Total
15276 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2014-9519 | 1 Infinitewp | 1 Infinitewp | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in login.php in InfiniteWP Admin Panel before 2.4.3 allows remote attackers to execute arbitrary SQL commands via the email parameter. | |||||
CVE-2014-5192 | 1 Sphider | 1 Sphider | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter parameter. | |||||
CVE-2015-2824 | 1 Simple Ads Manager Project | 1 Simple Ads Manager | 2025-04-12 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits action to sam-ajax.php; the (2) cstr parameter in a load_posts action to sam-ajax-admin.php; the (3) searchTerm parameter in a load_combo_data action to sam-ajax-admin.php; or the (4) subscriber, (5) contributor, (6) author, (7) editor, (8) admin, or (9) sadmin parameter in a load_users action to sam-ajax-admin.php. | |||||
CVE-2015-4967 | 1 Ibm | 13 Change And Configuration Management Database, Maximo Asset Management, Maximo Asset Management Essentials and 10 more | 2025-04-12 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-1000011 | 1 Dukapress Project | 1 Dukapress | 2025-04-12 | 7.5 HIGH | 9.8 CRITICAL |
Blind SQL Injection in wordpress plugin dukapress v2.5.9 | |||||
CVE-2015-2803 | 1 Akronymmanager Project | 1 Akronymmanager | 2025-04-12 | 6.0 MEDIUM | N/A |
SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3 allows remote authenticated users with permission to maintain acronyms to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2014-4034 | 1 Aas9 | 1 Zerocms | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter. | |||||
CVE-2015-6519 | 1 Arabportal | 1 Arab Portal | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in Arab Portal 3 allows remote attackers to execute arbitrary SQL commands via the showemail parameter in a signup action to members.php. | |||||
CVE-2014-10013 | 1 Strategy11 | 1 Awp Classifieds | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase parameter in a dosearch action. | |||||
CVE-2013-3727 | 1 Kasseler-cms | 1 Kasseler-cms | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users to execute arbitrary SQL commands via the groups[] parameter to admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands. | |||||
CVE-2014-3962 | 1 Videos Tube Project | 1 Videos Tube | 2025-04-12 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Videos Tube 1.0 allow remote attackers to execute arbitrary SQL commands via the url parameter to (1) videocat.php or (2) single.php. | |||||
CVE-2014-9237 | 1 Proticaret | 1 Proticaret | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a tem:Code element in a SOAP request. | |||||
CVE-2015-5148 | 1 Livelycart | 1 Livelycart | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in LivelyCart 1.2.0 allows remote attackers to execute arbitrary SQL commands via the search_query parameter to product/search. | |||||
CVE-2014-9528 | 1 Humhub | 1 Humhub | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in the actionIndex function in protected/modules_core/notification/controllers/ListController.php in HumHub 0.10.0-rc.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the from parameter to index.php. NOTE: this can be leveraged for cross-site scripting (XSS) attacks via a request that causes an error. | |||||
CVE-2015-6512 | 1 Codelogic | 1 Freichat | 2025-04-12 | 5.0 MEDIUM | N/A |
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows remote attackers to execute arbitrary SQL commands via the time parameter to server/freichat.php. | |||||
CVE-2015-0540 | 1 Emc | 1 Document Sciences Xpression | 2025-04-12 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the xAdmin interface in EMC Document Sciences xPression 4.2 before P44 and 4.5 SP1 before P03 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2016-5048 | 1 Readydesk | 1 Readydesk | 2025-04-12 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in chat/staff/default.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary SQL commands via the user name field. | |||||
CVE-2014-8339 | 2 Clip-share, Nuevolab | 2 Clipshare, Nuevoplayer | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in midroll.php in Nuevolab Nuevoplayer for ClipShare 8.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ch parameter. | |||||
CVE-2014-2081 | 1 Iii | 1 Vtls-virtua | 2025-04-12 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua before 2013.2.4 and 2014.x before 2014.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. | |||||
CVE-2011-5286 | 1 Social Slider Project | 1 Social Slider | 2025-04-12 | 7.5 HIGH | N/A |
SQL injection vulnerability in social-slider-2/ajax.php in the Social Slider plugin before 7.4.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the rA array parameter. |