Total
15226 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-35487 | 1 Nokia | 1 Broadcast Message Center | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifier HTTP POST parameter. This allows an attacker to obtain the database user, database name, and database version information, and potentially database data. | |||||
CVE-2021-35458 | 1 Online Pet Shop We App Project | 1 Online Pet Shop We App | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Online Pet Shop We App 1.0 is vulnerable to Union SQL Injection in products.php (aka p=products) via the c or s parameter. | |||||
CVE-2021-35456 | 1 Online Pet Shop Web Application Project | 1 Online Pet Shop Web Application | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload | |||||
CVE-2021-35437 | 1 Lmxcms | 1 Lmxcms | 2024-11-21 | N/A | 9.8 CRITICAL |
SQL injection vulnerability in LMXCMS v.1.4 allows attacker to execute arbitrary code via the TagsAction.class. | |||||
CVE-2021-35414 | 1 Chamilo | 1 Chamilo Lms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php. | |||||
CVE-2021-35283 | 1 Atoms183 Cms Project | 1 Atoms183 Cms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via the Name, Fname, and ID parameters to search.php. | |||||
CVE-2021-35234 | 1 Solarwinds | 1 Orion Platform | 2024-11-21 | 6.5 MEDIUM | 8.0 HIGH |
Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information. | |||||
CVE-2021-35212 | 1 Solarwinds | 1 Orion Platform | 2024-11-21 | 9.0 HIGH | 8.9 HIGH |
An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection which could lead to full read/write over the Orion database content including the Orion certificate for any authenticated user. | |||||
CVE-2021-35048 | 1 Fidelissecurity | 2 Deception, Network | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis software. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability. | |||||
CVE-2021-35042 | 2 Djangoproject, Fedoraproject | 2 Django, Fedora | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application. | |||||
CVE-2021-34684 | 1 Hitachi | 1 Vantara Pentaho | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and thus retrieve data from the related databases, as demonstrated by an api/repos/dashboards/editor URI. | |||||
CVE-2021-34609 | 1 Arubanetworks | 1 Clearpass Policy Manager | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
A remote SQL injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |||||
CVE-2021-34187 | 1 Chamilo | 1 Chamilo | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter. | |||||
CVE-2021-34166 | 1 Simple Food Website Project | 1 Simple Food Website | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin. | |||||
CVE-2021-34165 | 1 Basic Shopping Cart Project | 1 Basic Shopping Cart | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin. | |||||
CVE-2021-33894 | 1 Progress | 1 Moveit Transfer | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x before 2019.2.2 (11.2.2), 2020.x before 2020.0.5 (12.0.5), 2020.1.x before 2020.1.4 (12.1.4), and 2021.x before 2021.0.1 (13.0.1), a SQL injection vulnerability exists in SILUtility.vb in MOVEit.DMZ.WebApp in the MOVEit Transfer web app. This could allow an authenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database and/or execute SQL statements that alter or delete database elements. | |||||
CVE-2021-33736 | 1 Siemens | 1 Sinec Nms | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application. | |||||
CVE-2021-33735 | 1 Siemens | 1 Sinec Nms | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application. | |||||
CVE-2021-33734 | 1 Siemens | 1 Sinec Nms | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application. | |||||
CVE-2021-33733 | 1 Siemens | 1 Sinec Nms | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application. |