Vulnerabilities (CVE)

Filtered by CWE-89
Total 11593 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-24862 1 Pharmacy Medical Store And Sale Point Project 1 Pharmacy Medical Store And Sale Point 2021-06-09 5.0 MEDIUM 7.5 HIGH
The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via the /medical/inventories.php path which allows attackers to retrieve all databases.
CVE-2020-26668 1 Bigtreecms 1 Bigtree Cms 2021-06-09 6.5 MEDIUM 8.8 HIGH
A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to inject a malicious SQL query to the applications via the 'Create New Feed' function.
CVE-2021-33180 1 Synology 1 Media Server 2021-06-09 7.5 HIGH 9.8 CRITICAL
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2020-36004 1 Appcms 1 Appcms 2021-06-08 4.0 MEDIUM 6.5 MEDIUM
AppCMS 2.0.101 in /admin/download_frame.php has a SQL injection vulnerability which allows attackers to obtain sensitive database information.
CVE-2011-2703 2 Osgeo, Umn 2 Mapserver, Mapserver 2021-06-07 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support.
CVE-2013-7262 2 Osgeo, Umn 2 Mapserver, Mapserver 2021-06-07 6.8 MEDIUM N/A
SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service is used, allows remote attackers to execute arbitrary SQL commands via a crafted string in a PostGIS TIME filter.
CVE-2019-25019 1 Limesurvey 1 Limesurvey 2021-06-04 7.5 HIGH 9.8 CRITICAL
LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model.
CVE-2020-26677 1 Vfairs 1 Vfairs 2021-06-01 6.5 MEDIUM 8.8 HIGH
Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.
CVE-2021-30081 1 Emlog 1 Emlog 2021-05-27 6.5 MEDIUM 8.8 HIGH
An issue was discovered in emlog 6.0.0stable. There is a SQL Injection vulnerability that can execute any SQL statement and query server sensitive data via admin/navbar.php?action=add_page.
CVE-2019-12348 1 Zzcms 1 Zzcms 2021-05-27 7.5 HIGH 9.8 CRITICAL
An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.
CVE-2020-25409 1 College Management System Project 1 College Management System 2021-05-27 7.5 HIGH 9.8 CRITICAL
Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.
CVE-2021-20720 1 Kujirahand 1 Konawiki 2021-05-25 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the KonaWiki2 versions prior to 2.2.4 allows remote attackers to execute arbitrary SQL commands and to obtain/alter the information stored in the database via unspecified vectors.
CVE-2021-31827 1 Progress 1 Moveit Transfer 2021-05-25 6.5 MEDIUM 8.8 HIGH
In Progress MOVEit Transfer before 2021.0 (13.0), a SQL injection vulnerability has been found in the MOVEit Transfer web app that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or destroy database elements. This is in MOVEit.DMZ.WebApp in SILHuman.vb.
CVE-2020-4990 1 Ibm 1 Security Guardium 2021-05-25 6.5 MEDIUM 8.8 HIGH
IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 192710.
CVE-2021-29053 1 Liferay 2 Dxp, Liferay Portal 2021-05-24 6.5 MEDIUM 8.8 HIGH
Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter to (1) CommerceChannelRelFinder.countByC_C, or (2) CommerceChannelRelFinder.findByC_C.
CVE-2021-24295 1 Cleantalk 1 Spam Protection\, Antispam\, Firewall 2021-05-24 5.0 MEDIUM 7.5 HIGH
It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent Header by manipulating the cookies set by the Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.153.4, sending an initial request to obtain a ct_sfw_pass_key cookie and then manually setting a separate ct_sfw_passed cookie and disallowing it from being reset.
CVE-2021-24314 1 Boostifythemes 1 Goto 2021-05-24 7.5 HIGH 9.8 CRITICAL
The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue
CVE-2021-24285 1 Cars-seller-auto-classifieds-script Project 1 Cars-seller-auto-classifieds-script 2021-05-21 7.5 HIGH 9.8 CRITICAL
The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue.
CVE-2021-32615 1 Piwigo 1 Piwigo 2021-05-21 7.5 HIGH 9.8 CRITICAL
Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.
CVE-2021-32051 1 Hexagon 1 Intergraph G\!nius 2021-05-21 5.0 MEDIUM 7.5 HIGH
Hexagon G!nius Auskunftsportal before 5.0.0.0 allows SQL injection via the GiPWorkflow/Service/DownloadPublicFile id parameter.