Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-27130 1 Online Reviewer System Project 1 Online Reviewer System 2021-04-19 7.5 HIGH 9.8 CRITICAL
Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a reverse shell upload.
CVE-2021-30175 1 Zerof 1 Web Server 2021-04-14 7.5 HIGH 9.8 CRITICAL
ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.
CVE-2021-30176 1 Zerof 1 Expert 2021-04-14 7.5 HIGH 9.8 CRITICAL
The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint.
CVE-2021-30177 1 Phpnuke 1 Php-nuke 2021-04-13 7.5 HIGH 9.8 CRITICAL
There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution. This occurs because the U.S. state is not validated to be two letters, and the OrderBy field is not validated to be one of LASTNAME, CITY, or STATE.
CVE-2021-28925 1 Nagios 1 Network Analyzer 2021-04-13 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/.
CVE-2020-23763 1 Online Book Store Project 1 Online Book Store 2021-04-13 7.5 HIGH 9.8 CRITICAL
SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
CVE-2018-13824 2 Broadcom, Ca 2 Project Portfolio Management, Project Portfolio Management 2021-04-12 7.5 HIGH 9.8 CRITICAL
Insufficient input sanitization of two parameters in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute SQL injection attacks.
CVE-2018-9029 1 Broadcom 1 Privileged Access Manager 2021-04-12 7.5 HIGH 9.8 CRITICAL
An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL injection attacks.
CVE-2021-30000 1 Latrix Project 1 Latrix 2021-04-07 7.5 HIGH 9.8 CRITICAL
An issue was discovered in LATRIX 0.6.0. SQL injection in the txtaccesscode parameter of inandout.php leads to information disclosure and code execution.
CVE-2020-28172 1 Simple College Project 1 Simple College 2021-04-02 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin authentication mechanism in college_website/admin/ajax.php?action=login, thus gaining access to the website administrative panel.
CVE-2021-28668 1 Xerox 20 Altalink B8045, Altalink B8045 Firmware, Altalink B8055 and 17 more 2021-04-01 7.5 HIGH 9.8 CRITICAL
Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 has several SQL injection vulnerabilities.
CVE-2020-26935 4 Debian, Fedoraproject, Opensuse and 1 more 5 Debian Linux, Fedora, Backports Sle and 2 more 2021-03-30 7.5 HIGH 9.8 CRITICAL
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.
CVE-2019-15562 1 Gorm 1 Gorm 2021-03-30 7.5 HIGH 9.8 CRITICAL
** DISPUTED ** GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input where Gorm expects trusted SQL fragments is a vulnerability in the application, not in Gorm.
CVE-2020-10582 1 Invigo 1 Automatic Device Management 2021-03-27 7.5 HIGH 9.8 CRITICAL
A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database.
CVE-2020-6577 1 It-recht-kanzlei 1 It-recht-kanzlei 2021-03-25 7.5 HIGH 9.8 CRITICAL
The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection.
CVE-2020-35337 1 Thinksaas 1 Thinksaas 2021-03-24 7.5 HIGH 9.8 CRITICAL
ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows remote attackers to execute arbitrary SQL commands.
CVE-2021-22848 1 Hgiga 4 Msr45 Isherlock-antispam, Msr45 Isherlock-user, Ssr45 Isherlock-antispam and 1 more 2021-03-23 7.5 HIGH 9.8 CRITICAL
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.
CVE-2021-22859 1 Eic 1 E-document System 2021-03-23 7.5 HIGH 9.8 CRITICAL
The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary commands without privilege.
CVE-2021-24139 1 10web 1 Photo Gallery 2021-03-22 7.5 HIGH 9.8 CRITICAL
Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.
CVE-2021-28381 1 Vhs Project 1 Vhs 2021-03-22 7.5 HIGH 9.8 CRITICAL
The vhs (aka VHS: Fluid ViewHelpers) extension before 5.1.1 for TYPO3 allows SQL injection via isLanguageViewHelper.
CVE-2020-24913 1 Qcubed 1 Qcubed 2021-03-22 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.
CVE-2018-17254 1 Arkextensions 1 Jck Editor 2021-03-17 7.5 HIGH 9.8 CRITICAL
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
CVE-2020-24877 1 Zzzcms 1 Zzzphp 2021-03-16 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.
CVE-2021-27581 1 Kentico 1 Kentico Cms 2021-03-15 7.5 HIGH 9.8 CRITICAL
The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.
CVE-2021-23352 1 Madge Project 1 Madge 2021-03-13 7.5 HIGH 9.8 CRITICAL
This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image(), .svg() or .dot() functions are called, is executed by the childprocess.exec function.
CVE-2020-24791 1 Thedaylightstudio 1 Fuel Cms 2021-03-12 7.5 HIGH 9.8 CRITICAL
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
CVE-2021-27314 1 Doctor Appointment System Project 1 Doctor Appointment System 2021-03-05 7.5 HIGH 9.8 CRITICAL
SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.
