Total
14648 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-11471 | 1 Idera | 1 Uptime Infrastructure Monitor | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter. | |||||
CVE-2017-17582 | 1 Grubhub Clone Project | 1 Grubhub Clone | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter. | |||||
CVE-2017-17645 | 1 Phpautoclassifiedscript | 1 Bus Booking Script | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php. | |||||
CVE-2017-15969 | 1 Pilotgroup | 1 Allsharevideo | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category. | |||||
CVE-2017-16510 | 1 Wordpress | 1 Wordpress | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723. | |||||
CVE-2017-15980 | 1 Rowindex | 1 Us Zip Codes Database Script | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter. | |||||
CVE-2015-3934 | 1 Fiyo | 1 Fiyo Cms | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user parameter to user/login. | |||||
CVE-2017-17631 | 1 Multireligion Responsive Matrimonial Project | 1 Multireligion Responsive Matrimonial | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter. | |||||
CVE-2017-14601 | 1 Pragyan Cms Project | 1 Pragyan Cms | 2025-04-20 | 4.0 MEDIUM | 4.9 MEDIUM |
Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information Disclosure. | |||||
CVE-2017-5346 | 1 Genixcms | 1 Genixcms | 2025-04-20 | 6.5 MEDIUM | 7.2 HIGH |
SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php. | |||||
CVE-2017-17730 | 1 Dedecms | 1 Dedecms | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php. | |||||
CVE-2016-7508 | 1 Glpi-project | 1 Glpi | 2025-04-20 | 6.0 MEDIUM | 7.5 HIGH |
Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a certain character when the database is configured to use Big5 Asian encoding. | |||||
CVE-2017-17588 | 1 Imdb Clone Project | 1 Imdb Clone | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter. | |||||
CVE-2017-7581 | 1 News System Project | 1 News System | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed. | |||||
CVE-2017-14507 | 1 Shindiristudio | 1 Content Timeline | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timeline_edit.php or (3) pages/content_timeline_index.php. | |||||
CVE-2016-8025 | 1 Mcafee | 1 Virusscan Enterprise | 2025-04-20 | 6.0 MEDIUM | 6.2 MEDIUM |
SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to obtain product information via a crafted HTTP request parameter. | |||||
CVE-2017-15539 | 1 Zorovavi\/blog Project | 1 Zorovavi\/blog | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection exists in zorovavi/blog through 2017-10-17 via the id parameter to recept.php. | |||||
CVE-2017-15985 | 1 Readymadeb2bscript | 1 Basic B2b Script | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter. | |||||
CVE-2017-17594 | 1 Domainsale Php Script Project | 1 Domainsale Php Script | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter. | |||||
CVE-2017-6050 | 1 Ecava | 1 Integraxor | 2025-04-20 | 7.5 HIGH | 9.8 CRITICAL |
A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow for an unauthenticated attacker to remotely execute arbitrary code in the form of SQL queries. |