CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,889 vulnerabilities with CWE-89
CVE-2018-1282
CRITICAL
Apache Hive JDBC Driver 0.7.1-2.3.2 - SQL Injection via PreparedStatement Argument Bypass
CVSS 9.1
CVE-2018-9309
CRITICAL
zzcms 8.2 - SQL Injection via dl/dl_sendsms.php id Parameter
CVSS 9.8
CVE-2018-9247
CRITICAL
Gxlcms QY v1.0.0713 - SQL Injection via upsql Function
CVSS 9.8
CVE-2018-9230
CRITICAL
OpenResty < 1.13.6.1 - Parameter Overflow Bypass via URI Parameter Handling
CVSS 9.8
CVE-2018-8820
HIGH
Square 9 GlobalForms 6.2.x - SQL Injection
CVSS 7.5
CVE-2018-8802
HIGH
Unisys ClearPath ePortal Manager < 17.0a.31 and ePortal-2200 < 2.2.81 - SQL Injection
CVSS 8.1
CVE-2018-8967
CRITICAL
zzcms 8.2 - SQL Injection via adv2.php id Parameter
CVSS 9.8
CVE-2018-8943
CRITICAL
PHPSHE 1.6 - SQL Injection via Userbank Parameter
CVSS 9.8
CVE-2018-7528
CRITICAL
Geutebruck G-Cam/EFD-2250 and TopFD-2125 - SQL Injection
CVSS 9.1
CVE-2018-7269
CRITICAL
Yii 2.0.0-2.0.14 - SQL Injection via findByCondition in ActiveRecord
CVSS 9.8
CVE-2018-6843
HIGH
Kentico Xperience 10.0-10.0.50 - Authenticated SQL Injection
CVSS 7.2
CVE-2018-7033
CRITICAL
SchedMD Slurm < 17.02.10 and 17.11.x < 17.11.5 - SQL Injection
CVSS 9.8
CVE-2018-6230
MEDIUM
Trend Micro Email Encryption Gateway 5.5 - SQL Injection via Search Configuration Script
CVSS 6.8
CVE-2018-6229
CRITICAL
Trend Micro Email Encryption Gateway 5.5 - SQL Injection via Edit Policy Script
CVSS 9.8
CVE-2018-6228
CRITICAL
Trend Micro Email Encryption Gateway 5.5 - SQL Injection via Policy Script
CVSS 9.8
CVE-2018-8045
HIGH
Joomla! 3.5.0-3.8.5 - SQL Injection in User Notes List View
CVSS 8.8
CVE-2018-6329
CRITICAL
Unitrends Backup < 10.1.10 - SQL Injection and Remote Code Execution via Authentication Bypass
CVSS 9.8
CVE-2018-7474
CRITICAL
Textpattern < 4.6.2 - SQL Injection via qty Parameter
CVSS 9.8
CVE-2018-1000131
CRITICAL
WP Support Plus Responsive Ticket System < 9.0.2 - Unauthenticated SQL Injection via Email Cookie Parameter
CVSS 9.8
CVE-2018-7538
CRITICAL
Tuleap < 9.18 - SQL Injection in Tracker Functionality
CVSS 9.8
CVE-2018-8057
CRITICAL
Western Bridge Cobub Razor 0.8.0 - SQL Injection
CVSS 9.8
CVE-2018-7735
HIGH
Afian FileRun <2018.02.13 - SQL Injection
CVSS 7.2
CVE-2018-7734
HIGH
Afian FileRun <2018.02.13 - SQL Injection
CVSS 7.2
CVE-2018-7732
CRITICAL
YxtCMF < 3.1 - SQL Injection via ShitiController ids Parameter
CVSS 9.8
CVE-2018-7666
CRITICAL
ClipBucket < 4.0.0 - SQL Injection via channelId, email, or username Parameter
CVSS 9.8
Details
Vulnerabilities
19,889
Exploit Likelihood
High