Vulnerabilities (CVE)

Filtered by CWE-89
Total 11593 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15574 1 Cipsoft 1 Gesior-aac 2019-09-03 7.5 HIGH 9.8 CRITICAL
Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php.
CVE-2019-15558 1 Xm-online 1 Xm\^online 2 - Common Utils And Endpoints 2019-08-30 7.5 HIGH 9.8 CRITICAL
XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java.
CVE-2019-15533 1 Xayr 1 Xenfcoresharp 2019-08-30 7.5 HIGH 9.8 CRITICAL
XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php.
CVE-2019-15658 1 Connect-pg-simple Project 1 Connect-pg-simple 2019-08-30 7.5 HIGH 7.3 HIGH
connect-pg-simple before 6.0.1 allows SQL injection if tableName or schemaName is untrusted data.
CVE-2019-15559 1 Hawn Project 1 Hawn 2019-08-29 7.5 HIGH 9.8 CRITICAL
DianoxDragon Hawn before 2019-07-10 allows SQL injection.
CVE-2019-15563 1 Ohdsi 1 Webapi 2019-08-29 7.5 HIGH 9.8 CRITICAL
Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtractionService.java.
CVE-2019-15570 1 Bedita 1 Bedita 2019-08-29 7.5 HIGH 9.8 CRITICAL
BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.
CVE-2019-15536 1 Youracclaim 1 Acclaim 2019-08-29 7.5 HIGH 9.8 CRITICAL
The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.
CVE-2015-9334 1 Email-newsletter Project 1 Email-newsletter 2019-08-29 7.5 HIGH 9.8 CRITICAL
The email-newsletter plugin through 20.15 for WordPress has SQL injection.
CVE-2012-6719 1 Sharebar Project 1 Sharebar 2019-08-28 7.5 HIGH 9.8 CRITICAL
The sharebar plugin before 1.2.2 for WordPress has SQL injection.
CVE-2019-15568 1 Idseq 1 Idseq-web 2019-08-28 7.5 HIGH 9.8 CRITICAL
idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels.
CVE-2019-15659 1 Genetechsolutions 1 Pie Register 2019-08-28 7.5 HIGH 9.8 CRITICAL
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
CVE-2015-9352 1 Wp-polls Project 1 Wp-polls 2019-08-28 7.5 HIGH 9.8 CRITICAL
The wp-polls plugin before 2.72 for WordPress has SQL injection.
CVE-2019-15537 1 Cesnet 1 Proxystatistics 2019-08-28 7.5 HIGH 9.8 CRITICAL
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
CVE-2019-15565 1 Webimpacto 1 Icommktconnector 2019-08-28 7.5 HIGH 9.8 CRITICAL
The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php.
CVE-2019-15567 1 Openforis 1 Arena 2019-08-28 7.5 HIGH 9.8 CRITICAL
OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.
CVE-2018-21003 1 Themekraft 1 Buddyforms 2019-08-28 7.5 HIGH 9.8 CRITICAL
The buddyforms plugin before 2.2.8 for WordPress has SQL injection.
CVE-2019-15556 1 Social Network Project 1 Social Network 2019-08-28 7.5 HIGH 9.8 CRITICAL
Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php.
CVE-2019-15561 1 Flashlingo Project 1 Flashlingo 2019-08-28 7.5 HIGH 9.8 CRITICAL
FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js.
CVE-2019-15566 1 Alfresco 1 Alfresco 2019-08-27 7.5 HIGH 9.8 CRITICAL
The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java.