.5 HIGH | N/A |
SQL injection vulnerability in Segue 2.2.10.2 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2021-29343 | 1 Ovidentia | 1 Ovidentia | 2021-04-05 | 5.5 MEDIUM | 5.4 MEDIUM |
Ovidentia CMS 6.x contains a SQL injection vulnerability in the "id" parameter of index.php. The "checkbox" property into "text" data can be extracted and displayed in the text region or in source code. | |||||
CVE-2021-28245 | 1 Pbootcms | 1 Pbootcms | 2021-04-05 | 5.0 MEDIUM | 7.5 HIGH |
PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account. | |||||
CVE-2020-28172 | 1 Simple College Project | 1 Simple College | 2021-04-02 | 7.5 HIGH | 9.8 CRITICAL |
A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin authentication mechanism in college_website/admin/ajax.php?action=login, thus gaining access to the website administrative panel. | |||||
CVE-2021-28668 | 1 Xerox | 20 Altalink B8045, Altalink B8045 Firmware, Altalink B8055 and 17 more | 2021-04-01 | 7.5 HIGH | 9.8 CRITICAL |
Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 has several SQL injection vulnerabilities. | |||||
CVE-2015-7299 | 1 Nintex | 3 K2 Blackpearl, K2 For Sharepoint, K2 Smartforms | 2021-03-31 | 7.5 HIGH | N/A |
SQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote attackers to execute arbitrary SQL commands via the xml parameter. | |||||
CVE-2011-4710 | 2 Getpixie, Lucidcrew | 2 Pixie, Pixie | 2021-03-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI. | |||||
CVE-2020-10582 | 1 Invigo | 1 Automatic Device Management | 2021-03-27 | 7.5 HIGH | 9.8 CRITICAL |
A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database. | |||||
CVE-2020-27869 | 1 Solarwinds | 1 Network Performance Monitor | 2021-03-26 | 9.0 HIGH | 8.8 HIGH |
This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: 2020.2. Authentication is required to exploit this vulnerability. The specific flaw exists within the WriteToFile method. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges and reset the password for the Admin user. Was ZDI-CAN-11804. | |||||
CVE-2021-26578 | 1 Hpe | 1 Network Orchestrator | 2021-03-25 | 5.0 MEDIUM | 7.5 HIGH |
A potential security vulnerability has been identified in HPE Network Orchestrator (NetO) version(s): Prior to 2.5. The vulnerability could be remotely exploited with SQL injection. | |||||
CVE-2010-4400 | 1 Dynpg | 1 Dynpg | 2021-03-25 | 7.5 HIGH | N/A |
SQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote attackers to execute arbitrary SQL commands via the giveRights_UserId parameter. | |||||
CVE-2020-6577 | 1 It-recht-kanzlei | 1 It-recht-kanzlei | 2021-03-25 | 7.5 HIGH | 9.8 CRITICAL |
The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection. | |||||
CVE-2020-35337 | 1 Thinksaas | 1 Thinksaas | 2021-03-24 | 7.5 HIGH | 9.8 CRITICAL |
ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows remote attackers to execute arbitrary SQL commands. | |||||
CVE-2021-24131 | 1 Cleantalk | 1 Anti-spam | 2021-03-24 | 6.5 MEDIUM | 7.2 HIGH |
Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+). | |||||
CVE-2021-24132 | 1 10web | 1 Slider | 2021-03-24 | 6.5 MEDIUM | 8.8 HIGH |
The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" is turn on for other users) to perform a SQL Injection attacks. | |||||
CVE-2021-27320 | 1 Doctor Appointment System Project | 1 Doctor Appointment System | 2021-03-24 | 5.0 MEDIUM | 7.5 HIGH |
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter. | |||||
CVE-2021-27319 | 1 Doctor Appointment System Project | 1 Doctor Appointment System | 2021-03-24 | 5.0 MEDIUM | 7.5 HIGH |
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter. | |||||
CVE-2021-27316 | 1 Doctor Appointment System Project | 1 Doctor Appointment System | 2021-03-24 | 5.0 MEDIUM | 7.5 HIGH |
Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter. | |||||
CVE-2021-27315 | 1 Doctor Appointment System Project | 1 Doctor Appointment System | 2021-03-24 | 5.0 MEDIUM | 7.5 HIGH |
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter. |