CVE-2020-28657 1 Bittacora 1 Bpanel 2021-03-04 7.5 HIGH 9.8 CRITICAL
In bPanel 2.0, the administrative ajax endpoints (aka ajax/aj_*.php) are accessible without authentication and allow SQL injections, which could lead to platform compromise.
CVE-2021-26904 1 Isida 1 Retriever 2021-03-04 7.5 HIGH 9.8 CRITICAL
LMA ISIDA Retriever 5.2 allows SQL Injection.
CVE-2014-2323 4 Debian, Lighttpd, Opensuse and 1 more 5 Debian Linux, Lighttpd, Opensuse and 2 more 2021-02-26 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.
CVE-2017-1000060 1 Eyesofnetwork 1 Eyesofnetwork 2021-02-25 10.0 HIGH 9.8 CRITICAL
EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root
CVE-2021-25779 1 Baby Care System Project 1 Baby Care System 2021-02-23 7.5 HIGH 9.8 CRITICAL
Baby Care System v1.0 is vulnerable to SQL injection via the 'id' parameter on the contentsectionpage.php page.
CVE-2017-14252 1 Eyesofnetwork 1 Eyesofnetwork 2021-02-23 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the EyesOfNetwork web interface (aka eonweb) 5.1-0 via the group_id cookie to side.php.
CVE-2017-14403 1 Eyesofnetwork 1 Eyesofnetwork 2021-02-23 7.5 HIGH 9.8 CRITICAL
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the term parameter to module/admin_group/search.php.
CVE-2017-14247 1 Eyesofnetwork 1 Eyesofnetwork 2021-02-23 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the EyesOfNetwork web interface (aka eonweb) 5.1-0 via the user_id cookie to header.php, a related issue to CVE-2017-1000060.
CVE-2017-14401 1 Eyesofnetwork 1 Eyesofnetwork 2021-02-23 7.5 HIGH 9.8 CRITICAL
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT UPDATE" section.
CVE-2017-14402 1 Eyesofnetwork 1 Eyesofnetwork 2021-02-23 7.5 HIGH 9.8 CRITICAL
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT CREATION" section, related to lack of input validation in include/function.php.
CVE-2021-26201 1 Casap Automated Enrollment System Project 1 Casap Automated Enrollment System 2021-02-22 7.5 HIGH 9.8 CRITICAL
The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain access to the admin panel by injecting a SQL query in the username field of the login page.
CVE-2021-26200 1 Library System Project 1 Library System 2021-02-22 7.5 HIGH 9.8 CRITICAL
The user area for Library System 1.0 is vulnerable to SQL injection where a user can bypass the authentication and login as the admin user.
CVE-2021-27234 1 Mutare 1 Voice 2021-02-22 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. The web application suffers from SQL injection on Adminlog.asp, Archivemsgs.asp, Deletelog.asp, Eventlog.asp, and Evmlog.asp.
CVE-2020-24841 1 Sdg 1 Pnpscada 2021-02-19 7.5 HIGH 9.8 CRITICAL
PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
CVE-2021-21024 1 Magento 1 Magento 2021-02-16 6.5 MEDIUM 9.1 CRITICAL
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a blind SQL injection vulnerability in the Search module. Successful exploitation could lead to unauthorized access to restricted resources by an unauthenticated attacker. Access to the admin console is required for successful exploitation.
CVE-2021-22658 1 Advantech 1 Iview 2021-02-12 7.5 HIGH 9.8 CRITICAL
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'.
CVE-2020-26051 1 College Management System Project 1 College Management System 2021-02-10 7.5 HIGH 9.8 CRITICAL
College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters 'unametxt' and 'pwdtxt', which are not filtered before passing a SQL query.
CVE-2020-16629 1 Phpok 1 Phpok 2021-02-10 7.5 HIGH 9.8 CRITICAL
PhpOK 5.4.137 contains a SQL injection vulnerability that can inject an attachment data through SQL, and then call the attachment replacement function through api.php to write a PHP file to the target path.
CVE-2021-26754 1 Wpdatatables 1 Wpdatatables 2021-02-09 10.0 HIGH 9.8 CRITICAL
wpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL injection.
CVE-2020-18717 1 Zzzcms 1 Zzzphp 2021-02-08 7.5 HIGH 9.8 CRITICAL
SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.
CVE-2021-20016 1 Sonicwall 11 Sma 100, Sma 100 Firmware, Sma 200 and 8 more 2021-02-08 7.5 HIGH 9.8 CRITICAL
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.
CVE-2020-18714 1 Rockoa 1 Rockoa 2021-02-05 7.5 HIGH 9.8 CRITICAL
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php's getdata function.
CVE-2020-18716 1 Rockoa 1 Rockoa 2021-02-05 7.5 HIGH 9.8 CRITICAL
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php.