Vulnerabilities (CVE)

Filtered by CWE-89
Total 15470 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-5347 1 Metalgenix 1 Genixcms 2025-04-20 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in inc/mod/newsletter/options.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the recipient parameter to gxadmin/index.php.
CVE-2017-16846 1 Zohocorp 1 Manageengine Applications Manager 2025-04-20 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.
CVE-2017-12276 1 Cisco 1 Prime Collaboration Provisioning 2025-04-20 5.5 MEDIUM 8.1 HIGH
A vulnerability in the web framework code for the SQL database interface of the Cisco Prime Collaboration Provisioning application could allow an authenticated, remote attacker to impact the confidentiality and integrity of the application by executing arbitrary SQL queries, aka SQL Injection. The attacker could read or write information from the SQL database. The vulnerability is due to a lack of proper validation on user-supplied input within SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected application. An exploit could allow the attacker to determine the presence of certain values and write malicious input in the SQL database. The attacker would need to have valid user credentials. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases prior to 12.3. Cisco Bug IDs: CSCvf47935.
CVE-2017-2241 2 Apple, Hammock 2 Mac Os X, Assetview 2025-04-20 6.5 MEDIUM 6.3 MEDIUM
SQL injection vulnerability in the AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to execute arbitrary SQL commands via "File Transfer Web Service".
CVE-2017-17619 1 Laundry Booking Script Project 1 Laundry Booking Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-12946 1 Easymodal Project 1 Easy Modal 2025-04-20 6.5 MEDIUM 7.2 HIGH
classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in a delete action with the id, ids, or modal parameter to wp-admin/admin.php, exploitable by administrators.
CVE-2016-10509 1 Opencart 1 Opencart 2025-04-20 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 allows remote authenticated administrators to execute arbitrary SQL commands via a carrier (aka courier_id) parameter to openbay.php.
CVE-2017-15972 1 Softdatepro 1 Dating Software 2025-04-20 7.5 HIGH 9.8 CRITICAL
SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15971.
CVE-2015-5052 1 Sefrengo 1 Sefrengo 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Sefrengo before 1.6.5 beta2.
CVE-2017-17598 1 Affiliate Mlm Script Project 1 Affiliate Mlm Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.
CVE-2017-17605 1 Consumer Complaints Clone Script Project 1 Consumer Complaints Clone Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
CVE-2016-6818 1 Sap 1 Business Intelligence Platform 2025-04-20 10.0 HIGH 9.8 CRITICAL
SQL injection vulnerability in SAP Business Intelligence platform before January 2017 allows remote attackers to obtain sensitive information, modify data, cause a denial of service (data deletion), or launch administrative operations or possibly OS commands via a crafted SQL query. The vendor response is SAP Security Note 2361633.
CVE-2015-4724 1 Concretecms 1 Concrete Cms 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in Concrete5 5.7.3.1.
CVE-2017-13669 1 Nexusphp 1 Nexusphp 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php.
CVE-2017-16561 1 Ingenious School Management System Project 1 Ingenious School Management System 2025-04-20 7.5 HIGH 9.8 CRITICAL
/view/friend_profile.php in Ingenious School Management System 2.3.0 is vulnerable to Boolean-based and Time-based SQL injection in the 'friend_index' parameter of a GET request.
CVE-2017-17603 1 Advanced Real Estate Script Project 1 Advanced Real Estate Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter.
CVE-2017-10899 1 Ark-web 1 A-reserve 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-7719 1 Web-dorado 1 Spider Event Calendar 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php.
CVE-2017-6492 1 Admidio 1 Admidio 2025-04-20 9.0 HIGH 7.2 HIGH
SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization.
CVE-2017-11324 1 Tilde Cms Project 1 Tilde Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Tilde CMS 1.0.1. Due to missing escaping of the backtick character, a SELECT query in class.SystemAction.php is vulnerable to SQL Injection. The vulnerability can be triggered via a POST request to /actionphp/action.input.php with the id parameter.