Vulnerabilities (CVE)

Filtered by CWE-89
Total 14648 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-11471 1 Idera 1 Uptime Infrastructure Monitor 2025-04-20 7.5 HIGH 9.8 CRITICAL
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter.
CVE-2017-17582 1 Grubhub Clone Project 1 Grubhub Clone 2025-04-20 7.5 HIGH 9.8 CRITICAL
FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.
CVE-2017-17645 1 Phpautoclassifiedscript 1 Bus Booking Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
CVE-2017-15969 1 Pilotgroup 1 Allsharevideo 2025-04-20 7.5 HIGH 9.8 CRITICAL
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category.
CVE-2017-16510 1 Wordpress 1 Wordpress 2025-04-20 7.5 HIGH 9.8 CRITICAL
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
CVE-2017-15980 1 Rowindex 1 Us Zip Codes Database Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter.
CVE-2015-3934 1 Fiyo 1 Fiyo Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user parameter to user/login.
CVE-2017-17631 1 Multireligion Responsive Matrimonial Project 1 Multireligion Responsive Matrimonial 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
CVE-2017-14601 1 Pragyan Cms Project 1 Pragyan Cms 2025-04-20 4.0 MEDIUM 4.9 MEDIUM
Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information Disclosure.
CVE-2017-5346 1 Genixcms 1 Genixcms 2025-04-20 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.
CVE-2017-17730 1 Dedecms 1 Dedecms 2025-04-20 7.5 HIGH 9.8 CRITICAL
DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.
CVE-2016-7508 1 Glpi-project 1 Glpi 2025-04-20 6.0 MEDIUM 7.5 HIGH
Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a certain character when the database is configured to use Big5 Asian encoding.
CVE-2017-17588 1 Imdb Clone Project 1 Imdb Clone 2025-04-20 7.5 HIGH 9.8 CRITICAL
FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter.
CVE-2017-7581 1 News System Project 1 News System 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.
CVE-2017-14507 1 Shindiristudio 1 Content Timeline 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timeline_edit.php or (3) pages/content_timeline_index.php.
CVE-2016-8025 1 Mcafee 1 Virusscan Enterprise 2025-04-20 6.0 MEDIUM 6.2 MEDIUM
SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to obtain product information via a crafted HTTP request parameter.
CVE-2017-15539 1 Zorovavi\/blog Project 1 Zorovavi\/blog 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in zorovavi/blog through 2017-10-17 via the id parameter to recept.php.
CVE-2017-15985 1 Readymadeb2bscript 1 Basic B2b Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.
CVE-2017-17594 1 Domainsale Php Script Project 1 Domainsale Php Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.
CVE-2017-6050 1 Ecava 1 Integraxor 2025-04-20 7.5 HIGH 9.8 CRITICAL
A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow for an unauthenticated attacker to remotely execute arbitrary code in the form of SQL queries.