CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,889 vulnerabilities with CWE-89
CVE-2018-11309
CRITICAL
MemberMouse < 2.2.8 - Unauthenticated Blind SQL Injection via Coupon Code Parameter
CVSS 9.8
CVE-2018-11515
CRITICAL
wpForo < 1.4.5 - SQL Injection via Forum Search Parameter
CVSS 9.8
CVE-2018-6410
CRITICAL
MachForm - SQL Injection via Download Page q Parameter
CVSS 9.8
CVE-2018-10350
HIGH
Trend Micro Smart Protection Server (Standalone) 3.x - SQL Injection
CVSS 8.8
CVE-2018-11470
HIGH
iScripts eSwap 2.4 - SQL Injection via User Panel Search Told Parameter
CVSS 8.8
CVE-2018-11444
CRITICAL
EasyService Billing 1.0 - SQL Injection via jobcard-ongoing.php q Parameter
CVSS 9.8
CVE-2018-11414
HIGH
BearAdmin 0.5 - SQL Injection via Admin Log User ID Parameter
CVSS 8.8
CVE-2018-10595
MEDIUM
ReadA <1.1.0.2 - Privilege Escalation
CVSS 6.3
CVE-2018-10593
MEDIUM
DB Manager <3.0.1.0 - Privilege Escalation
CVSS 5.6
CVE-2018-11231
HIGH
Divido - SQL Injection
CVSS 8.1
CVE-2018-10356
HIGH
Trend Micro Email Encryption Gateway 5.5 - RCE
CVSS 8.8
CVE-2018-10353
MEDIUM
Trend Micro Email Encryption Gateway 5.5 - SQL Injection
CVSS 6.5
CVE-2018-10352
HIGH
Trend Micro Email Encryption Gateway 5.5 - SQL Injection
CVSS 8.8
CVE-2018-10351
HIGH
Trend Micro Email Encryption Gateway 5.5 - SQL Injection
CVSS 8.8
CVE-2018-9019
CRITICAL
Dolibarr < 7.0.2 - SQL Injection via sortfield Parameter
CVSS 9.8
CVE-2018-10094
CRITICAL
Dolibarr < 7.0.2 - SQL Injection via Integer Parameter
CVSS 9.8
CVE-2018-6493
HIGH
HP Network Operations Management Ultimate 2017.07-2018.02 & Network Automation 10.00-10.50 - Remote SQL Injection
CVSS 8.8
CVE-2018-6494
MEDIUM
Micro Focus Service Manager 9.30-9.51 - SQL Injection
CVSS 5.4
CVE-2018-11373
CRITICAL
iScripts eSwap 2.4 - SQL Injection via User Panel ToId Parameter
CVSS 9.8
CVE-2018-11372
CRITICAL
iScripts eSwap 2.4 - SQL Injection via User Panel ToId Parameter
CVSS 9.8
CVE-2018-11369
CRITICAL
PbootCMS 1.0.9 - SQL Injection via ParserController.php scode Parameter
CVSS 9.8
CVE-2018-9250
HIGH
OpenEMR < 5.0.1.1 - Authenticated SQL Injection via newlistname Parameter
CVSS 8.8
CVE-2018-10759
CRITICAL
ProjectPier < 0.8.8 - Remote File Inclusion and SQL Injection via id Parameter
CVSS 9.8
CVE-2018-10738
HIGH
Nagios XI 5.2.0-5.2.9 - SQL Injection via admin/menuaccess.php chbKey1 Parameter
CVSS 7.2
CVE-2018-10737
HIGH
Nagios XI 5.2.0-5.2.9 - SQL Injection via Logbook Search Parameter
CVSS 7.2
Details
Vulnerabilities
19,889
Exploit Likelihood
High