Total
18012 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-6491 | 1 Risi | 1 Gestao De Horarios | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
RISI Gestao de Horarios v3201.09.08 rev.23 allows SQL Injection.
|
|||||
| CVE-2019-6296 | 1 Skymoonlabs | 1 Cleanto | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Cleanto 5.0 has SQL Injection via the assets/lib/export_ajax.php id parameter.
|
|||||
| CVE-2019-6295 | 1 Skymoonlabs | 1 Cleanto | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Cleanto 5.0 has SQL Injection via the assets/lib/service_method_ajax.php service_id parameter.
|
|||||
| CVE-2019-6259 | 1 Icmsdev | 1 Icms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data_id parameter.
|
|||||
| CVE-2019-6127 | 1 Xiaocms | 1 Xiaocms | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
An issue was discovered in XiaoCms 20141229. It allows admin/index.php?c=database table[] SQL injection. This can be used for PHP code execution via "INTO OUTFILE" with a .php filename.
|
|||||
| CVE-2019-6012 | 1 Tms-outsource | 1 Wpdatatables Lite | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
|||||
| CVE-2019-5996 | 1 Panasonic | 1 Video Insight Vms | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
SQL injection vulnerability in the Video Insight VMS 7.3.2.5 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
|||||
| CVE-2019-5991 | 1 Cybozu | 1 Garoon | 2024-11-21 | 6.5 MEDIUM | 7.6 HIGH |
|
SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
|||||
| CVE-2019-5934 | 1 Cybozu | 1 Garoon | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.0 allows attacker with administrator rights to execute arbitrary SQL commands via the Log Search function of application 'logging'.
|
|||||
| CVE-2019-5893 | 1 Nelson-it | 1 Open Source Erp | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter.
|
|||||
| CVE-2019-5722 | 1 Portier | 1 Portier | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handling, it has various SQL injections, including on the login form, and on the search form for a key ring number.
|
|||||
| CVE-2019-5720 | 1 Frontaccounting | 1 Frontaccounting | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
includes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field that can allow the attacker to grab the entire database of the application via the void_transaction.php filterType parameter.
|
|||||
| CVE-2019-5715 | 1 Silverstripe | 1 Silverstripe | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject.
|
|||||
| CVE-2019-5488 | 1 Earclink | 1 Espcms-p8 | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
EARCLINK ESPCMS-P8 has SQL injection in the install_pack/index.php?ac=Member&at=verifyAccount verify_key parameter. install_pack/espcms_public/espcms_db.php may allow retrieving sensitive information from the ESPCMS database.
|
|||||
| CVE-2019-5476 | 1 Nextcloud | 1 Lookup-server | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able to execute arbitrary SQL commands.
|
|||||
| CVE-2019-5454 | 1 Nextcloud | 1 Nextcloud | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account.
|
|||||
| CVE-2019-5151 | 1 Youphptube | 1 Youphptube | 2024-11-21 | 7.5 HIGH | 10.0 CRITICAL |
|
An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to code execution. An attacker can send an HTTP request to trigger this vulnerability.
|
|||||
| CVE-2019-5150 | 1 Youphptube | 1 Youphptube | 2024-11-21 | 6.8 MEDIUM | 8.9 HIGH |
|
An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. When the "VideoTags" plugin is enabled, a specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to code execution. An attacker can send an HTTP request to trigger this vulnerability.
|
|||||
| CVE-2019-5123 | 1 Youphptube | 1 Youphptube | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Specially crafted web requests can cause SQL injections in YouPHPTube 7.6. An attacker can send a web request with Parameter dir in /objects/pluginSwitch.json.php.
|
|||||
| CVE-2019-5122 | 1 Youphptube | 1 Youphptube | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
SQL injection vulnerabilities exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with Parameter name in /objects/pluginSwitch.json.php.
|
|||||
| CVE-2019-5121 | 1 Youphptube | 1 Youphptube | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
SQL injection vulnerabilities exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with Parameter uuid in /objects/pluginSwitch.json.php
|
|||||
| CVE-2019-5120 | 1 Youphptube | 1 Youphptube | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
An exploitable SQL injection vulnerability exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain configurations, access the underlying operating system.
