Vulnerability index

Browse CVEs

60 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
HIGH 8.8 CVE-2023-49736 A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Sup… Superset 2.1.2 / 3.0.2+ Fix from $1,9502023-12-19 CRITICAL 9.8 CVE-2022-45135 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon:… Cocoon 2.3.0+ Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-37924EPSS 7% Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now … Submarine 0.8.0+ Fix from $2,3002023-11-22 CRITICAL 9.8 CVE-2023-35088 Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This i… Inlong after 1.7.0 Fix from $2,3002023-07-25 HIGH 8.8 CVE-2023-31038 SQL injection in Log4cxx when using the ODBC appender to send log messages to a database.  No fields sent to the database were properly escaped for S… Log4cxx 1.1.0+ Fix from $1,9502023-05-08 MEDIUM 5.3 CVE-2023-30465 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This i… Inlong Mitigation only Fix from $1,6002023-04-11 MEDIUM 6.3 CVE-2023-25197 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation apache fineract. Aut… Fineract after 1.8.2 Fix from $1,6002023-03-28 HIGH 8.1 CVE-2022-45786 There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for PostgreSQL 11 & AGE for Postgre… Age after 1.1.0 Fix from $1,9502023-02-04 MEDIUM 5.4 CVE-2022-41703 A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subquerie… Superset after 1.5.2 Fix from $1,6002023-01-16 CRITICAL 9.8 CVE-2022-27479 Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue. Superset 1.4.2+ Fix from $2,3002022-04-13 CRITICAL 9.8 CVE-2022-23305EPSS 67% By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from … Log4j 1.2.18.2+ Fix from $2,3002022-01-18 HIGH 8.8 CVE-2021-27644 In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data so… Dolphinscheduler 1.3.6+ Fix from $1,9502021-11-01 HIGH 8.8 CVE-2021-41971 Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malic… Superset after 1.3.0 Fix from $1,9502021-10-18 CRITICAL 9.8 CVE-2020-13921EPSS 33% **Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases. Skywalking Patch available Fix from $2,3002020-08-05 CRITICAL 9.8 CVE-2020-13926 Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, wh… Kylin 3.1.0+ Fix from $2,3002020-07-14 HIGH 7.5 CVE-2020-9483EPSS 35% **Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability… Skywalking after 6.6.0 Fix from $1,9502020-06-30 HIGH 8.8 CVE-2020-1937 Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries. Kylin after 2.6.4 Fix from $1,9502020-02-24 HIGH 7.2 CVE-2018-11774 Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in… Virtual Computing Lab after 2.5 Fix from $1,9502019-07-29 HIGH 7.2 CVE-2018-11772 Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privileg… Virtual Computing Lab after 2.5 Fix from $1,9502019-07-29 CRITICAL 9.8 CVE-2018-11800EPSS 5% SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts … Fineract 1.3.0+ Fix from $2,3002019-06-11 CRITICAL 9.8 CVE-2018-11801EPSS 5% SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related… Fineract 1.3.0+ Fix from $2,3002019-06-11 CRITICAL 9.8 CVE-2018-1290 In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL para… Fineract Mitigation only Fix from $2,3002018-04-20 HIGH 8.8 CVE-2018-1289 In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain… Fineract Mitigation only Fix from $1,9502018-04-20 HIGH 8.1 CVE-2018-1291 Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with … Fineract Mitigation only Fix from $1,9502018-04-20 HIGH 8.1 CVE-2018-1292 Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/u… Fineract Mitigation only Fix from $1,9502018-04-20 CRITICAL 9.1 CVE-2018-1282EPSS 6% This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup th… Hive after 2.3.2 Fix from $2,3002018-04-05 HIGH 8.8 CVE-2017-5663 In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissio… Fineract Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-7681 Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the … Openmeetings Mitigation only Fix from $1,9502017-07-17 HIGH 7.2 CVE-2016-2174 SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQ… Ranger Mitigation only Fix from $1,9502016-06-13 HIGH 8.8 CVE-2016-0710EPSS 52% Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL co… Jetspeed after 2.3.0 Fix from $1,9502016-04-11