Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2015-0842
yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass.
Yubiserver
Mitigation only
CRITICAL 9.8
CVE-2020-22669
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters an…
Debian Linux
Patch available
CRITICAL 9.8
CVE-2022-29155EPSS 64%
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL s…
Debian Linux
2.5.12 / 2.6.2+
CRITICAL 9.8
CVE-2022-26651EPSS 7%
An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escapi…
Debian Linux
16.25.2 / 18.11.2+
HIGH 8.8
CVE-2022-24407
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
Debian Linux
after 2.1.27
HIGH 7.4
CVE-2020-25638
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can…
Debian Linux
5.3.20 / 5.4.24+
HIGH 8.0
CVE-2020-10802
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly esca…
Debian Linux
4.9.5 / 5.0.2+
MEDIUM 5.4
CVE-2020-10803
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XS…
Debian Linux
4.9.5 / 5.0.2+
HIGH 8.8
CVE-2020-5504EPSS 39%
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of…
Debian Linux
4.9.4 / 5.0.1+
CRITICAL 9.8
CVE-2013-2745
An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0
Debian Linux
1.1.0+
MEDIUM 6.5
CVE-2019-18890
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted obj…
Debian Linux
3.3.10+
CRITICAL 9.8
CVE-2019-12838
SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.
Debian Linux
after 18.08.7
CRITICAL 9.8
CVE-2019-7164
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
Debian Linux
after 1.2.17
HIGH 7.8
CVE-2019-7548
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
Debian Linux
Patch available
CRITICAL 9.8
CVE-2018-4056
An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a…
Debian Linux
4.5.0.9+
HIGH 8.8
CVE-2017-11509EPSS 6%
An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.
Debian Linux
No fix yet
CRITICAL 9.8
CVE-2018-7033
SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD.
Debian Linux
17.02.10.0 / 17.11.5.0+
CRITICAL 9.8
CVE-2014-4914
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL…
Debian Linux
1.12.7+
CRITICAL 9.8
CVE-2015-7695
The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL c…
Debian Linux
after 1.12.15
HIGH 7.5
CVE-2015-3427
Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted, which allows remote attackers t…
Debian Linux
after 0.12.1
HIGH 7.5
CVE-2014-9057
SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers t…
Debian Linux
after 5.17
HIGH 7.5
CVE-2014-9089
Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL commands vi…
Debian Linux
after 1.2.17
HIGH 7.5
CVE-2014-1609
Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters …
Debian Linux
after 1.2.15
HIGH 7.5
CVE-2014-1608
SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arb…
Debian Linux
after 1.2.15
CRITICAL 9.8
CVE-2014-2323EPSS 62%
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host nam…
Debian Linux
1.4.35+
HIGH 7.5
CVE-2013-5589
SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parame…
Debian Linux
after 0.8.8b
HIGH 7.5
CVE-2011-2688EPSS 6%
SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attac…
Debian Linux
after 3.2.5
HIGH 7.5
CVE-2009-4015
Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitrary commands via shell metacha…
Lintian
Patch available
MEDIUM 6.5
CVE-2007-6170
SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x b…
Debian Linux
1.2.25 / 1.4.15+