Vulnerability index

Browse CVEs

60 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Superset HIGH 8.8
CVE-2023-49736

A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Sup…

Fix: 2.1.2 / 3.0.2+
Fix from $1,950 2023-12-19
Cocoon CRITICAL 9.8
CVE-2022-45135

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon:…

Fix: 2.3.0+
Fix from $2,300 2023-11-30
Submarine CRITICAL 9.8
CVE-2023-37924EPSS 7%

Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now …

Fix: 0.8.0+
Fix from $2,300 2023-11-22
Inlong CRITICAL 9.8
CVE-2023-35088

Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This i…

Fix: after 1.7.0
Fix from $2,300 2023-07-25
Log4cxx HIGH 8.8
CVE-2023-31038

SQL injection in Log4cxx when using the ODBC appender to send log messages to a database.  No fields sent to the database were properly escaped for S…

Fix: 1.1.0+
Fix from $1,950 2023-05-08
Inlong MEDIUM 5.3
CVE-2023-30465

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This i…

Mitigation only
Fix from $1,600 2023-04-11
Fineract MEDIUM 6.3
CVE-2023-25197

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation apache fineract. Aut…

Fix: after 1.8.2
Fix from $1,600 2023-03-28
Age HIGH 8.1
CVE-2022-45786

There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for PostgreSQL 11 & AGE for Postgre…

Fix: after 1.1.0
Fix from $1,950 2023-02-04
Superset MEDIUM 5.4
CVE-2022-41703

A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subquerie…

Fix: after 1.5.2
Fix from $1,600 2023-01-16
Superset CRITICAL 9.8
CVE-2022-27479

Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.

Fix: 1.4.2+
Fix from $2,300 2022-04-13
Log4j CRITICAL 9.8
CVE-2022-23305EPSS 67%

By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from …

Fix: 1.2.18.2+
Fix from $2,300 2022-01-18
Dolphinscheduler HIGH 8.8
CVE-2021-27644

In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data so…

Fix: 1.3.6+
Fix from $1,950 2021-11-01
Superset HIGH 8.8
CVE-2021-41971

Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malic…

Fix: after 1.3.0
Fix from $1,950 2021-10-18
Skywalking CRITICAL 9.8
CVE-2020-13921EPSS 33%

**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.

Patch available
Fix from $2,300 2020-08-05
Kylin CRITICAL 9.8
CVE-2020-13926

Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, wh…

Fix: 3.1.0+
Fix from $2,300 2020-07-14
Skywalking HIGH 7.5
CVE-2020-9483EPSS 35%

**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability…

Fix: after 6.6.0
Fix from $1,950 2020-06-30
Kylin HIGH 8.8
CVE-2020-1937

Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.

Fix: after 2.6.4
Fix from $1,950 2020-02-24
Virtual Computing Lab HIGH 7.2
CVE-2018-11774

Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in…

Fix: after 2.5
Fix from $1,950 2019-07-29
Virtual Computing Lab HIGH 7.2
CVE-2018-11772

Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privileg…

Fix: after 2.5
Fix from $1,950 2019-07-29
Fineract CRITICAL 9.8
CVE-2018-11800EPSS 5%

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts …

Fix: 1.3.0+
Fix from $2,300 2019-06-11
Fineract CRITICAL 9.8
CVE-2018-11801EPSS 5%

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related…

Fix: 1.3.0+
Fix from $2,300 2019-06-11
Fineract CRITICAL 9.8
CVE-2018-1290

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL para…

Mitigation only
Fix from $2,300 2018-04-20
Fineract HIGH 8.8
CVE-2018-1289

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain…

Mitigation only
Fix from $1,950 2018-04-20
Fineract HIGH 8.1
CVE-2018-1291

Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with …

Mitigation only
Fix from $1,950 2018-04-20
Fineract HIGH 8.1
CVE-2018-1292

Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/u…

Mitigation only
Fix from $1,950 2018-04-20
Hive CRITICAL 9.1
CVE-2018-1282EPSS 6%

This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup th…

Fix: after 2.3.2
Fix from $2,300 2018-04-05
Fineract HIGH 8.8
CVE-2017-5663

In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissio…

Mitigation only
Fix from $1,950 2017-12-14
Openmeetings HIGH 8.8
CVE-2017-7681

Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the …

Mitigation only
Fix from $1,950 2017-07-17
Ranger HIGH 7.2
CVE-2016-2174

SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQ…

Mitigation only
Fix from $1,950 2016-06-13
Jetspeed HIGH 8.8
CVE-2016-0710EPSS 52%

Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL co…

Fix: after 2.3.0
Fix from $1,950 2016-04-11