Vulnerabilities (CVE)

Filtered by CWE-89
Angry Yack Logo
Total 18012 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-35245 1 Flamingo Project 1 Flamingo 2024-11-21 7.5 HIGH 9.8 CRITICAL
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser.
CVE-2020-35244 1 Flamingo Project 1 Flamingo 2024-11-21 7.5 HIGH 9.8 CRITICAL
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addGroup.
CVE-2020-35243 1 Flamingo Project 1 Flamingo 2024-11-21 7.5 HIGH 9.8 CRITICAL
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb.
CVE-2020-35242 1 Flamingo Project 1 Flamingo 2024-11-21 7.5 HIGH 9.8 CRITICAL
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAndMemory.
CVE-2020-35151 1 Phpgurukul 1 Online Marriage Registration System 2024-11-21 6.5 MEDIUM 8.8 HIGH
The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.
CVE-2020-35122 1 Keysight 1 Keysight Database Connector 2024-11-21 4.0 MEDIUM 7.5 HIGH
An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could bypass the access controls for using a saved database connection profile to submit arbitrary SQL against a saved database connection.
CVE-2020-35012 1 Pixelite 1 Events Manager 2024-11-21 6.5 MEDIUM 7.2 HIGH
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection
CVE-2020-29493 1 Dell 2 Emc Avamar Server, Emc Integrated Data Protection Appliance 2024-11-21 7.5 HIGH 10.0 CRITICAL
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database, causing unauthorized read and write access to application data. Exploitation may lead to leakage or deletion of sensitive backup data; hence the severity is Critical. Dell EMC recommends customers to upgrade at the earlies ...

