Vulnerabilities (CVE)

Filtered by CWE-89
Total 11593 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-16119 1 10web 1 Photo Gallery 2023-02-23 7.5 HIGH 9.8 CRITICAL
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
CVE-2023-24647 1 Online Food Ordering System Project 1 Online Food Ordering System 2023-02-22 N/A 7.5 HIGH
Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter.
CVE-2022-45962 1 Os4ed 1 Opensis 2023-02-22 N/A 6.5 MEDIUM
Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php.
CVE-2021-44345 1 Wvti 1 One Card Integrated Management System 2023-02-22 5.0 MEDIUM 7.5 HIGH
Beijing Wisdom Vision Technology Industry Co., Ltd One Card Integrated Management System 3.0 is vulnerable to SQL Injection.
CVE-2023-24084 1 Chikoi Project 1 Chikoi 2023-02-22 N/A 9.8 CRITICAL
ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function.
CVE-2023-23948 1 Owncloud 1 Owncloud 2023-02-21 N/A 5.5 MEDIUM
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable to SQL injection in `FileContentProvider.kt`. This issue can lead to information disclosure. Two databases, `filelist` and `owncloud_database`, are affected. In version 3.0, the `filelist` database was deprecated. However, injections affecting `owncloud_database` remain relevant as of version 3.0.
CVE-2022-45526 1 Institutional Management Website Project 1 Institutional Management Website 2023-02-18 N/A 9.8 CRITICAL
SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php.
CVE-2020-22669 2 Debian, Owasp 2 Debian Linux, Owasp Modsecurity Core Rule Set 2023-02-16 N/A 9.8 CRITICAL
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
CVE-2023-24684 1 Churchcrm 1 Churchcrm 2023-02-16 N/A 7.2 HIGH
ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the EID parameter at GetText.php.
CVE-2023-0771 1 Ampache 1 Ampache 2023-02-16 N/A 8.8 HIGH
SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop.
CVE-2022-46443 1 Bangresto Project 1 Bangresto 2023-02-13 N/A 8.8 HIGH
mesinkasir Bangresto 1.0 is vulnberable to SQL Injection via the itemqty%5B%5D parameter.
CVE-2013-2050 1 Redhat 2 Cloudforms Management Engine, Manageiq Enterprise Virtualization Manager 2023-02-13 7.5 HIGH N/A
SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualization Manager 5.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the profile[] parameter in an explorer action.
CVE-2014-7814 1 Redhat 1 Cloudforms 3.1 Management Engine 2023-02-13 6.5 MEDIUM N/A
SQL injection vulnerability in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 allows remote authenticated users to execute arbitrary SQL commands via a crafted REST API request to an SQL filter.
CVE-2014-0137 1 Redhat 1 Cloudforms 3.0 Management Engine 2023-02-13 6.5 MEDIUM N/A
SQL injection vulnerability in the saved_report_delete action in the ReportController in Red Hat CloudForms Management Engine (CFME) before 5.2.3.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, related to MiqReportResult.exists.
CVE-2013-4386 2 Redhat, Theforeman 2 Openstack, Foreman 2023-02-13 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
CVE-2018-14623 1 Theforeman 1 Katello 2023-02-12 4.0 MEDIUM 4.3 MEDIUM
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulnerable.
CVE-2016-3072 2 Katello, Redhat 3 Katello, Enterprise Linux, Satellite 2023-02-12 6.5 MEDIUM 8.8 HIGH
Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbitrary SQL commands via the (1) sort_by or (2) sort_order parameter.
CVE-2023-23489 1 Sandhillsdev 1 Easy Digital Downloads 2023-02-10 N/A 9.8 CRITICAL
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action.
CVE-2021-36434 1 Jocms Project 1 Jocms 2023-02-10 N/A 9.1 CRITICAL
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check function in jocms/apps/mask/inc/getmask.php.
CVE-2021-36431 1 Jocms Project 1 Jocms 2023-02-10 N/A 9.1 CRITICAL
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check() function in jocms/apps/mask/inc/mask.php.