Total
18012 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-38574 | 1 Foxitsoftware | 2 Foxit Reader, Phantompdf | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.
|
|||||
| CVE-2021-38481 | 1 Auvesy | 1 Versiondog | 2024-11-21 | 7.5 HIGH | 8.1 HIGH |
|
The scheduler service running on a specific TCP port enables the user to start and stop jobs. There is no sanitation of the supplied JOB ID provided to the function. An attacker may send a malicious payload that can enable the user to execute another SQL expression by sending a specific string.
|
|||||
| CVE-2021-38393 | 1 Deltaww | 1 Diaenergie | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
|
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.
|
|||||
| CVE-2021-38391 | 1 Deltaww | 1 Diaenergie | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
|
A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.
|
|||||
| CVE-2021-38390 | 1 Deltaww | 1 Diaenergie | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
|
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.
|
|||||
| CVE-2021-38324 | 1 Smartypantsplugins | 1 Sp Rental Manager | 2024-11-21 | 5.0 MEDIUM | 8.2 HIGH |
|
The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3.
|
|||||
| CVE-2021-38303 | 1 Surelinesystems | 1 Sureedge Migrator | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
A SQL injection vulnerability exists in Sureline SUREedge Migrator 7.0.7.29360.
|
|||||
| CVE-2021-38302 | 1 Newsletter Project | 1 Newsletter | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.
|
|||||
| CVE-2021-38176 | 1 Sap | 4 Landscape Transformation, Landscape Transformation Replication Server, S\/4hana and 1 more | 2024-11-21 | 9.0 HIGH | 8.8 HIGH |
|
Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system.
|
|||||
| CVE-2021-38168 | 1 Roxy-wi | 1 Roxy-wi | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Roxy-WI through 5.2.2.0 allows authenticated SQL injection via select_servers.
|
|||||
| CVE-2021-38167 | 1 Roxy-wi | 1 Roxy-wi | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication.
|
|||||
| CVE-2021-38159 | 1 Progress | 1 Moveit Transfer | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
In certain Progress MOVEit Transfer versions before 2021.0.4 (aka 13.0.4), SQL injection in the MOVEit Transfer web application could allow an unauthenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, or execute SQL statements that alter or delete database elements, via crafted strings sent to unique MOVEit T ...
Show More |
|||||
| CVE-2021-38145 | 1 Formtools | 1 Core | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user (client) tries to export a form with data, e.g., manipulation of modules/export_manager/export.php?export_group_id=1&export_group_1_results=all&export_type_id=1.
|
|||||
| CVE-2021-37832 | 1 Digitaldruid | 1 Hoteldruid | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.
|
|||||
| CVE-2021-37808 | 1 Phpgurukul | 1 News Portal | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
|
SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap to further the exploitation for extracting sensitive information from the database.
|
|||||
| CVE-2021-37807 | 1 Phpgurukul | 1 Online Shopping Portal | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.
|
|||||
| CVE-2021-37806 | 1 Phpgurukul | 1 Vehicle Parking Management System | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
|
An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. The system is vulnerable to time-based SQL injection on multiple endpoints. Based on the SLEEP(N) function payload that will sleep for a number of seconds used on the (1) editid , (2) viewid, and (3) catename parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap to further the ...
Show More |
|||||
| CVE-2021-37803 | 1 Online Covid Vaccination Scheduler System Project | 1 Online Covid Vaccination Scheduler System | 2024-11-21 | 9.3 HIGH | 8.1 HIGH |
|
An SQL Injection vulnerability exists in Sourcecodester Online Covid Vaccination Scheduler System 1.0 via the username in lognin.php .
|
|||||
| CVE-2021-37749 | 1 Hexagongeospatial | 1 Geomedia Webmap | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
|
MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (within sourceItems) parameter to the GetMap method.
|
|||||
| CVE-2021-37737 | 1 Arubanetworks | 1 Clearpass Policy Manager | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
A remote SQL injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.
|
|||||
| CVE-2021-37614 | 1 Progress | 1 Moveit Transfer | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
In certain Progress MOVEit Transfer versions before 2021.0.3 (aka 13.0.3), SQL injection in the MOVEit Transfer web application could allow an authenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, or execute SQL statements that alter or delete database elements, via crafted strings sent to unique MOVEit Tra ...