Show More

CVE-2020-29474 1 Egavilanmedia 1 Egm Address Book 2024-11-21 7.5 HIGH 9.8 CRITICAL
EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
CVE-2020-29472 1 Egavilanmedia 1 Under Construction Page With Cpanel 2024-11-21 7.5 HIGH 9.8 CRITICAL
EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
CVE-2020-29437 1 Orangehrm 1 Orangehrm 2024-11-21 5.5 MEDIUM 8.1 HIGH
SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php loadMorePostsForm[profileUserId] parameter to the buzz/loadMoreProfile endpoint.
CVE-2020-29287 1 Car Rental Management System Project 1 Car Rental Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter in view_car.php or the car_id parameter in booking.php.
CVE-2020-29285 1 Point Of Sales In Php\/pdo Project 1 Point Of Sales In Php\/pdo 2024-11-21 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter to edit_category.php.
CVE-2020-29284 1 Multi Restaurant Table Reservation System Project 1 Multi Restaurant Table Reservation System 2024-11-21 7.5 HIGH 9.8 CRITICAL
The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.
CVE-2020-29283 1 Online Doctor Appointment Booking System Php And Mysql Project 1 Online Doctor Appointment Booking System Php And Mysql 2024-11-21 7.5 HIGH 9.8 CRITICAL
An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.
CVE-2020-29282 1 Bloodx Project 1 Bloodx 2024-11-21 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication.
CVE-2020-29280 1 Victor Cms Project 1 Victor Cms 2024-11-21 7.5 HIGH 9.8 CRITICAL
The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.
CVE-2020-29228 1 Egavilanmedia 1 User Registration And Login System With Admin Panel 2024-11-21 5.0 MEDIUM 7.5 HIGH
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.
CVE-2020-29214 1 Alumni Management System Project 1 Alumni Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php.
CVE-2020-29163 1 Rainbowfishsoftware 1 Pacsone Server 2024-11-21 6.5 MEDIUM 8.8 HIGH
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by SQL injection.
CVE-2020-29147 1 Wayang-cms Project 1 Wayang-cms 2024-11-21 5.0 MEDIUM 7.5 HIGH
A SQL injection vulnerability in wy_controlls/wy_side_visitor.php of Wayang-CMS v1.0 allows attackers to obtain sensitive database information.
CVE-2020-29143 1 Open-emr 1 Openemr 2024-11-21 6.5 MEDIUM 7.2 HIGH
A SQL injection vulnerability in interface/reports/non_reported.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the form_code parameter.
CVE-2020-29142 1 Open-emr 1 Openemr 2024-11-21 6.5 MEDIUM 7.2 HIGH
A SQL injection vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the schedule_facility parameter when restrict_user_facility=on is in global settings.
CVE-2020-29140 1 Open-emr 1 Openemr 2024-11-21 6.5 MEDIUM 7.2 HIGH
A SQL injection vulnerability in interface/reports/immunization_report.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the form_code parameter.
CVE-2020-29139 1 Open-emr 1 Openemr 2024-11-21 6.5 MEDIUM 7.2 HIGH
A SQL injection vulnerability in interface/main/finder/patient_select.php from library/patient.inc in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the searchFields parameter.
CVE-2020-29015 1 Fortinet 1 Fortiweb 2024-11-21 7.5 HIGH 9.8 CRITICAL
A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing a malicious SQL statement.
CVE-2020-29011 1 Fortinet 1 Fortisandbox 2024-11-21 6.5 MEDIUM 8.8 HIGH
Instances of SQL Injection vulnerabilities in the checksum search and MTA-quarantine modules of FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated attacker to execute unauthorized code on the underlying SQL interpreter via specifically crafted HTTP requests.
CVE-2020-28994 1 Karenderia Multiple Restaurant System Project 1 Karenderia Multiple Restaurant System 2024-11-21 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifying and leaking all contents of the database.
CVE-2020-28960 1 Cct95 1 Chichen Tech Cms 2024-11-21 10.0 HIGH 9.8 CRITICAL
Chichen Tech CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the file product_list.php via the id and cid parameters.
CVE-2020-28860 1 Openasset 1 Digital Asset Management 2024-11-21 6.5 MEDIUM 8.8 HIGH
OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.
CVE-2020-28702 1 Pybbs Project 1 Pybbs 2024-11-21 5.0 MEDIUM 7.5 HIGH
A SQL injection vulnerability in TopicMapper.xml of PybbsCMS v5.2.1 allows attackers to access sensitive database information.
CVE-2020-28679 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 6.5 MEDIUM 8.8 HIGH
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
CVE-2020-28657 1 Bittacora 1 Bpanel 2024-11-21 7.5 HIGH 9.8 CRITICAL
In bPanel 2.0, the administrative ajax endpoints (aka ajax/aj_*.php) are accessible without authentication and allow SQL injections, which could lead to platform compromise.
CVE-2020-28413 1 Mantisbt 1 Mantisbt 2024-11-21 4.0 MEDIUM 5.3 MEDIUM
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.
CVE-2020-28183 1 Water Billing System Project 1 Water Billing System 2024-11-21 10.0 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php.
CVE-2020-28172 1 Simple College Project 1 Simple College 2024-11-21 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin authentication mechanism in college_website/admin/ajax.php?action=login, thus gaining access to the website administrative panel.
CVE-2020-28138 1 Online Clothing Store Project 1 Online Clothing Store 2024-11-21 7.5 HIGH 9.8 CRITICAL
SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php.
CVE-2020-28133 1 Simple Grocery Store Sales And Inventory Sales Project 1 Simple Grocery Store Sales And Inventory System 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in sales_inventory/login.php.
CVE-2020-28115 1 Web-audimex 1 Audimexee 2024-11-21 6.5 MEDIUM 8.8 HIGH
SQL Injection vulnerability in "Documents component" found in AudimexEE version 14.1.0 allows an attacker to execute arbitrary SQL commands via the object_path parameter.
CVE-2020-28103 1 Chshcms 1 Cscms 2024-11-21 7.5 HIGH 9.8 CRITICAL
cscms v4.1 allows for SQL injection via the "page_del" function.