Vulnerabilities (CVE)

Filtered by CWE-89
Total 11593 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-17581 1 Quibids Clone Project 1 Quibids Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.
CVE-2017-17578 1 Crowdfunding Script Project 1 Crowdfunding Script 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
CVE-2017-17577 1 Trademe Clone Project 1 Trademe Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id parameter.
CVE-2017-17576 1 Gigs Script Project 1 Gigs Script 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or service-provider.php ser parameter.
CVE-2017-17575 1 Groupon Clone Project 1 Groupon Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
CVE-2017-17574 1 Care Clone Project 1 Care Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
CVE-2017-17572 1 Amazon Clone Project 1 Amazon Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
CVE-2017-17571 1 Foodpanda Clone Project 1 Foodpanda Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
CVE-2017-17570 1 Expedia Clone Project 1 Expedia Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter.
CVE-2020-19447 1 Jdownloads 1 Jdownloads 2020-09-29 5.0 MEDIUM 7.5 HIGH
SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_files_id parameter.
CVE-2020-13504 1 Aveva 1 Edna Enterprise Data Historian 2020-09-29 7.5 HIGH 9.8 CRITICAL
Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.
CVE-2020-19451 1 Jdownloads 1 Jdownloads 2020-09-28 5.0 MEDIUM 7.5 HIGH
SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, updateLog function via the X-forwarded-for Header parameter.
CVE-2020-19450 1 Jdownloads 1 Jdownloads 2020-09-28 5.0 MEDIUM 7.5 HIGH
SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, getUserLimits function in the list parameter.
CVE-2020-19455 1 Jdownloads 1 Jdownloads 2020-09-28 5.0 MEDIUM 7.5 HIGH
SQL injection exists in the jdownloads 3.2.63 component for Joomla! via components/com_jdownloads/helpers/categories.php, order function via the filter_order parameter.
CVE-2020-13505 1 Aveva 1 Edna Enterprise Data Historian 2020-09-25 7.5 HIGH 9.8 CRITICAL
Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.
CVE-2020-25751 1 Corephp 1 Pago Commerce 2020-09-24 6.5 MEDIUM 8.8 HIGH
The paGO Commerce plugin 2.5.9.0 for Joomla! allows SQL Injection via the administrator/index.php?option=com_pago&view=comments filter_published parameter.
CVE-2020-0344 1 Google 1 Android 2020-09-21 2.1 LOW 5.5 MEDIUM
In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-140729887
CVE-2020-0352 1 Google 1 Android 2020-09-21 2.1 LOW 5.5 MEDIUM
In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-132074310
CVE-2020-23833 1 Projectworlds 1 House Rental 2020-09-18 7.5 HIGH 9.8 CRITICAL
Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on the hosting webserver via a malicious index.php POST request.
CVE-2019-4671 1 Ibm 1 Maximo Asset Management 2020-09-16 6.5 MEDIUM 6.3 MEDIUM
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171437.