Vulnerabilities (CVE)

Filtered by CWE-89
Total 15112 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15555 1 Wellness Project 1 Wellness 2024-11-21 7.5 HIGH 9.8 CRITICAL
FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnessTrack.php, and server.php.
CVE-2019-15537 1 Cesnet 1 Proxystatistics 2024-11-21 7.5 HIGH 9.8 CRITICAL
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
CVE-2019-15536 1 Youracclaim 1 Acclaim 2024-11-21 7.5 HIGH 9.8 CRITICAL
The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.
CVE-2019-15535 1 Hostosm 1 Tasking Manager 2024-11-21 7.5 HIGH 9.8 CRITICAL
Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.
CVE-2019-15534 1 Raml-module-builder Project 1 Raml-module-builder 2024-11-21 7.5 HIGH 9.8 CRITICAL
Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.
CVE-2019-15533 1 Xayr 1 Xenfcoresharp 2024-11-21 7.5 HIGH 9.8 CRITICAL
XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php.
CVE-2019-15301 1 Terrasoft 1 Bpm Online Crm System Sdk 2024-11-21 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13 allows attackers to execute arbitrary SQL commands via the value parameter.
CVE-2019-15300 1 Centreon 1 Centreon Web 2024-11-21 6.5 MEDIUM 8.8 HIGH
A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml/ldap_host.php. The arId parameter is not properly filtered before being passed to the SQL query.
CVE-2019-15105 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 9.0 HIGH 8.8 HIGH
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.
CVE-2019-15104 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 9.0 HIGH 8.8 HIGH
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.
CVE-2019-15025 1 Ninjaforms 1 Ninjaforms 2024-11-21 7.5 HIGH 9.8 CRITICAL
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
CVE-2019-15016 1 Zingbox 1 Inspector 2024-11-21 6.5 MEDIUM 8.8 HIGH
An SQL injection vulnerability exists in the management interface of Zingbox Inspector versions 1.288 and earlier, that allows for unsanitized data provided by an authenticated user to be passed from the web UI into the database.
CVE-2019-14968 1 Txjia 1 Imcat 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action.
CVE-2019-14966 1 Frappe 1 Frappe 2024-11-21 6.5 MEDIUM 8.8 HIGH
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.
CVE-2019-14937 1 Vanderbilt 1 Redcap 2024-11-21 6.0 MEDIUM 7.5 HIGH
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data.
CVE-2019-14900 3 Hibernate, Quarkus, Redhat 11 Hibernate Orm, Quarkus, Build Of Quarkus and 8 more 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.
CVE-2019-14801 1 Foliovision 1 Fv Flowplayer Video Player 2024-11-21 7.5 HIGH 9.8 CRITICAL
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.
CVE-2019-14754 1 Open-school 1 Open-school 2024-11-21 7.5 HIGH 9.8 CRITICAL
Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id parameter.
CVE-2019-14702 1 Microdigital 6 Mdc-n2190v, Mdc-n2190v Firmware, Mdc-n4090 and 3 more 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. SQL injection vulnerabilities exist in 13 forms that are reachable through HTTPD. An attacker can, for example, create an admin account.
CVE-2019-14695 1 Sygnoos 1 Popup Builder 2024-11-21 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers Table ordering is mishandled.