Total
20125 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2020-23685 | 1 Vtimecn | 1 188jianzhan | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| SQL Injection vulnerability in 188Jianzhan v2.1.0, allows attackers to execute arbitrary code and gain escalated privileges, via the username parameter to login.php. | |||||
| CVE-2020-23282 | 1 Mv | 1 Mconnect | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| SQL injection in Logon Page in MV's mConnect application, v02.001.00, allows an attacker to use a non existing user with a generic password to connect to the application and get access to unauthorized information. | |||||
| CVE-2020-23262 | 1 Mingsoft | 1 Mcms | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do. | |||||
| CVE-2020-23150 | 1 Rconfig | 1 Rconfig | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| A SQL injection vulnerability in config.inc.php of rConfig 3.9.5 allows attackers to access sensitive database information via a crafted GET request to install/lib/ajaxHandlers/ajaxDbInstall.php. | |||||
| CVE-2020-23149 | 1 Rconfig | 1 Rconfig | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| The dbName parameter in ajaxDbInstall.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a SQL injection and access sensitive database information. | |||||
| CVE-2020-23045 | 1 Macs Cms Project | 1 Macs Cms | 2026-06-17 | 6.5 MEDIUM | 7.2 HIGH |
| Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a SQL injection vulnerability via the 'roleId' parameter of the `editRole` and `deletUser` modules. | |||||
| CVE-2020-22820 | 1 Mkcms Project | 1 Mkcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter. | |||||
| CVE-2020-22819 | 1 Mkcms Project | 1 Mkcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter. | |||||
| CVE-2020-22818 | 1 Mkcms Project | 1 Mkcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter. | |||||
| CVE-2020-22807 | 1 Vtiger | 1 Vtiger Crm | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature. | |||||
| CVE-2020-22781 | 1 Etherpad | 1 Etherpad | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash the instance). | |||||
| CVE-2020-22669 | 2 Debian, Owasp | 2 Debian Linux, Owasp Modsecurity Core Rule Set | 2026-06-17 | N/A | 9.8 CRITICAL |
| Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications. | |||||
| CVE-2020-22425 | 1 Centreon | 1 Centreon | 2026-06-17 | 6.5 MEDIUM | 8.8 HIGH |
| Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an authorized user is able to inject additional SQL queries to perform remote command execution. | |||||
| CVE-2020-22226 | 1 Phpjabbers | 1 Fundraising Script | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function. | |||||
| CVE-2020-22225 | 1 Phpjabbers | 1 Fundraising Script | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function. | |||||
| CVE-2020-22223 | 1 Phpjabbers | 1 Fundraising Script | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function. | |||||
| CVE-2020-22212 | 1 74cms | 1 74cms | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php. | |||||
| CVE-2020-22211 | 1 74cms | 1 74cms | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php. | |||||
| CVE-2020-22210 | 1 74cms | 1 74cms | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php. | |||||
| CVE-2020-22209 | 1 74cms | 1 74cms | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php. | |||||
