Total
15911 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-7735 | 1 Afian | 1 Filerun | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=metadata§ion=cpanel&page=list_filetypes request. | |||||
CVE-2018-7734 | 1 Afian | 1 Filerun | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=users§ion=cpanel&page=list request. | |||||
CVE-2018-7732 | 1 Yxtcmf | 1 Yxtcmf | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in YxtCMF 3.1. SQL Injection exists in ShitiController.class.php via the ids array parameter to exam/shiti/delshiti.html. | |||||
CVE-2018-7666 | 1 Clip-bucket | 1 Clipbucket | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in ClipBucket before 4.0.0 Release 4902. SQL injection vulnerabilities exist in the actions/vote_channel.php channelId parameter, the ajax/commonAjax.php email parameter, and the ajax/commonAjax.php username parameter. | |||||
CVE-2018-7579 | 1 Yzmcms | 1 Yzmcms | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
\application\admin\controller\update_urls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to admin/update_urls/update_category_url.html. | |||||
CVE-2018-7538 | 1 Enalean | 1 Tuleap | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 allows attackers to execute arbitrary SQL commands. | |||||
CVE-2018-7528 | 1 Geutebrueck | 4 G-cam\/efd-2250, G-cam\/efd-2250 Firmware, Topfd-2125 and 1 more | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
An SQL injection vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which may allow an attacker to alter stored data. | |||||
CVE-2018-7501 | 1 Advantech | 4 Webaccess, Webaccess\/nms, Webaccess Dashboard and 1 more | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several SQL injection vulnerabilities have been identified, which may allow an attacker to disclose sensitive information from the host. | |||||
CVE-2018-7477 | 1 School Management Script Project | 1 School Management Script | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/Parent_module/parent_login.php. | |||||
CVE-2018-7474 | 1 Textpattern | 1 Textpattern | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php. | |||||
CVE-2018-7463 | 1 Asanhamayesh | 1 Asanhamayesh Cms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in files.php in the "files" component in ASANHAMAYESH CMS 3.4.6 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter. | |||||
CVE-2018-7319 | 1 Os Property Real Estate Project | 1 Os Property Real Estate | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter. | |||||
CVE-2018-7318 | 2 Belitsoft, Oracle | 2 Checklist, Data Integrator | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order parameter. | |||||
CVE-2018-7315 | 1 Harmistechnology | 1 Ek Rishta | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, caste, or country parameter. | |||||
CVE-2018-7314 | 1 Mlwebtechnologies | 1 Prayercenter | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429. | |||||
CVE-2018-7313 | 1 Cwjoomla | 1 Cw Tags | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter. | |||||
CVE-2018-7312 | 1 Alexandriabooklibrary | 1 Alexandria Book Library | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter. | |||||
CVE-2018-7282 | 1 Titool | 1 Printmonitor | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based blind SQLi. | |||||
CVE-2018-7269 | 1 Yiiframework | 1 Yii | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input. | |||||
CVE-2018-7180 | 1 Saxum2003 | 1 Astro | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter. |