Vulnerabilities (CVE)

Filtered by CWE-89
Total 15425 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-28183 1 Water Billing System Project 1 Water Billing System 2024-11-21 10.0 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php.
CVE-2020-28172 1 Simple College Project 1 Simple College 2024-11-21 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin authentication mechanism in college_website/admin/ajax.php?action=login, thus gaining access to the website administrative panel.
CVE-2020-28138 1 Online Clothing Store Project 1 Online Clothing Store 2024-11-21 7.5 HIGH 9.8 CRITICAL
SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php.
CVE-2020-28133 1 Simple Grocery Store Sales And Inventory Sales Project 1 Simple Grocery Store Sales And Inventory System 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in sales_inventory/login.php.
CVE-2020-28115 1 Web-audimex 1 Audimexee 2024-11-21 6.5 MEDIUM 8.8 HIGH
SQL Injection vulnerability in "Documents component" found in AudimexEE version 14.1.0 allows an attacker to execute arbitrary SQL commands via the object_path parameter.
CVE-2020-28103 1 Chshcms 1 Cscms 2024-11-21 7.5 HIGH 9.8 CRITICAL
cscms v4.1 allows for SQL injection via the "page_del" function.
CVE-2020-28102 1 Chshcms 1 Cscms 2024-11-21 7.5 HIGH 9.8 CRITICAL
cscms v4.1 allows for SQL injection via the "js_del" function.
CVE-2020-28091 1 Cxuu 1 Cxuucms 2024-11-21 5.0 MEDIUM 7.5 HIGH
cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php.
CVE-2020-28087 1 Jeecg 1 Jeecg Boot 2024-11-21 5.0 MEDIUM 7.5 HIGH
A SQL injection vulnerability in /jeecg boot/sys/dict/loadtreedata of jeecg-boot CMS 2.3 allows attackers to access sensitive database information.
CVE-2020-28074 1 Online Health Care System Project 1 Online Health Care System 2024-11-21 7.5 HIGH 9.8 CRITICAL
SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass the authentication system and become an admin.
CVE-2020-28073 1 Library Management System Project 1 Library Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authentication and impersonate any user on the system.
CVE-2020-28070 1 Alumni Management System Project 1 Alumni Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter.
CVE-2020-27995 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 7.5 HIGH 9.8 CRITICAL
SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.
CVE-2020-27886 1 Eyesofnetwork 1 Eyesofnetwork 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to exploit the username_available function of the includes/functions.php file (which is called by login.php).
CVE-2020-27869 1 Solarwinds 1 Network Performance Monitor 2024-11-21 9.0 HIGH 8.8 HIGH
This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: 2020.2. Authentication is required to exploit this vulnerability. The specific flaw exists within the WriteToFile method. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges and reset the password for the Admin user. Was ZDI-CAN-11804.
CVE-2020-27848 1 Dotcms 1 Dotcms 2024-11-21 6.5 MEDIUM 8.8 HIGH
dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used to paginate results of a REST endpoints do not sanitize the orderBy parameter and in some cases it is vulnerable to SQL injection attacks. A user must be an authenticated manager in the dotCMS system to exploit this vulnerability.
CVE-2020-27733 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 6.5 MEDIUM 8.8 HIGH
Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.
CVE-2020-27660 1 Synology 1 Safeaccess 2024-11-21 10.0 HIGH 9.6 CRITICAL
SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter.
CVE-2020-27615 1 Loginizer 1 Loginizer 2024-11-21 7.5 HIGH 9.8 CRITICAL
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.
CVE-2020-27481 1 Goodlayers 1 Good Learning Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Parameter "id" was sent straight into SQL query without sanitization.