Vulnerabilities (CVE)

Filtered by CWE-89
Total 19833 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-3404 1 Cisco 1 Unified Communications Manager 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, leading to discovery of encrypted credentials by leveraging metadata, aka Bug ID CSCuh01051.
CVE-2013-3294 1 Exponentcms 1 Exponent Cms 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Exponent CMS before 2.2.0 release candidate 1 allow remote attackers to execute arbitrary SQL commands via the (1) src or (2) username parameter to index.php.
CVE-2013-3213 1 Vtiger 1 Vtiger Crm 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) picklist_name parameter in the get_picklists method to soap/customerportal.php, (2) where parameter in the get_tickets_list method to soap/customerportal.php, or (3) emailaddress parameter in the SearchContactsByEmail method to soap/vtigerolservice.php; or remote authenticated users to execute arbitrary SQL commands via the (4) emailaddress parameter in the SearchContactsByEmail method to soap/thunderbirdplugin.php.
CVE-2013-3081 1 Jojocms 1 Jojo-cms 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the checkEmailFormat function in plugins/jojo_core/classes/Jojo.php in Jojo before 1.2.2 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header to /articles/test/.
CVE-2013-3050 1 Zapms 1 Zapms 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in ZAPms 1.41 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter to product.
CVE-2013-3033 1 Ibm 1 Tivoli Remote Control 2026-06-16 6.5 MEDIUM N/A
SQL injection vulnerability in the server component in IBM Tivoli Remote Control 5.1.2 before 5.1.2-TIV-TRC512-IF0015 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2013-3000 1 Ibm 1 Infosphere Data Replication Dashboard 2026-06-16 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. IBM X-Force ID: 84116.
CVE-2013-2956 1 Ibm 1 Infosphere Optim Data Growth For Oracle E-business Suite 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2013-2945 1 B2evolution 1 B2evolution 2026-06-16 6.5 MEDIUM N/A
SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary SQL commands via the show_statuses[] parameter. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.
CVE-2013-2745 2 Debian, Minidlna Project 2 Debian Linux, Minidlna 2026-06-16 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0
CVE-2013-2738 1 Readymedia Project 1 Readymedia 2026-06-16 7.5 HIGH 9.8 CRITICAL
minidlna has SQL Injection that may allow retrieval of arbitrary files
CVE-2013-2690 1 Synchroweb 1 Synconnect 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in Synchroweb Technology SynConnect 2.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter in a logoff action.
CVE-2013-2627 1 Idleman 1 Leed 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in action.php in Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to execute arbitrary SQL commands via the id parameter in a removeFolder action.
CVE-2013-2594 1 Hornbill 1 Supportworks Itsm 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote attackers to execute arbitrary SQL commands via the callref parameter.
CVE-2013-2559 1 Getsymphony 1 Symphony 2026-06-16 6.5 MEDIUM N/A
SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter to system/authors/. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.
CVE-2013-2498 1 Simplehrm 1 Simplehrm 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the login page in flexycms/modules/user/user_manager.php in SimpleHRM 2.3, 2.2, and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to index.php/user/setLogin.
CVE-2013-2226 1 Glpi-project 1 Glpi 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands via the (1) users_id_assign parameter to ajax/ticketassigninformation.php, (2) filename parameter to front/document.form.php, or (3) table parameter to ajax/comments.php.
CVE-2013-2091 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-16 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.
CVE-2013-2050 1 Redhat 2 Cloudforms Management Engine, Manageiq Enterprise Virtualization Manager 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualization Manager 5.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the profile[] parameter in an explorer action.
CVE-2013-2046 1 Owncloud 1 Owncloud Server 2026-06-16 6.5 MEDIUM N/A
SQL injection vulnerability in lib/bookmarks.php in ownCloud Server 4.5.x before 4.5.11 and 5.x before 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.