CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,914 vulnerabilities with CWE-89
CVE-2015-5052
CRITICAL
Sefrengo < 1.6.5 - SQL Injection
CVSS 9.8
CVE-2015-4724
HIGH
Concrete CMS 5.7.3.1 - SQL Injection
CVSS 8.8
CVE-2015-4627
CRITICAL
Pragyan CMS 3.0 - SQL Injection
CVSS 9.8
CVE-2015-3314
HIGH
WordPress Tune Library <1.5.5 - SQL Injection
CVSS 8.1
CVE-2015-3313
CRITICAL
WordPress Community Events <1.4 - SQL Injection
CVSS 9.8
CVE-2015-8334
HIGH
Huawei VCN500 <V100R002C00SPC201 - SQL Injection
CVSS 8.8
CVE-2015-7517
CRITICAL
WordPress Double Opt-In <2.0.9 - SQL Injection
CVSS 9.8
CVE-2015-8355
HIGH
Bitrix Orion <2.1.3 - SQL Injection
CVSS 8.8
CVE-2015-3616
CRITICAL
Fortinet FortiManager <5.0.11, <5.2.2 - SQL Injection
CVSS 9.8
CVE-2015-0782
CRITICAL
Novell ZENworks Configuration Management - SQL Injection via ScheduleQuery Method
CVSS 9.8
CVE-2015-0780
CRITICAL
Novell ZENworks Configuration Management - SQL Injection
CVSS 9.8
CVE-2015-2798
CRITICAL
Contact Form Maker 1.0.1 - SQL Injection via id Parameter
CVSS 9.8
CVE-2015-9098
CRITICAL
Redgate SQL Monitor < 3.10 and 4.x < 4.2 - Unauthenticated SQL Injection
CVSS 9.8
CVE-2015-7346
CRITICAL
ZCMS 1.1 - SQL Injection
CVSS 9.8
CVE-2015-7569
HIGH
Yeager CMS 1.2.1 - SQL Injection via pagedir_orderby Parameter
CVSS 8.8
CVE-2015-7568
CRITICAL
Yeager CMS 1.2.1 - SQL Injection via Password Recovery UserEmail Parameter
CVSS 9.8
CVE-2015-8356
HIGH
Bitrix mcart.xls <6.5.2 - SQL Injection
CVSS 8.0
CVE-2015-7564
CRITICAL
TeamPass < 2.1.24 - SQL Injection via Item Query or View Log Parameters
CVSS 9.8
CVE-2015-6028
HIGH
Castle Rock Computing SNMPc <2015-12-17 - SQL Injection
CVSS 8.8
CVE-2015-8974
CRITICAL
MyBB Merge System < 1.8.6 and MyBB < 1.6.18 and 1.8.x < 1.8.6 - SQL Injection in Group Promotions Module
CVSS 10.0
CVE-2015-4592
HIGH
eClinicalWorks Population Health - Authenticated SQL Injection via portalUserService.jsp
CVSS 8.8
CVE-2015-1000011
CRITICAL
WordPress Dukapress <2.5.9 - SQL Injection
CVSS 9.8
CVE-2015-1000003
CRITICAL
filedownload v1.4 - Blind SQL Injection
CVSS 9.8
CVE-2015-8157
HIGH
Symantec Embedded Security - SQL Injection
CVSS 8.8
CVE-2015-7695
CRITICAL
Zend Framework <1.12.16 - SQL Injection
CVSS 9.8
Details
Vulnerabilities
19,914
Exploit Likelihood
High