Total
15998 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-41971 | 1 Apache | 1 Superset | 2024-11-21 | 6.0 MEDIUM | 8.8 HIGH |
Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malicious authenticated user sends an http request with a custom URL. | |||||
CVE-2021-41965 | 1 Churchcrm | 1 Churchcrm | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue an arbitrary SQL command to the database through the unsanitized EN_tyid, theID and EID fields used when an Edit action on an existing record is being performed. | |||||
CVE-2021-41947 | 1 Intelliants | 1 Subrion Cms | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode. | |||||
CVE-2021-41942 | 1 Msvod | 1 Msvod Cms | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The Magic CMS MSVOD v10 video system has a SQL injection vulnerability. Attackers can use vulnerabilities to obtain sensitive information in the database. | |||||
CVE-2021-41932 | 1 Wolterskluwer | 1 Teammate\+ Audit | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
A blind SQL injection vulnerability in search form in TeamMate+ Audit version 28.0.19.0 allows any authenticated user to create malicious SQL injections, which can result in complete database compromise, gaining information about other users, unauthorized access to audit data etc. | |||||
CVE-2021-41931 | 1 Recruitment Management System Project | 1 Recruitment Management System | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnerable to SQL injection. The payloads 19424269' or '1309'='1309 and 39476597' or '2917'='2923 were each submitted in the id parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way. | |||||
CVE-2021-41928 | 1 Try My Recipe Project | 1 Try My Recipe | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code via the rid parameter to the view_recipe page. | |||||
CVE-2021-41920 | 1 Webtareas Project | 1 Webtareas | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker to access all the data in the database and obtain access to the webTareas application. | |||||
CVE-2021-41845 | 1 Thycotic | 1 Secret Server | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
A SQL injection issue was discovered in ThycoticCentrify Secret Server before 11.0.000007. The only affected versions are 10.9.000032 through 11.0.000006. | |||||
CVE-2021-41843 | 1 Open-emr | 1 Openemr | 2024-11-21 | 6.8 MEDIUM | 6.5 MEDIUM |
An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables of the database via the parameter provider_id, as demonstrated by the /interface/main/calendar/index.php?module=PostCalendar&func=search URI. | |||||
CVE-2021-41765 | 1 Montala | 1 Resourcespace | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote unauthenticated attackers to execute arbitrary SQL commands via the k parameter. This allows attackers to uncover the full contents of the ResourceSpace database, including user session cookies. An attacker who gets an admin user session cookie can use the session cookie to execute arbitrary code on the server. | |||||
CVE-2021-41756 | 1 Dynamicvision | 1 Dynamicmarkt | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
dynamicMarkt <= 3.10 is affected by SQL injection in the kat parameter of index.php. | |||||
CVE-2021-41755 | 1 Dynamicvision | 1 Dynamicmarkt | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
dynamicMarkt <= 3.10 is affected by SQL injection in the kat1 parameter of index.php. | |||||
CVE-2021-41754 | 1 Dynamicvision | 1 Dynamicmarkt | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
dynamicMarkt <= 3.10 is affected by SQL injection in the parent parameter of index.php. | |||||
CVE-2021-41746 | 1 Yonyou | 1 Turbocrm | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
SQL Injection vulnerability exists in all versions of Yonyou TurboCRM.via the orgcode parameter in changepswd.php. Attackers can use the vulnerabilities to obtain sensitive database information. | |||||
CVE-2021-41695 | 1 Globaldatingsoftware | 1 Premiumdatingscript | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. . | |||||
CVE-2021-41679 | 1 Os4ed | 1 Opensis | 2024-11-21 | 6.8 MEDIUM | 9.8 CRITICAL |
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.php, period parameter. | |||||
CVE-2021-41678 | 1 Os4ed | 1 Opensis | 2024-11-21 | 6.8 MEDIUM | 9.8 CRITICAL |
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter. | |||||
CVE-2021-41677 | 1 Os4ed | 1 Opensis | 2024-11-21 | 6.8 MEDIUM | 9.8 CRITICAL |
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade= parameter. | |||||
CVE-2021-41676 | 1 Pharmacy Point Of Sale System Project | 1 Pharmacy Point Of Sale System | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An SQL Injection vulnerabilty exists in the oretnom23 Pharmacy Point of Sale System 1.0 in the login function in actions.php. |