Vulnerability index

Browse CVEs

29 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Yubiserver CRITICAL 9.8
CVE-2015-0842

yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass.

Mitigation only
Fix from $2,300 2025-06-26
Debian Linux CRITICAL 9.8
CVE-2020-22669

Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters an…

Patch available
Fix from $2,300 2022-09-02
Debian Linux CRITICAL 9.8
CVE-2022-29155EPSS 64%

In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL s…

Fix: 2.5.12 / 2.6.2+
Fix from $2,300 2022-05-04
Debian Linux CRITICAL 9.8
CVE-2022-26651EPSS 7%

An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escapi…

Fix: 16.25.2 / 18.11.2+
Fix from $2,300 2022-04-15
Debian Linux HIGH 8.8
CVE-2022-24407

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

Fix: after 2.1.27
Fix from $1,950 2022-02-24
Debian Linux HIGH 7.4
CVE-2020-25638

A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can…

Fix: 5.3.20 / 5.4.24+
Fix from $1,950 2020-12-02
Debian Linux HIGH 8.0
CVE-2020-10802

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly esca…

Fix: 4.9.5 / 5.0.2+
Fix from $1,950 2020-03-22
Debian Linux MEDIUM 5.4
CVE-2020-10803

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XS…

Fix: 4.9.5 / 5.0.2+
Fix from $1,600 2020-03-22
Debian Linux HIGH 8.8
CVE-2020-5504EPSS 39%

In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of…

Fix: 4.9.4 / 5.0.1+
Fix from $1,950 2020-01-09
Debian Linux CRITICAL 9.8
CVE-2013-2745

An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0

Fix: 1.1.0+
Fix from $2,300 2019-12-04
Debian Linux MEDIUM 6.5
CVE-2019-18890

A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted obj…

Fix: 3.3.10+
Fix from $1,600 2019-11-21
Debian Linux CRITICAL 9.8
CVE-2019-12838

SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.

Fix: after 18.08.7
Fix from $2,300 2019-07-11
Debian Linux CRITICAL 9.8
CVE-2019-7164

SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

Fix: after 1.2.17
Fix from $2,300 2019-02-20
Debian Linux HIGH 7.8
CVE-2019-7548

SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.

Patch available
Fix from $1,950 2019-02-06
Debian Linux CRITICAL 9.8
CVE-2018-4056

An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a…

Fix: 4.5.0.9+
Fix from $2,300 2019-02-05
Debian Linux HIGH 8.8
CVE-2017-11509EPSS 6%

An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.

No fix yet
Fix from $1,950 2018-03-28
Debian Linux CRITICAL 9.8
CVE-2018-7033

SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD.

Fix: 17.02.10.0 / 17.11.5.0+
Fix from $2,300 2018-03-15
Debian Linux CRITICAL 9.8
CVE-2014-4914

The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL…

Fix: 1.12.7+
Fix from $2,300 2017-12-29
Debian Linux CRITICAL 9.8
CVE-2015-7695

The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL c…

Fix: after 1.12.15
Fix from $2,300 2016-06-07
Debian Linux HIGH 7.5
CVE-2015-3427

Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted, which allows remote attackers t…

Fix: after 0.12.1
Fix from $1,950 2015-05-14
Debian Linux HIGH 7.5
CVE-2014-9057

SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers t…

Fix: after 5.17
Fix from $1,950 2014-12-16
Debian Linux HIGH 7.5
CVE-2014-9089

Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL commands vi…

Fix: after 1.2.17
Fix from $1,950 2014-11-28
Debian Linux HIGH 7.5
CVE-2014-1609

Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters …

Fix: after 1.2.15
Fix from $1,950 2014-03-20
Debian Linux HIGH 7.5
CVE-2014-1608

SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arb…

Fix: after 1.2.15
Fix from $1,950 2014-03-18
Debian Linux CRITICAL 9.8
CVE-2014-2323EPSS 62%

SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host nam…

Fix: 1.4.35+
Fix from $2,300 2014-03-14
Debian Linux HIGH 7.5
CVE-2013-5589

SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parame…

Fix: after 0.8.8b
Fix from $1,950 2013-08-29
Debian Linux HIGH 7.5
CVE-2011-2688EPSS 6%

SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attac…

Fix: after 3.2.5
Fix from $1,950 2011-07-28
Lintian HIGH 7.5
CVE-2009-4015

Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitrary commands via shell metacha…

Patch available
Fix from $1,950 2010-02-02
Debian Linux MEDIUM 6.5
CVE-2007-6170

SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x b…

Fix: 1.2.25 / 1.4.15+
Fix from $1,600 2007-11-30