Total
14188 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-0894 | 1 Tips And Tricks Hq | 1 All In One Wordpress Security And Firewall | 2015-03-09 | 6.0 MEDIUM | N/A |
SQL injection vulnerability in the All In One WP Security & Firewall plugin before 3.8.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-2199 | 1 Wonderplugin | 1 Audio Player | 2015-03-04 | 6.5 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote authenticated users to execute arbitrary SQL commands via the item[id] parameter in a wonderplugin_audio_save_item action to wp-admin/admin-ajax.php or remote administrators to execute arbitrary SQL commands via the itemid parameter in the (2) wonderplugin_audio_show_item, (3) wonderplugin_audio_show_items, or (4) wonderplugin_audio_edit_item page to wp-admin/admin.php. | |||||
CVE-2015-2196 | 1 Web-dorado | 1 Spider Calendar | 2015-03-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php. | |||||
CVE-2015-1605 | 1 Dell | 1 Asset Manager | 2015-02-25 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Dell ScriptLogic Asset Manager (aka Quest Workspace Asset Manager) before 9.5 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to (1) GetClientPackage.aspx or (2) GetProcessedPackage.aspx. | |||||
CVE-2015-1616 | 1 Mcafee | 1 Data Loss Prevention Endpoint | 2015-02-18 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated ePO users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-1471 | 1 Pragyan Cms Project | 1 Pragyan Cms | 2015-02-13 | 7.5 HIGH | N/A |
SQL injection vulnerability in userprofile.lib.php in Pragyan CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to the default URI. | |||||
CVE-2015-1576 | 1 Yuba | 1 U5cms | 2015-02-12 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands via the name parameter to (1) copy2.php, (2) localize.php, (3) metai.php, (4) nc.php, (5) new2.php, or (6) rename2.php in u5admin/; (7) c parameter to u5admin/editor.php; (8) typ parameter to u5admin/meta2.php; or (9) newname parameter to u5admin/rename2.php. | |||||
CVE-2015-1442 | 1 Aas9 | 1 Zerocms | 2015-02-09 | 7.5 HIGH | N/A |
SQL injection vulnerability in views/zero_transact_user.php in the administrative backend in ZeroCMS 1.3.3, 1.3.2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the user_id parameter in a Modify Account action. NOTE: The article_id parameter to zero_view_article.php vector is already covered by CVE-2014-4034. | |||||
CVE-2015-1479 | 1 Zohocorp | 1 Servicedesk Plus | 2015-02-06 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to execute arbitrary SQL commands via the site parameter. | |||||
CVE-2015-1477 | 1 Cmsjunkie | 1 J-classifiedsmanager | 2015-02-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewad task to classifieds/offerring-ads. | |||||
CVE-2015-1476 | 1 Ecommercemajor Project | 1 Ecommercemajor | 2015-02-04 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in xlinkerz ecommerceMajor allow remote attackers to execute arbitrary SQL commands via the (1) productbycat parameter to product.php, or (2) username or (3) password parameter to __admin/index.php. | |||||
CVE-2015-1441 | 1 Piwigo | 1 Piwigo | 2015-02-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in Piwigo before 2.5.6, 2.6.x before 2.6.5, and 2.7.x before 2.7.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-1400 | 1 Npds | 1 Revolution | 2015-02-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in search.php in NPDS Revolution 13 allows remote attackers to execute arbitrary SQL commands via the query parameter. | |||||
CVE-2015-1450 | 1 Restaurantbiller | 1 Restaurant Biller | 2015-02-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in Restaurant Biller allows remote attackers to execute arbitrary SQL commands via the cid parameter in a category action to index.php. | |||||
CVE-2015-1403 | 1 Content Rating Project | 1 Content Rating | 2015-02-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Content Rating extension 1.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-1405 | 1 Content Rating Extbase Project | 1 Content Rating Extbase | 2015-02-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Content Rating Extbase extension 2.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-1369 | 1 Sequelize Project | 1 Sequelize | 2015-01-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in Sequelize before 2.0.0-rc7 for Node.js allows remote attackers to execute arbitrary SQL commands via the order parameter. | |||||
CVE-2015-1364 | 1 Freereprintables | 1 Articlefr | 2015-01-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in the getProfile function in system/profile.functions.php in Free Reprintables ArticleFR 3.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter to register/. | |||||
CVE-2015-1372 | 1 Ferretcms Project | 1 Ferretcms | 2015-01-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in ferretCMS 1.0.4-alpha allows remote attackers to execute arbitrary SQL commands via the p parameter in an update action to admin.php. | |||||
CVE-2014-2081 | 1 Iii | 1 Vtls-virtua | 2015-01-26 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua before 2013.2.4 and 2014.x before 2014.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. |