Vulnerabilities (CVE)

Filtered by CWE-89
Total 19846 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-5089 1 Status2k 1 Status2k 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL commands via the log parameter.
CVE-2014-5082 1 Sphider 1 Sphider 2026-06-17 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers to execute arbitrary SQL commands via the (1) site_id or (2) url parameter.
CVE-2014-5071 1 Microsemi 2 S350i, S350i Firmware 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the checkPassword function in Symmetricom s350i 2.70.15 allows remote attackers to execute arbitrary SQL commands via vectors involving a username.
CVE-2014-5017 1 Limesurvey 1 Limesurvey 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx parameter in a JSON request to admin/participants/sa/getParticipants_json, related to a search parameter.
CVE-2014-4984 1 Dejavuprotech 1 Crescendo - Sales Crm 2026-06-17 7.5 HIGH 9.8 CRITICAL
Déjà Vu Crescendo Sales CRM has remote SQL Injection
CVE-2014-4977 1 Sonicwall 1 Scrutinizer 2026-06-17 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) selectedUserGroup parameter in a create new user request to cgi-bin/admin.cgi or the (2) user_id parameter in the changeUnit function, (3) methodDetail parameter in the methodDetail function, or (4) xcNetworkDetail parameter in the xcNetworkDetail function in d4d/exporters.php.
CVE-2014-4960 1 Joomlaboat 1 Com Youtubegallery 2026-06-17 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.
CVE-2014-4959 1 Google 1 Android 2026-06-17 7.5 HIGH 9.8 CRITICAL
**DISPUTED** SQL injection vulnerability in SQLiteDatabase.java in the SQLi Api in Android allows remote attackers to execute arbitrary SQL commands via the delete method.
CVE-2014-4944 1 Bannersky 1 Bsk Pdf Manager 2026-06-17 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) categoryid or (2) pdfid parameter to wp-admin/admin.php.
CVE-2014-4939 1 Enl Newsletter Plugin Project 1 Enl-newsletter 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in the ENL Newsletter (enl-newsletter) plugin 1.0.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in the enl-add-new page to wp-admin/admin.php.
CVE-2014-4938 1 Wp Rss Poster Plugin Project 1 Wp-rss-poster 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in the WP Rss Poster (wp-rss-poster) plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in the wrp-add-new page to wp-admin/admin.php.
CVE-2014-4928 1 Invisioncommunity 1 Invision Power Board 2026-06-17 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the cId parameter.
CVE-2014-4914 2 Debian, Zend 2 Debian Linux, Zend Framework 2026-06-17 7.5 HIGH 9.8 CRITICAL
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
CVE-2014-4873 1 Bmc 1 Track-it\! 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands via crafted POST data.
CVE-2014-4858 1 Sabreairlinesolutions 5 Crew Management, Crew Operations, Crew Planning and 2 more 2026-06-17 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.
CVE-2014-4852 1 Thedigitalcraft 1 Atomcms 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2014-4850 1 Foecms 1 Foecms 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in index.php in FoeCMS allows remote attackers to execute arbitrary SQL commands via the i parameter.
CVE-2014-4824 1 Ibm 1 Qradar Security Information And Event Manager 2026-06-17 6.5 MEDIUM N/A
SQL injection vulnerability in IBM Security QRadar SIEM 7.2 before 7.2.3 Patch 1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2014-4741 1 Artifectx 1 Xclassified 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in demo/ads.php in Artifectx xClassified 1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
CVE-2014-4736 1 Blogengine 1 E2 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @actions/comment-process.