Vulnerability index

Browse CVEs

29 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
CRITICAL 9.8 CVE-2015-0842 yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass. Yubiserver Mitigation only Fix from $2,3002025-06-26 CRITICAL 9.8 CVE-2020-22669 Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters an… Debian Linux Patch available Fix from $2,3002022-09-02 CRITICAL 9.8 CVE-2022-29155EPSS 64% In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL s… Debian Linux 2.5.12 / 2.6.2+ Fix from $2,3002022-05-04 CRITICAL 9.8 CVE-2022-26651EPSS 7% An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escapi… Debian Linux 16.25.2 / 18.11.2+ Fix from $2,3002022-04-15 HIGH 8.8 CVE-2022-24407 In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement. Debian Linux after 2.1.27 Fix from $1,9502022-02-24 HIGH 7.4 CVE-2020-25638 A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can… Debian Linux 5.3.20 / 5.4.24+ Fix from $1,9502020-12-02 HIGH 8.0 CVE-2020-10802 In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly esca… Debian Linux 4.9.5 / 5.0.2+ Fix from $1,9502020-03-22 MEDIUM 5.4 CVE-2020-10803 In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XS… Debian Linux 4.9.5 / 5.0.2+ Fix from $1,6002020-03-22 HIGH 8.8 CVE-2020-5504EPSS 39% In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of… Debian Linux 4.9.4 / 5.0.1+ Fix from $1,9502020-01-09 CRITICAL 9.8 CVE-2013-2745 An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0 Debian Linux 1.1.0+ Fix from $2,3002019-12-04 MEDIUM 6.5 CVE-2019-18890 A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted obj… Debian Linux 3.3.10+ Fix from $1,6002019-11-21 CRITICAL 9.8 CVE-2019-12838 SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection. Debian Linux after 18.08.7 Fix from $2,3002019-07-11 CRITICAL 9.8 CVE-2019-7164 SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. Debian Linux after 1.2.17 Fix from $2,3002019-02-20 HIGH 7.8 CVE-2019-7548 SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled. Debian Linux Patch available Fix from $1,9502019-02-06 CRITICAL 9.8 CVE-2018-4056 An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a… Debian Linux 4.5.0.9+ Fix from $2,3002019-02-05 HIGH 8.8 CVE-2017-11509EPSS 6% An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement. Debian Linux No fix yet Fix from $1,9502018-03-28 CRITICAL 9.8 CVE-2018-7033 SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD. Debian Linux 17.02.10.0 / 17.11.5.0+ Fix from $2,3002018-03-15 CRITICAL 9.8 CVE-2014-4914 The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL… Debian Linux 1.12.7+ Fix from $2,3002017-12-29 CRITICAL 9.8 CVE-2015-7695 The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL c… Debian Linux after 1.12.15 Fix from $2,3002016-06-07 HIGH 7.5 CVE-2015-3427 Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted, which allows remote attackers t… Debian Linux after 0.12.1 Fix from $1,9502015-05-14 HIGH 7.5 CVE-2014-9057 SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers t… Debian Linux after 5.17 Fix from $1,9502014-12-16 HIGH 7.5 CVE-2014-9089 Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL commands vi… Debian Linux after 1.2.17 Fix from $1,9502014-11-28 HIGH 7.5 CVE-2014-1609 Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters … Debian Linux after 1.2.15 Fix from $1,9502014-03-20 HIGH 7.5 CVE-2014-1608 SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arb… Debian Linux after 1.2.15 Fix from $1,9502014-03-18 CRITICAL 9.8 CVE-2014-2323EPSS 62% SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host nam… Debian Linux 1.4.35+ Fix from $2,3002014-03-14 HIGH 7.5 CVE-2013-5589 SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parame… Debian Linux after 0.8.8b Fix from $1,9502013-08-29 HIGH 7.5 CVE-2011-2688EPSS 6% SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attac… Debian Linux after 3.2.5 Fix from $1,9502011-07-28 HIGH 7.5 CVE-2009-4015 Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitrary commands via shell metacha… Lintian Patch available Fix from $1,9502010-02-02 MEDIUM 6.5 CVE-2007-6170 SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x b… Debian Linux 1.2.25 / 1.4.15+ Fix from $1,6002007-11-30