Vulnerabilities (CVE)

Filtered by CWE-89
Total 19913 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-15961 1 Iproject Management System Project 1 Iproject Management System 2026-06-17 7.5 HIGH 9.8 CRITICAL
iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.
CVE-2017-15960 1 Yourarticlesdirectory 1 Article Directory Script 2026-06-17 7.5 HIGH 9.8 CRITICAL
Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.
CVE-2017-15959 1 Adultscriptpro 1 Adultscriptpro 2026-06-17 7.5 HIGH 9.8 CRITICAL
Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-2007-6576.
CVE-2017-15958 1 Domainzaar 1 D-park Pro 2026-06-17 7.5 HIGH 9.8 CRITICAL
D-Park Pro Domain Parking Script 1.0 allows SQL Injection via the username to admin/loginform.php.
CVE-2017-15949 1 Angry-frog 1 Xavier 2026-06-17 6.5 MEDIUM 7.2 HIGH
Xavier PHP Management Panel 2.4 allows SQL injection via the usertoedit parameter to admin/adminuseredit.php or the log_id parameter to admin/editgroup.php.
CVE-2017-15946 1 Selfget 1 Tag Meta 2026-06-17 7.5 HIGH 9.8 CRITICAL
In the com_tag component 1.7.6 for Joomla!, a SQL injection vulnerability is located in the `tag` parameter to index.php. The request method to execute is GET.
CVE-2017-15933 1 Eyesofnetwork 1 Eyesofnetwork 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL commands via the host parameter to module/capacity_per_device/index.php.
CVE-2017-15919 1 Accesspressthemes 1 Ultimate-form-builder-lite 2026-06-17 7.5 HIGH 9.8 CRITICAL
The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.
CVE-2017-15907 1 Phpcollab 1 Phpcollab 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in phpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to newsdesk/newsdesk.php.
CVE-2017-15880 1 Eyesofnetwork 1 Eyesofnetwork 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL commands via the group_name parameter to module/admin_group/add_modify_group.php (for insert_group and update_group).
CVE-2017-15875 1 Sistemagpweb 1 Gpweb 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Password Recovery in GPWeb 8.4.61 allows remote attackers to execute arbitrary SQL commands via the "checkemail" parameter.
CVE-2017-15579 1 Phpsugar 1 Php Melody 2026-06-17 7.5 HIGH 9.8 CRITICAL
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.
CVE-2017-15578 1 Phpsugar 1 Php Melody 2026-06-17 6.0 MEDIUM 8.8 HIGH
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.
CVE-2017-15546 1 Emc 1 Rsa Authentication Manager 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
The Security Console in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier is affected by a blind SQL injection vulnerability. Authenticated malicious users could potentially exploit this vulnerability to read any unencrypted data from the database.
CVE-2017-15539 1 Zorovavi\/blog Project 1 Zorovavi\/blog 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in zorovavi/blog through 2017-10-17 via the id parameter to recept.php.
CVE-2017-15381 1 Softwarepublico 1 E-sic 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script).
CVE-2017-15379 1 Softwarepublico 1 E-sic 2026-06-17 7.5 HIGH 9.8 CRITICAL
An authentication bypass exists in the E-Sic 1.0 /index (aka login) URI via '=''or' values for the username and password.
CVE-2017-15378 1 Softwarepublico 1 E-sic 2026-06-17 6.5 MEDIUM 8.8 HIGH
SQL Injection exists in the E-Sic 1.0 password reset parameter (aka the cpfcnpj parameter to the /reset URI).
CVE-2017-15373 1 Softwarepublico 1 E-sic 2026-06-17 7.5 HIGH 9.8 CRITICAL
E-Sic 1.0 allows SQL injection via the q parameter to esiclivre/restrito/inc/lkpcep.php (aka the search private area).
CVE-2017-15367 1 Bacula 1 Bacula-web 2026-06-17 7.5 HIGH 9.8 CRITICAL
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.