CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,913 vulnerabilities with CWE-89
CVE-2016-6611
HIGH
phpMyAdmin <4.6.4, <4.4.15.8, <4.0.10.17 - SQL Injection
CVSS 8.1
CVE-2016-2873
HIGH
IBM QRadar Security Information and Event Manager < 7.1.0 - Authenticated SQL Injection
CVSS 8.8
CVE-2016-2950
MEDIUM
IBM BigFix Remote Control < 9.1.3 - Authenticated SQL Injection
CVSS 6.5
CVE-2016-9481
CRITICAL
Exponent CMS 2.4.0 - SQL Injection via content_id Parameter
CVSS 9.8
CVE-2016-9287
CRITICAL
Exponent CMS 2.4.0 patch1 - SQL Injection
CVSS 9.8
CVE-2016-8908
HIGH
dotcms < 3.3 - Authenticated SQL Injection via Orderby Parameter
CVSS 8.8
CVE-2016-8907
HIGH
dotcms < 3.3 - Authenticated SQL Injection via Orderby Parameter
CVSS 8.8
CVE-2016-8906
HIGH
dotcms < 3.3 - Authenticated SQL Injection via Orderby Parameter
CVSS 8.8
CVE-2016-8905
HIGH
dotcms < 3.3 - Authenticated SQL Injection via JSONTags Servlet Sort Parameter
CVSS 8.8
CVE-2016-8904
HIGH
dotcms < 3.3 - Authenticated SQL Injection via Orderby Parameter
CVSS 8.8
CVE-2016-8903
HIGH
dotcms < 3.3 - Authenticated SQL Injection via Orderby Parameter
CVSS 8.8
CVE-2016-8902
CRITICAL
dotcms < 3.3 - Unauthenticated SQL Injection via CategoriesServlet Sort Parameter
CVSS 9.8
CVE-2016-9288
CRITICAL
Exponent CMS <2.4.0 - SQL Injection
CVSS 9.8
CVE-2016-9283
HIGH
Exponent CMS <2.4.0 - SQL Injection
CVSS 7.5
CVE-2016-9282
HIGH
Exponent CMS <2.4.0 - SQL Injection
CVSS 7.5
CVE-2016-9272
CRITICAL
Exponent CMS <2.4.0 - SQL Injection
CVSS 9.1
CVE-2016-9242
HIGH
Exponent CMS 2.4.0 - Authenticated SQL Injection via Content Type or Subtype Parameter
CVSS 8.8
CVE-2016-9184
HIGH
Exponent CMS 2.4.0 - SQL Injection and Information Disclosure via Table Name Manipulation
CVSS 7.5
CVE-2016-6453
HIGH
Cisco ISE <1.3 - Privilege Escalation
CVSS 7.3
CVE-2016-9135
HIGH
Exponent CMS 2.3.9 - SQL Injection in Help Controller Version Parameter
CVSS 7.5
CVE-2016-9134
HIGH
Exponent CMS 2.3.9 - SQL Injection in expPaginator.php Order Parameter
CVSS 7.5
CVE-2016-7453
CRITICAL
Exponent CMS < 2.3.9 - SQL Injection via Pixidou Image Editor
CVSS 9.8
CVE-2016-8582
CRITICAL
AlienVault OSSIM & USM <5.3.2 - SQL Injection
CVSS 9.8
CVE-2016-7919
HIGH
Moodle 3.1.2 - Exposure of Sensitive Information via SQL Injection in Installation Process
CVSS 7.5
CVE-2016-6443
HIGH
Cisco Prime Infrastructure - SQL Injection
CVSS 8.8
Details
Vulnerabilities
19,913
Exploit Likelihood
High