Vulnerabilities (CVE)

Filtered by CWE-89
Total 11593 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-17376 1 Thephpfactory 1 Reverse Auction Factory 2018-11-14 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.
CVE-2018-17384 1 Thephpfactory 1 Swap Factory 2018-11-14 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
CVE-2018-17378 1 Thephpfactory 1 Penny Auction Factory 2018-11-14 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.
CVE-2018-17375 1 Joomlathat 1 Music Collection 2018-11-14 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
CVE-2015-8298 1 Rxtec 1 Rxadmin 2018-11-13 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to execute arbitrary SQL commands via the (1) loginpassword, (2) loginusername, (3) zusatzlicher, or (4) groupid parameter to index.htm, or the (5) rxtec cookie to index.htm.
CVE-2018-15904 1 A10networks 1 Acos Web Application Firewall 2018-11-09 7.5 HIGH 9.8 CRITICAL
A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8, and 4.1.2 before 4.1.2-P4 mishandles the configured rules for blocking SQL injection attacks, aka A10-2017-0008.
CVE-2018-14592 1 Cwjoomla 2 Cw Article Attachments Free, Cw Article Attachments Pro 2018-11-09 7.5 HIGH 9.8 CRITICAL
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.
CVE-2018-17129 1 Metinfo 1 Metinfo 2018-11-09 4.0 MEDIUM 4.9 MEDIUM
MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field.
CVE-2018-17110 1 Tecdiary 1 Simple Pos 2018-11-09 7.5 HIGH 9.8 CRITICAL
Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1.
CVE-2008-6124 2 Debian, Moodle 2 Debian Linux, Moodle 2018-11-08 7.5 HIGH N/A
SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers to execute arbitrary SQL commands via a crafted selected attempt.
CVE-2018-16822 1 Seacms 1 Seacms 2018-11-07 7.5 HIGH 9.8 CRITICAL
SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
CVE-2018-17035 1 Ucms Project 1 Ucms 2018-11-07 7.5 HIGH 9.8 CRITICAL
UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter.
CVE-2018-16436 1 Gxlcms 1 Gxlcms 2018-11-05 6.5 MEDIUM 7.2 HIGH
Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator.
CVE-2018-16389 1 E107 1 E107 2018-11-02 5.5 MEDIUM 6.5 MEDIUM
e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter.
CVE-2018-17136 1 Zzcms 1 Zzcms 2018-11-01 7.5 HIGH 9.8 CRITICAL
zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header.
CVE-2014-6045 1 Phpmyfaq 1 Phpmyfaq 2018-10-31 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via vectors involving the restore function.
CVE-2018-16385 1 Thinkphp 1 Thinkphp 2018-10-31 7.5 HIGH 9.8 CRITICAL
ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.
CVE-2008-3129 1 Catviz 1 Catviz 2018-10-30 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL commands via the (1) foreign_key_value parameter in the news page and (2) webpage parameter in the webpage_multi_edit form.
CVE-2014-8810 1 Wpsymposiumpro 1 Wp Symposium 2018-10-30 6.5 MEDIUM N/A
SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tray parameter in a getMailMessage action.
CVE-2012-2109 2 Buddypress, Wordpress 2 Buddypress, Wordpress 2018-10-30 7.5 HIGH N/A
SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attackers to execute arbitrary SQL commands via the page parameter in an activity_widget_filter action.