Show More |
|||||
| CVE-2021-37599 | 1 Nuance | 1 Winscribe Dictation | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
The exporter/Login.aspx login form in the Exporter in Nuance Winscribe Dictation 4.1.0.99 is vulnerable to SQL injection that allows a remote, unauthenticated attacker to read the database (and execute code in some situations) via the txtPassword parameter.
|
|||||
| CVE-2021-37593 | 1 Peel | 1 Peel Shopping | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
|
PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the execution of predefined SQL commands. Upon a successful SQL injection attack, an attacker can read sensitive data from the database and possibly modify database data.
|
|||||
| CVE-2021-37589 | 1 Virtuasoftware | 1 Cobranca | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
Virtua Cobranca before 12R allows SQL Injection on the login page.
|
|||||
| CVE-2021-37558 | 1 Centreon | 1 Centreon | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to execute arbitrary SQL commands via the host_name and service_description parameters. The vulnerability can be exploited only when a valid Knowledge Base URL is configured on the Knowledge Base configuration page and points to a MediaWiki instance. This relates to the proxy feature in class/centreon-knowledge/ProceduresProxy.class.php and include/configu ...
Show More |
|||||
| CVE-2021-37557 | 1 Centreon | 1 Centreon | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/views/graphs/generateGraphs/generateImage.php index parameter.
|
|||||
| CVE-2021-37556 | 1 Centreon | 1 Centreon | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/reporting/dashboard/csvExport/csv_HostGroupLogs.php start and end parameters.
|
|||||
| CVE-2021-37538 | 1 Smartdatasoft | 1 Smartblog | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive controller, or the id_category parameter to the controllers/front/category.php category controller.
|
|||||
| CVE-2021-37522 | 1 Locke-bot Project | 1 Locke-bot | 2024-11-21 | N/A | 9.8 CRITICAL |
|
SQL injection vulnerability in HKing2802 Locke-Bot 2.0.2 allows remote attackers to run arbitrary SQL commands via crafted string to /src/db.js, /commands/mute.js, /modules/event/messageDelete.js.
|
|||||
| CVE-2021-37478 | 1 Naviwebs | 1 Navigatecms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, which results in arbitrary sql query execution in the backend database.
|
|||||
| CVE-2021-37477 | 1 Naviwebs | 1 Navigatecms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `children_order`, which results in arbitrary sql query execution in the backend database.
|
|||||
| CVE-2021-37476 | 1 Naviwebs | 1 Navigatecms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` through a post request, which results in arbitrary sql query execution in the backend database.
|
|||||
| CVE-2021-37475 | 1 Naviwebs | 1 Navigatecms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `template-properties-order`, which results in arbitrary sql query execution in the backend database.
|
|||||
| CVE-2021-37473 | 1 Naviwebs | 1 Navigatecms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request, which results in arbitrary sql query execution in the backend database.
|
|||||
| CVE-2021-37422 | 1 Zohocorp | 1 Manageengine Adselfservice Plus | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.
|
|||||
| CVE-2021-37413 | 1 Grandcom | 1 Dynweb | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify and sanitize user-provided strings.
|
|||||
| CVE-2021-37371 | 1 Online Student Admission System Project | 1 Online Student Admission System | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Online Student Admission System 1.0 is affected by an unauthenticated SQL injection bypass vulnerability in /admin/login.php.
|
|||||
| CVE-2021-37358 | 1 Seacms | 1 Seacms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".
|
|||||
| CVE-2021-37350 | 1 Nagios | 1 Nagios Xi | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.
|
|||||
| CVE-2021-37291 | 1 Kevinlab | 1 4st L-bems | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
|
|||||