Total
18012 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-11452 | 1 Whatsns | 1 Whatsns | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
whatsns 4.0 allows index.php?admin_category/remove.html cid[] SQL injection.
|
|||||
| CVE-2019-11451 | 1 Whatsns | 1 Whatsns | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
whatsns 4.0 allows index.php?inform/add.html qid SQL injection.
|
|||||
| CVE-2019-11450 | 1 Whatsns | 1 Whatsns | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
whatsns 4.0 allows index.php?question/ajaxadd.html title SQL injection.
|
|||||
| CVE-2019-11448 | 1 Zohocorp | 1 Manageengine Applications Manager | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
|
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file.
|
|||||
| CVE-2019-11363 | 1 Prophecyinternational | 1 Snare Central | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
A SQL injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to execute arbitrary SQL commands via the AgentConsole/UserGroupQuery.php ShowUser parameter.
|
|||||
| CVE-2019-11362 | 1 Rocboss | 1 Rocboss | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
app/controllers/frontend/PostController.php in ROCBOSS V2.2.1 has SQL injection via the Post:doReward score paramter, as demonstrated by the /do/reward/3 URI.
|
|||||
| CVE-2019-11196 | 1 Vpcsbd | 1 Integrated University Management System | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
|
An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allows unauthenticated, remote attackers to gain administrator privileges via the Teachers Web Panel (TWP) User ID or Password field. If exploited, the attackers could perform any actions with administrator privileges (e.g., enumerate/delete all the students' personal information or modify various settings).
|
|||||
| CVE-2019-11057 | 1 Vtiger | 1 Vtiger Crm | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.
|
|||||
| CVE-2019-10916 | 1 Siemens | 4 Simatic Pcs 7, Simatic Wincc, Simatic Wincc \(tia Portal\) and 1 more | 2024-11-21 | 9.0 HIGH | 8.8 HIGH |
|
A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.3 Upd 19), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd11), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP2 with WinCC V7.4 SP1 Upd11), SIMATIC WinCC (TIA Portal) V13 (All versions), SIMATIC WinCC (TIA Portal) V14 (All versions < V14 SP1 Upd 9), SIMATIC WinCC (TIA Portal) V15 (All versions < V15.1 Upd 3), SIMATIC WinCC Runtime Professional ...
Show More |
|||||
| CVE-2019-10913 | 1 Sensiolabs | 1 Symfony | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.
|
|||||
| CVE-2019-10910 | 2 Drupal, Sensiolabs | 2 Drupal, Symfony | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.
|
|||||
| CVE-2019-10866 | 1 10web | 1 Form Maker | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.
|
|||||
| CVE-2019-10852 | 1 Computrols | 1 Computrols Building Automation Software | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start_pulling&id= substring.
|
|||||
| CVE-2019-10766 | 1 Pixie Project | 1 Pixie | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.
|
|||||
| CVE-2019-10763 | 1 Pimcore | 1 Pimcore | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) can achieve a SQL injection that can lead in data leakage. The vulnerability can be exploited via 'id', 'storeId', 'pageSize' and 'tables' parameters, using a payload for trigger a time based or error based sql injection.
|
|||||
| CVE-2019-10762 | 1 Medoo | 1 Medoo | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
columnQuote in medoo before 1.7.5 allows remote attackers to perform a SQL Injection due to improper escaping.
|
|||||
| CVE-2019-10757 | 1 Knexjs | 1 Knex | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.
|
|||||
| CVE-2019-10752 | 1 Sequelizejs | 1 Sequelize | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.
|
|||||
| CVE-2019-10749 | 1 Sequelizejs | 1 Sequelize | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the Postgres dialect.
|
|||||
| CVE-2019-10748 | 1 Sequelizejs | 1 Sequelize | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.
|
|||||
| CVE-2019-10708 | 1 S-cms | 1 S-cms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
|
|||||
| CVE-2019-10707 | 1 Mkcms Project | 1 Mkcms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
MKCMS V5.0 has SQL injection via the bplay.php play parameter.
