Vulnerabilities (CVE)

Filtered by CWE-89
Total 15226 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-3637 1 Phpmybackuppro 1 Phpmybackuppro 2025-04-20 6.8 MEDIUM 8.1 HIGH
SQL injection vulnerability in phpMyBackupPro when run in multi-user mode before 2.5 allows remote attackers to execute arbitrary SQL commands via the username and password parameters.
CVE-2017-0304 1 F5 1 Big-ip Advanced Firewall Manager 2025-04-20 5.5 MEDIUM 5.4 MEDIUM
A SQL injection vulnerability exists in the BIG-IP AFM management UI on versions 12.0.0, 12.1.0, 12.1.1, 12.1.2 and 13.0.0 that may allow a copy of the firewall rules to be tampered with and impact the Configuration Utility until there is a resync of the rules. Traffic processing and the live firewall rules in use are not affected.
CVE-2017-14145 1 Helpdezk 1 Helpdezk 2025-04-20 7.5 HIGH 9.8 CRITICAL
HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function.
CVE-2017-5574 1 Metalgenix 1 Genixcms 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows unauthenticated users to execute arbitrary SQL commands via the activation parameter.
CVE-2017-17713 1 Boxug 1 Trape 2025-04-20 7.5 HIGH 9.8 CRITICAL
Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp parameter, the /register lat parameter, the /register lon parameter, the /register org parameter, the /register query parameter, the /register region parameter, the /register regionName parameter, the /register timezone parameter, the /register vId parameter, the /register zip parameter, or the /tping id parameter.
CVE-2017-8835 1 Peplink 12 1350hw2 Firmware, 2500 Firmware, 380hw6 Firmware and 9 more 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be retrieved from the sessions database.
CVE-2016-4893 1 Setucocms Project 1 Setucocms 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2014-9558 1 Smartcms 1 Smartcms 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in SmartCMS v.2.
CVE-2016-9402 1 Mybb 2 Merge System, Mybb 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-6571 1 Mail-masta Project 1 Mail-masta 2025-04-20 6.5 MEDIUM 7.2 HIGH
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign.php with the GET Parameter: id.
CVE-2017-15966 1 Zh Yandexmap Project 1 Zh Yandexmap 2025-04-20 7.5 HIGH 9.8 CRITICAL
The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php.
CVE-2017-11384 1 Trendmicro 1 Control Manager 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation in mdHandlerLicenseManager.dll. Formerly ZDI-CAN-4561.
CVE-2017-17606 1 Co-work Space Search Script Project 1 Co-work Space Search Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-1000004 1 Atutor 1 Atutor 2025-04-20 7.5 HIGH 9.8 CRITICAL
ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email, Course Alumni, Course Enrolment, Group Membership, Course unenrolment, Course Enrolment List Search, Glossary, Social Group Member Search, Social Friend Search, Social Group Search, File Comment, Gradebook Test Title, User Group Membership, Inbox/Sent Items, Sent Messages, Links, Photo Album, Poll, Social Application, Social Profile, Test, Content Menu, Auto-Login, and Gradebook components resulting in information disclosure, database modification, or potential code execution.
CVE-2017-14846 1 Dasinfomedia 1 Hospital Management System 2025-04-20 6.5 MEDIUM 8.8 HIGH
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
CVE-2017-8198 1 Huawei 1 Fusionsphere 2025-04-20 6.5 MEDIUM 7.2 HIGH
FusionSphere V100R006C00SPC102(NFV) has an SQL injection vulnerability. An authenticated, remote attacker could craft interface messages carrying malicious SQL statements and send them to a target device. Successful exploit could allow the attacker to launch an SQL injection attack and execute SQL commands.
CVE-2017-17872 1 Jextn 1 Jextn Video Gallery 2025-04-20 7.5 HIGH 9.8 CRITICAL
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
CVE-2017-5347 1 Metalgenix 1 Genixcms 2025-04-20 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in inc/mod/newsletter/options.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the recipient parameter to gxadmin/index.php.
CVE-2017-15985 1 Readymadeb2bscript 1 Basic B2b Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.
CVE-2017-14403 1 Eyesofnetwork 1 Eyesofnetwork 2025-04-20 7.5 HIGH 9.8 CRITICAL
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the term parameter to module/admin_group/search.php.