Total
14683 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-13978 | 1 Ovidentia | 1 Ovidentia | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
Ovidentia 8.4.3 has SQL Injection via the id parameter in an index.php?tg=delegat&idx=mem request. | |||||
CVE-2019-13969 | 1 Metinfo | 1 Metinfo | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
Metinfo 6.x allows SQL Injection via the id parameter in an admin/index.php?n=ui_set&m=admin&c=index&a=doget_text_content&table=lang&field=1 request. | |||||
CVE-2019-13957 | 1 Umbraco | 1 Umbraco | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
In Umbraco 7.3.8, there is SQL Injection in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the nodeName parameter. | |||||
CVE-2019-13578 | 1 Givewp | 1 Givewp | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/payments/class-payments-query.php. | |||||
CVE-2019-13575 | 1 Wpeverest | 1 Everest Forms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php | |||||
CVE-2019-13573 | 1 Foliovision | 1 Fv Flowplayer Video Player | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. | |||||
CVE-2019-13572 | 1 Adenion | 1 Blog2social | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection. | |||||
CVE-2019-13571 | 1 Vsourz | 1 Advanced Cf7 Db | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. | |||||
CVE-2019-13570 | 1 Ajdg | 1 Adrotate | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection. | |||||
CVE-2019-13569 | 1 Icegram | 1 Email Subscribers \& Newsletters | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. | |||||
CVE-2019-13507 | 1 Hidea | 1 Az Admin | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection. | |||||
CVE-2019-13489 | 1 Trape Project | 1 Trape | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Trape through 2019-05-08 has SQL injection via the data[2] variable in core/db.py, as demonstrated by the /bs t parameter. | |||||
CVE-2019-13462 | 1 Lansweeper | 1 Lansweeper | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
Lansweeper before 7.1.117.4 allows unauthenticated SQL injection. | |||||
CVE-2019-13447 | 1 Sertek | 1 Xpare | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious agent could access the backend database via SQL injection. | |||||
CVE-2019-13413 | 1 Boiteasite | 1 Rencontre | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Rencontre plugin before 3.1.3 for WordPress allows SQL Injection via inc/rencontre_widget.php. | |||||
CVE-2019-13409 | 1 Topmeeting | 1 Topmeeting | 2024-11-21 | 5.0 MEDIUM | 9.8 CRITICAL |
A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and username/password. | |||||
CVE-2019-13375 | 2 Dlink, Microsoft | 2 Central Wifimanager, Windows | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcodeAuth parameter passcode. The vulnerability does not need any authentication. | |||||
CVE-2019-13373 | 2 Dlink, Microsoft | 2 Central Wifimanager, Windows | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validated and arbitrary SQL statements can be executed in the database via the /web/Public/Conn.php parameter dbSQL. | |||||
CVE-2019-13292 | 1 Weberp | 1 Weberp | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks. | |||||
CVE-2019-13275 | 1 Veronalabs | 1 Wp Statistics | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection. |