Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness SQL InjectionCWE-89 × clear
Developer Hub MEDIUM 6.5
CVE-2026-3118

A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to insufficient input validation…

Mitigation only
Fix from $1,600 2026-02-25
Advanced Cluster Management For Kubernetes MEDIUM 6.5
CVE-2022-2238

A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets pa…

Mitigation only
Fix from $1,600 2022-09-01
Enterprise Linux HIGH 8.1
CVE-2021-3935

When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first e…

Fix: 1.16.1+
Fix from $1,950 2021-11-22
Build Of Quarkus MEDIUM 6.5
CVE-2019-14900

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API ca…

Fix: 7.8.0+
Fix from $1,600 2020-07-06
Enterprise Linux CRITICAL 9.8
CVE-2014-8089

SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows …

Fix: 1.12.9 / 2.2.8+
Fix from $2,300 2020-02-17
Openstack CRITICAL 9.1
CVE-2019-10141

A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability wa…

Fix: 5.0.2 / 6.0.3+
Fix from $2,300 2019-07-30
Openstack HIGH 7.5
CVE-2018-10915EPSS 5%

A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections…

Patch available
Fix from $1,950 2018-08-09
Satellite MEDIUM 6.5
CVE-2018-1096

An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an S…

Fix: 1.16.1+
Fix from $1,600 2018-04-05
Dashbuilder CRITICAL 9.8
CVE-2016-4999

SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuil…

Fix: after 0.5.0
Fix from $2,300 2016-08-05
Satellite HIGH 8.8
CVE-2016-3072

Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote auth…

Patch available
Fix from $1,950 2016-06-07
Cloudforms 3.1 Management Engine MEDIUM 6.5
CVE-2014-7814

SQL injection vulnerability in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 allows remote authenticated users to execute arbitrary SQL command…

Mitigation only
Fix from $1,600 2015-01-16
Cloudforms 3.0 Management Engine MEDIUM 6.5
CVE-2014-0137

SQL injection vulnerability in the saved_report_delete action in the ReportController in Red Hat CloudForms Management Engine (CFME) before 5.2.3.2 a…

Fix: after 5.2.3
Fix from $1,600 2014-05-14
Cloudforms Management Engine HIGH 7.5
CVE-2013-2050EPSS 16%

SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualizatio…

Fix: after 5.0
Fix from $1,950 2014-01-11
Enterprise Mrg HIGH 7.5
CVE-2013-4461

SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL comman…

Mitigation only
Fix from $1,950 2013-12-23
Openstack HIGH 7.5
CVE-2013-4386

Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL …

Fix: after 1.2.2
Fix from $1,950 2013-11-20
Enterprise Mrg HIGH 7.5
CVE-2012-2684

Multiple SQL injection vulnerabilities in the get_sample_filters_by_signature function in Cumin before 0.1.5444, as used in Red Hat Enterprise Messag…

Fix: after 0.1.5192-4
Fix from $1,950 2012-09-28