Skip to main content

CWE archive

CWE-89 CVEs

Programmatic archive

19,895 CVEs tagged with CWE-894,425 Critical, 8,379 High, 6,141 Medium, 949 Low, 1 Unrated.

CVE-2013-4467

Published Mar 11, 2014

Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3961

Published Mar 11, 2014

SQL injection vulnerability in edit_event.php in Simple PHP Agenda before 2.2.9 allows remote authenticated users to execute arbitrary SQL commands via the eventid parameter.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6290

Published Mar 11, 2014

SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL commands via the q parameter to admin/admin_search/. NOTE:…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2318

Published Mar 11, 2014

SQL injection vulnerability in ATCOM Netvolution 3 allows remote attackers to execute arbitrary SQL commands via the m parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2317

Published Mar 9, 2014

SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table parameter. NOTE: some of these de…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1945

Published Mar 9, 2014

SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the add_value parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2046

Published Mar 9, 2014

SQL injection vulnerability in lib/bookmarks.php in ownCloud Server 4.5.x before 4.5.11 and 5.x before 5.0.6 allows remote authenticated users to execute arbitrary SQL commands vi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2045

Published Mar 9, 2014

SQL injection vulnerability in lib/db.php in ownCloud Server 5.0.x before 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1893

Published Mar 9, 2014

SQL injection vulnerability in addressbookprovider.php in ownCloud Server before 5.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2245

Published Mar 5, 2014

SQL injection vulnerability in the News module in CMS Made Simple (CMSMS) before 1.11.10 allows remote authenticated users with the "Modify News" permission to execute arbitrary S…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2238

Published Mar 5, 2014

SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitr…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3478

Published Mar 5, 2014

SQL injection vulnerability in Apptha WordPress Video Gallery 2.0, 1.6, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the playid paramete…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6331

Published Mar 5, 2014

SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6302

Published Mar 5, 2014

SQL injection vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2211

Published Mar 3, 2014

SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 before 3.3.0 allows remote attackers to execute arbitrary SQL commands via the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2498

Published Mar 1, 2014

SQL injection vulnerability in the login page in flexycms/modules/user/user_manager.php in SimpleHRM 2.3, 2.2, and earlier allows remote attackers to execute arbitrary SQL command…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1854

Published Feb 27, 2014

SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free plugin 3.9 through 3.9.4 for WordPress allows remote attacke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1597

Published Feb 27, 2014

SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remote attackers to execute arbitrary SQL commands via the objID…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0821

Published Feb 27, 2014

SQL injection vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to execute arbitrary SQL commands…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0080

Published Feb 20, 2014

SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/cast.rb in Active Record in Ruby on Rails 4.0.x before 4.0.3, and 4.1.0.beta1, when Po…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0734

Published Feb 20, 2014

SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remot…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0729

Published Feb 13, 2014

SQL injection vulnerability in the Enterprise Mobility Application (EMApp) interface in Cisco Unified Communications Manager (UCM) allows remote attackers to execute arbitrary SQL…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0728

Published Feb 13, 2014

SQL injection vulnerability in the Java database interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL comma…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 16,176-16,200 of 19,895 CVEsPage 648 of 796