Vulnerabilities (CVE)

Filtered by CWE-89
Total 19857 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-6329 1 Cisco 1 Prime Collaboration Provisioning 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in Cisco Prime Collaboration Provisioning 10.6 and 11.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCut64074.
CVE-2015-6319 2 Cisco, Sun 23 Rv016 Multi-wan Vpn Router, Rv042 Dual Wan Vpn Router, Rv042g Dual Gigabit Wan Vpn Router and 20 more 2026-06-17 10.0 HIGH 9.8 CRITICAL
SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows remote attackers to execute arbitrary SQL commands via a crafted header in an HTTP request, aka Bug ID CSCuv29574.
CVE-2015-6299 1 Cisco 1 Unity Connection 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in the web interface in Cisco Unity Connection 9.1(1.2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted POST request, aka Bug ID CSCuv63824.
CVE-2015-6028 1 Castlerock 1 Snmpc 2026-06-17 6.5 MEDIUM 8.8 HIGH
Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.
CVE-2015-6009 1 Refbase 1 Refbase 2026-06-17 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL commands via (1) the where parameter to rss.php or (2) the sqlQuery parameter to search.php, a different issue than CVE-2015-7382.
CVE-2015-6004 1 Progress 1 Whatsup Gold 2026-06-17 6.5 MEDIUM 6.5 MEDIUM
Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary SQL commands via (1) the UniqueID (aka sUniqueID) parameter to WrFreeFormText.asp in the Reports component or (2) the Find Device parameter.
CVE-2015-5725 1 Codeigniter 1 Codeigniter 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter before 2.2.4 allows remote attackers to execute arbitrary SQL commands via vectors involving the offset variable.
CVE-2015-5703 1 Open-xchange Ox Guard 1 Open-xchange Ox Guard 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in the public key discovery API call in Open-Xchange OX Guard before 2.0.0-rev8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-5668 1 Techno Project Japan 1 Enisys Gw 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-5659 1 Network Applied Communication Laboratory 1 Shimane Prefecture Cms 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in Network Applied Communication Laboratory Pref Shimane CMS 2.x before 2.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-5648 1 Loenshotel 1 Phprechnung 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in list.php in phpRechnung before 1.6.5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-5642 1 Icz 1 Matchasns 2026-06-17 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in ICZ MATCHA INVOICE before 2.5.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-5641 1 Basercms 1 Basercms 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in baserCMS before 3.0.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-5617 1 Enorth 1 Webpublisher Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in pub/m_pending_news/delete_pending_news.jsp in Enorth Webpublisher CMS allows remote attackers to execute arbitrary SQL commands via the cbNewsId parameter.
CVE-2015-5599 1 Powerplay Gallery Project 1 Powerplay Gallery 2026-06-17 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) albumid or (2) name parameter.
CVE-2015-5591 1 Zenphoto 1 Zenphoto 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.
CVE-2015-5533 1 Count Per Day Project 1 Count Per Day 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.
CVE-2015-5504 1 Novalnet 1 Novalnet Payment Module Ubercart- 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in the Novalnet Payment Module Ubercart module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-5459 1 Zohocorp 1 Manageengine Password Manager Pro 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in the AdvanceSearch.class in AdventNetPassTrix.jar in ManageEngine Password Manager Pro (PMP) before 8.1 Build 8101 allows remote authenticated users to execute arbitrary SQL commands via the ANDOR parameter, as demonstrated by a request to STATE_ID/1425543888647/SQLAdvancedALSearchResult.cc.
CVE-2015-5452 1 Watchguard 1 Xcs 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitrary SQL commands via the sid cookie, as demonstrated by a request to borderpost/imp/compose.php3.