|
|||||
| CVE-2019-10692 | 1 Codecabin | 1 Wp Go Maps | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.
|
|||||
| CVE-2019-10687 | 1 Kbpublisher | 1 Kbpublisher | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?module=log id parameter, or an index.php?View=print&id[]= request.
|
|||||
| CVE-2019-10671 | 1 Librenms | 1 Librenms | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queries, resulting in SQL injection. An authenticated attacker can subvert these database queries to extract or manipulate data, as demonstrated by the graph.php sort parameter.
|
|||||
| CVE-2019-10664 | 1 Domoticz | 1 Domoticz | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.
|
|||||
| CVE-2019-10663 | 1 Grandstream | 2 Ucm6204, Ucm6204 Firmware | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodeblueGroup API call to the /cgi? URI.
|
|||||
| CVE-2019-10653 | 1 Hsycms | 1 Hsycms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
An issue was discovered in Hsycms V1.1. There is a SQL injection vulnerability via a /news/*.html page.
|
|||||
| CVE-2019-10262 | 1 Bluecms Project | 1 Bluecms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in the admin folder, and is not wrapped in single quotes, resulting in injection around the escape of magic quotes.
|
|||||
| CVE-2019-10232 | 1 Teclib-edition | 1 Gestionnaire Libre De Parc Informatique | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.
|
|||||
| CVE-2019-10208 | 1 Postgresql | 1 Postgresql | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 where arbitrary SQL statements can be executed given a suitable SECURITY DEFINER function. An attacker, with EXECUTE permission on the function, can execute arbitrary SQL as the owner of the function.
|
|||||
| CVE-2019-10141 | 2 Openstack, Redhat | 3 Ironic-inspector, Enterprise Linux, Openstack | 2024-11-21 | 6.4 MEDIUM | 8.3 HIGH |
|
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint). Because the API is unauthenticated, the flaw could be exploited by an attacker with access to the network on which ironic-inspector is listening. Be ...
Show More |
|||||
| CVE-2019-10123 | 1 Ais | 2 Esel-server, Logistic Software | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker to execute arbitrary code in the context of the user of the MSSQL database. The default user for the database is the 'sa' user.
|
|||||
| CVE-2019-1010259 | 1 Saltstack | 2 Salt 2018, Salt 2019 | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt. The attack vector is: specially crafted password string. The fixed version is: 2018.3.4.
|
|||||
| CVE-2019-1010248 | 1 I-doit | 1 I-doit | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can exploit the vulnerability by sending a malicious HTTP POST request. The fixed version is: 1.12.1.
|
|||||
| CVE-2019-1010201 | 1 Jeesite | 1 Jeesite | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
Jeesite 1.2.7 is affected by: SQL Injection. The impact is: sensitive information disclosure. The component is: updateProcInsIdByBusinessId() function in src/main/java/com.thinkgem.jeesite/modules/act/ActDao.java has SQL Injection vulnerability. The attack vector is: network connectivity,authenticated. The fixed version is: 4.0 and later.
|
|||||
| CVE-2019-1010191 | 1 Marginalia Project | 1 Marginalia | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
marginalia < 1.6 is affected by: SQL Injection. The impact is: The impact is a injection of any SQL queries when a user controller argument is added as a component. The component is: Affects users that add a component that is user controller, for instance a parameter or a header. The attack vector is: Hacker inputs a SQL to a vulnerable vector(header, http parameter, etc). The fixed version is: 1.6.
|
|||||
| CVE-2019-1010153 | 1 Zzcms | 1 Zzcms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
zzcms 8.3 and earlier is affected by: SQL Injection. The impact is: sql inject. The component is: zs/subzs.php.
|
|||||
| CVE-2019-1010148 | 1 Zzcms | 1 Zzcms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
zzcms version 8.3 and earlier is affected by: SQL Injection. The impact is: zzcms File Delete to Code Execution.
|
|||||
| CVE-2019-1010104 | 1 Techytalk | 1 Quick Chat | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Crafted ajax request.
|
|||||