Total
14524 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-24132 | 1 10web | 1 Slider | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" is turn on for other users) to perform a SQL Injection attacks. | |||||
CVE-2021-24131 | 1 Cleantalk | 1 Anti-spam | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+). | |||||
CVE-2021-24130 | 1 Flippercode | 1 Wp Google Map | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+). | |||||
CVE-2021-24125 | 1 Contact Form Submissions Project | 1 Contact Form Submissions | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf7_contact_form GET parameter when submitting a filter request as a high privilege user (admin+) | |||||
CVE-2021-24007 | 1 Fortinet | 1 Fortimail | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | |||||
CVE-2021-23837 | 1 Flatcore | 1 Flatcore | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
An issue was discovered in flatCore before 2.0.0 build 139. A time-based blind SQL injection was identified in the selected_folder HTTP request body parameter for the acp interface. The affected parameter (which retrieves the file contents of the specified folder) was found to be accepting malicious user input without proper sanitization, thus leading to SQL injection. Database related information can be successfully retrieved. | |||||
CVE-2021-23405 | 1 Pimcore | 1 Pimcore | 2024-11-21 | 6.5 MEDIUM | 8.3 HIGH |
This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the ClassificationstoreController class. | |||||
CVE-2021-23352 | 1 Madge Project | 1 Madge | 2024-11-21 | 7.5 HIGH | 8.6 HIGH |
This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image(), .svg() or .dot() functions are called, is executed by the childprocess.exec function. | |||||
CVE-2021-23276 | 1 Eaton | 3 Intelligent Power Manager, Intelligent Power Manager Virtual Appliance, Intelligent Power Protector | 2024-11-21 | 6.5 MEDIUM | 7.1 HIGH |
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit the vulnerability. Successful exploitation of this vulnerability can allow attackers to add users in the data base. | |||||
CVE-2021-23230 | 1 Gallagher | 1 Command Centre | 2024-11-21 | 3.5 LOW | 9.9 CRITICAL |
A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); 8.10 versions prior to 8.10.1284 (MR7); version 8.00 and prior versions. | |||||
CVE-2021-23214 | 3 Fedoraproject, Postgresql, Redhat | 6 Fedora, Postgresql, Enterprise Linux and 3 more | 2024-11-21 | 5.1 MEDIUM | 8.1 HIGH |
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. | |||||
CVE-2021-23040 | 1 F5 | 1 Big-ip Advanced Firewall Manager | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
On BIG-IP AFM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This issue is exposed only when BIG-IP AFM is provisioned. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |||||
CVE-2021-22859 | 1 Eic | 1 E-document System | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary commands without privilege. | |||||
CVE-2021-22856 | 1 Changjia Property Management System Project | 1 Changjia Property Management System | 2024-11-21 | 5.0 MEDIUM | 9.8 CRITICAL |
The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into the parameters in Cookie and obtain data in the database without privilege. | |||||
CVE-2021-22854 | 1 Hr Portal Project | 1 Hr Portal | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The HR Portal of Soar Cloud System fails to filter specific parameters. Remote attackers can inject SQL syntax and obtain all data in the database without privilege. | |||||
CVE-2021-22852 | 1 Hgiga | 1 Oaklouds Openid | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain database schema and data. | |||||
CVE-2021-22851 | 1 Hgiga | 1 Oaklouds Openid | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data. | |||||
CVE-2021-22848 | 1 Hgiga | 4 Msr45 Isherlock-antispam, Msr45 Isherlock-user, Ssr45 Isherlock-antispam and 1 more | 2024-11-21 | 7.5 HIGH | 7.0 HIGH |
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege. | |||||
CVE-2021-22847 | 1 Hyweb | 1 Hycms-j1 | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
Hyweb HyCMS-J1's API fail to filter POST request parameters. Remote attackers can inject SQL syntax and execute commands without privilege. | |||||
CVE-2021-22658 | 1 Advantech | 1 Iview | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'. |