|
|||||
| CVE-2019-5119 | 1 Youphptube | 1 Youphptube | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
An exploitable SQL injection vulnerability exist in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain configurations, access the underlying operating system.
|
|||||
| CVE-2019-5117 | 1 Youphptube | 1 Youphptube | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Exploitable SQL injection vulnerabilities exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain configuration, access the underlying operating system.
|
|||||
| CVE-2019-5116 | 1 Youphptube | 1 Youphptube | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
An exploitable SQL injection vulnerability exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause a SQL injection. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain configuration, access the underlying operating system.
|
|||||
| CVE-2019-5114 | 1 Youphptube | 1 Youphptube | 2024-11-21 | 9.3 HIGH | 9.9 CRITICAL |
|
An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and,in certain configuration, access the underlying operating system.
|
|||||
| CVE-2019-5112 | 1 Formalms | 1 Formalms | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_status was confirmed to suffer from SQL injections and could be exploited by authenticated attackers. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and, in certain configurations, access the underlying operating sy ...
Show More |
|||||
| CVE-2019-5111 | 1 Formalms | 1 Formalms | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_cat was confirmed to suffer from SQL injections and could be exploited by authenticated attackers. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and, in certain configurations, access the underlying operating syste ...
Show More |
|||||
| CVE-2019-5110 | 1 Formalms | 1 Formalms | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Exploitable SQL injection vulnerabilities exist in the authenticated portion of Forma LMS 2.2.1. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and, in certain configurations, access the underlying operating system.
|
|||||
| CVE-2019-5109 | 1 Formalms | 1 Formalms | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Exploitable SQL injection vulnerabilities exists in the authenticated portion of Forma LMS 2.2.1. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and, in certain configurations, access the underlying operating system.
|
|||||
| CVE-2019-5070 | 1 Epignosishq | 1 Efront Lms | 2024-11-21 | 6.4 MEDIUM | 6.5 MEDIUM |
|
An exploitable SQL injection vulnerability exists in the unauthenticated portion of eFront LMS, versions v5.2.12 and earlier. Specially crafted web request to login page can cause SQL injections, resulting in data compromise. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.
|
|||||
| CVE-2019-4752 | 1 Ibm | 2 Emptoris Spend Analysis, Emptoris Strategic Supply Management Platform | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
IBM Emptoris Spend Analysis and IBM Emptoris Strategic Supply Management Platform 10.1.0.x, 10.1.1.x, and 10.1.3.x is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 173348.
|
|||||
| CVE-2019-4680 | 1 Ibm | 1 Sterling B2b Integrator | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.2.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171733.
|
|||||
| CVE-2019-4671 | 1 Ibm | 1 Maximo Asset Management | 2024-11-21 | 6.5 MEDIUM | 6.3 MEDIUM |
|
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171437.
|
|||||
| CVE-2019-4669 | 1 Ibm | 2 Business Automation Workflow, Business Process Manager | 2024-11-21 | 6.5 MEDIUM | 6.3 MEDIUM |
|
IBM Business Process Manager 8.5.7.0 through 8.5.7.0 2017.06, 8.6.0.0 through 8.6.0.0 CF2018.03, and IBM Business Automation Workflow 18.0.0.1 through 19.0.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 171254.
|
|||||
| CVE-2019-4651 | 1 Ibm | 1 Jazz Reporting Service | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962.
|
|||||
| CVE-2019-4650 | 1 Ibm | 1 Maximo Asset Management | 2024-11-21 | 6.5 MEDIUM | 6.3 MEDIUM |
|
IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170961.
|
|||||
| CVE-2019-4598 | 1 Ibm | 1 Sterling B2b Integrator | 2024-11-21 | 6.5 MEDIUM | 6.3 MEDIUM |
|
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 167881.
|
|||||
| CVE-2019-4597 | 1 Ibm | 1 Sterling B2b Integrator | 2024-11-21 | 6.5 MEDIUM | 6.3 MEDIUM |
|
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 167880.
|
|||||
| CVE-2019-4575 | 1 Ibm | 1 Financial Transaction Manager | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 166801.
|
|||||