Total
15512 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-7791 | 1 Welcart | 1 Welcart E-commerce | 2025-04-12 | 6.5 MEDIUM | 6.3 MEDIUM |
Multiple SQL injection vulnerabilities in admin.php in the Collne Welcart plugin before 1.5.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) search[column] or (2) switch parameter. | |||||
CVE-2016-8903 | 1 Dotcms | 1 Dotcms | 2025-04-12 | 6.5 MEDIUM | 8.8 HIGH |
SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter. | |||||
CVE-2012-6290 | 1 Imagecms | 1 Imagecms | 2025-04-12 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL commands via the q parameter to admin/admin_search/. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands. | |||||
CVE-2016-0233 | 1 Ibm | 1 Marketing Platform | 2025-04-12 | 6.5 MEDIUM | 8.8 HIGH |
SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2014-3906 | 1 Kk-osk | 2 Advance-flow, Advance-flow Forms | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in OSK Advance-Flow 4.41 and earlier and Advance-Flow Forms 4.41 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2014-5109 | 1 Netfortris | 1 Trixbox | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL commands via the mac parameter in a Submit action. | |||||
CVE-2014-8999 | 1 Xoops | 1 Xoops | 2025-04-12 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in htdocs/modules/system/admin.php in XOOPS before 2.5.7 Final allows remote authenticated users to execute arbitrary SQL commands via the selgroups parameter. | |||||
CVE-2014-2376 | 1 Ecava | 1 Integraxor | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2013-5640 | 1 Raoul Proenca | 1 Gnew | 2025-04-12 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) answer_id or (2) question_id parameter to polls/vote.php, (3) story_id parameter to comments/add.php or (4) comments/edit.php, or (5) thread_id parameter to posts/add.php. NOTE: this issue was SPLIT due to differences in researchers and disclosure dates. CVE-2013-7349 already covers the news_id parameter to news/send.php, user_email parameter to users/register.php, and thread_id to posts/edit.php vectors. | |||||
CVE-2014-10020 | 1 Tecorange | 1 Simple E-document | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |||||
CVE-2015-3993 | 1 Actian | 1 Matrix | 2025-04-12 | 6.5 MEDIUM | N/A |
Actian Matrix 5.1.x through 5.1.2.4 and 5.2.x through 5.2.0.1 allows remote authenticated users to bypass intended write-access restrictions and execute an UPDATE statement by referencing a table. | |||||
CVE-2015-2564 | 1 Projectsend | 1 Projectsend | 2025-04-12 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to users-edit.php. | |||||
CVE-2014-8248 | 1 Broadcom | 1 Release Automation | 2025-04-12 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote authenticated users to execute arbitrary SQL commands via a crafted query. | |||||
CVE-2015-1875 | 1 Palosanto | 1 Elastix | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in a2billing/customer/iridium_threed.php in Elastix 2.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the transactionID parameter. | |||||
CVE-2015-3345 | 1 Phplist Integration Project | 1 Phplist Integration | 2025-04-12 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the PHPlist Integration Module before 6.x-1.7 for Drupal allows remote administrators to execute arbitrary SQL commands via unspecified vectors, related to the "phpList database." | |||||
CVE-2016-1000123 | 1 Huge-it | 1 Video Gallery | 2025-04-12 | 7.5 HIGH | 9.8 CRITICAL |
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla | |||||
CVE-2015-4208 | 1 Cisco | 1 Webex Meeting Center | 2025-04-12 | 7.5 HIGH | N/A |
Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive information or conduct SQL injection attacks via vectors involving read access to a request, aka Bug ID CSCup88398. | |||||
CVE-2014-3138 | 1 Xerox | 1 Docushare | 2025-04-12 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in Xerox DocuShare before 6.53 Patch 6 Hotfix 2, 6.6.1 Update 1 before Hotfix 24, and 6.6.1 Update 2 before Hotfix 3 allows remote authenticated users to execute arbitrary SQL commands via the PATH_INFO to /docushare/dsweb/ResultBackgroundJobMultiple/. NOTE: some of these details are obtained from third party information. | |||||
CVE-2012-5648 | 1 Theforeman | 1 Foreman | 2025-04-12 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) app/models/hostext/search.rb or (2) app/models/puppetclass.rb, related to the search mechanism. | |||||
CVE-2016-5843 | 1 Otrs | 1 Faq | 2025-04-12 | 9.0 HIGH | 9.4 CRITICAL |
Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted search parameters. |