Vulnerabilities (CVE)

Filtered by CWE-89
Total 11593 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15564 1 Compassionuk 1 Compassion Switzerland 2019-08-27 7.5 HIGH 9.8 CRITICAL
The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py.
CVE-2019-10687 1 Kbpublisher 1 Kbpublisher 2019-08-27 7.5 HIGH 9.8 CRITICAL
KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?module=log id parameter, or an index.php?View=print&id[]= request.
CVE-2019-14937 1 Vanderbilt 1 Redcap 2019-08-27 6.0 MEDIUM 7.5 HIGH
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data.
CVE-2019-14430 1 Youphptube 1 Youphptube 2019-08-26 5.0 MEDIUM 5.3 MEDIUM
plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.
CVE-2019-15104 1 Zohocorp 1 Manageengine Applications Manager 2019-08-26 9.0 HIGH 8.8 HIGH
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.
CVE-2019-15535 1 Hostosm 1 Tasking Manager 2019-08-26 7.5 HIGH 9.8 CRITICAL
Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.
CVE-2019-15105 1 Zohocorp 1 Manageengine Applications Manager 2019-08-26 9.0 HIGH 8.8 HIGH
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.
CVE-2014-10387 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2019-08-26 7.5 HIGH 9.8 CRITICAL
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
CVE-2019-15534 1 Raml-module-builder Project 1 Raml-module-builder 2019-08-26 7.5 HIGH 9.8 CRITICAL
Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.
CVE-2017-18573 1 Simplerealtytheme 1 Simple Login Log 2019-08-26 7.5 HIGH 9.8 CRITICAL
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
CVE-2017-18571 1 Search Everything Project 1 Search Everything 2019-08-26 7.5 HIGH 9.8 CRITICAL
The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulnerability than CVE-2014-2316.
CVE-2016-10921 1 Ays-pro 1 Photo Gallery 2019-08-26 7.5 HIGH 9.8 CRITICAL
The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
CVE-2016-10916 1 Codepeople 1 Appointment Booking Calendar 2019-08-26 7.5 HIGH 9.8 CRITICAL
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
CVE-2015-9335 1 Bestwebsoft 1 Limit Attempts 2019-08-26 7.5 HIGH 9.8 CRITICAL
The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.
CVE-2016-10917 1 Search Everything Project 1 Search Everything 2019-08-26 7.5 HIGH 9.8 CRITICAL
The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CVE-2014-2316.
CVE-2017-18570 1 Cformsii Project 1 Cformsii 2019-08-23 7.5 HIGH 9.8 CRITICAL
The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.
CVE-2014-10379 1 Duplicate Post Project 1 Duplicate Post 2019-08-22 7.5 HIGH 9.8 CRITICAL
The duplicate-post plugin before 2.6 for WordPress has SQL injection.
CVE-2015-9330 1 Soflyy 1 Wp All Import 2019-08-22 7.5 HIGH 9.8 CRITICAL
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
CVE-2019-1010034 1 Deepsoft 1 Weblibrarian 2019-08-21 4.0 MEDIUM 6.5 MEDIUM
Deepwoods Software WebLibrarian 3.5.2 and earlier is affected by: SQL Injection. The impact is: Exposing the entire database. The component is: Function "AllBarCodes" (defined at database_code.php line 1018) is vulnerable to a boolean-based blind sql injection. This function call can be triggered by any user logged-in with at least Volunteer role or manage_circulation capabilities. PoC : /wordpress/wp-admin/admin.php?page=weblib-circulation-desk&orderby=title&order=DESC.
CVE-2015-9325 1 Bestwebsoft 1 Visitors Online 2019-08-21 7.5 HIGH 9.8 CRITICAL
The visitors-online plugin before 0.4 for WordPress has SQL injection.