Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

20,240 CVEs tagged with CWE-894,532 Critical, 8,498 High, 6,235 Medium, 974 Low, 1 Unrated.

CVE-2015-7569

Published Apr 24, 2017

SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_orderby" parameter.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7568

Published Apr 24, 2017

SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" param…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7991

Published Apr 22, 2017

Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7879

Published Apr 14, 2017

SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7878

Published Apr 14, 2017

SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read and write to the users database.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7717

Published Apr 14, 2017

SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users to execute arbitrary SQL comm…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8356

Published Apr 14, 2017

Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated users to execute arbitrary SQL commands via the (1) xls_prof…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6818

Published Apr 13, 2017

SQL injection vulnerability in SAP Business Intelligence platform before January 2017 allows remote attackers to obtain sensitive information, modify data, cause a denial of servi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-2555

Published Apr 13, 2017

SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friend…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-1914

Published Apr 13, 2017

Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4893

Published Apr 12, 2017

SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4337

Published Apr 12, 2017

SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-7564

Published Apr 12, 2017

Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7719

Published Apr 12, 2017

SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or w…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-6088

Published Apr 11, 2017

Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) displ…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-6028

Published Apr 10, 2017

Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-7581

Published Apr 7, 2017

SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involvi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-3886

Published Apr 7, 2017

A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing ar…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7410

Published Apr 3, 2017

Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote attackers to execute arbitrary SQL commands vi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7290

Published Mar 30, 2017

SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter t…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 15,876-15,900 of 20,240 CVEsPage 636 of 810