CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,889 vulnerabilities with CWE-89
CVE-2018-14066
CRITICAL
Android - SQL Injection via wappush Content Provider
CVSS 9.8
CVE-2018-14012
CRITICAL
WolfSight CMS 3.2 - SQL Injection via PATH_INFO
CVSS 9.8
CVE-2018-10197
CRITICAL
ELO ELOenterprise/ELOprofessional <10.18.040 - SQL Injection
CVSS 9.8
CVE-2018-13850
CRITICAL
Firebase Cloud Messaging + Advance Admin Panel < 2017-10-26 - SQL Injection via Login Username Parameter
CVSS 9.8
CVE-2018-12977
HIGH
SoftExpert Excellence Suite 2.0 - Authenticated SQL Injection via cddocument Parameter
CVSS 8.8
CVE-2018-13450
CRITICAL
Dolibarr 7.0.3 - SQL Injection via Status Batch Parameter
CVSS 9.8
CVE-2018-13449
CRITICAL
Dolibarr ERP/CRM 7.0.3 - SQL Injection via statut_buy Parameter
CVSS 9.8
CVE-2018-13448
CRITICAL
Dolibarr 7.0.3 - SQL Injection via country_id Parameter
CVSS 9.8
CVE-2018-13447
CRITICAL
Dolibarr ERP/CRM 7.0.3 - SQL Injection via statut Parameter
CVSS 9.8
CVE-2018-3754
HIGH
query-mysql 0.0.0-0.0.2 - SQL Injection
CVSS 8.8
CVE-2018-13116
CRITICAL
zzcms 8.3 - SQL Injection via tablename Parameter
CVSS 9.8
CVE-2018-11643
HIGH
Dialogic PowerMedia XMS <= 3.5 - Authenticated SQL Injection via filterPattern Parameter
CVSS 8.8
CVE-2018-7774
HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-7773
HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-7772
HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-7769
HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-7768
HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-7767
HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-7766
HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-7765
HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-13050
CRITICAL
Zoho ManageEngine Applications Manager 13.x < 13800 - SQL Injection via j_username Parameter
CVSS 9.8
CVE-2018-13049
HIGH
GLPI 9.2.0-9.3.0 - SQL Injection via LIMIT Clause in Computer Search
CVSS 8.8
CVE-2018-12464
CRITICAL
Micro Focus Secure Messaging Gateway <471 - SQL Injection
CVSS 10.0
CVE-2018-12912
HIGH
HongCMS 3.0.0 - SQL Injection via Database Empty Table URI Parameter
CVSS 7.2
CVE-2018-1000558
MEDIUM
OCS Inventory NG ocsreports <2.4.1 - SQL Injection
CVSS 6.5
Details
Vulnerabilities
19,889
Exploit Likelihood
High