Vulnerabilities (CVE)

Filtered by CWE-89
Total 15872 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8637 1 Testlink 1 Testlink 2024-11-21 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.
CVE-2020-8611 2 Progess, Progress 2 Moveit Transfer, Moveit Transfer 2024-11-21 6.5 MEDIUM 8.8 HIGH
In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, multiple SQL Injection vulnerabilities have been found in the REST API that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database via the REST API. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or destroy database elements.
CVE-2020-8596 1 Xnau 1 Participants Database 2024-11-21 6.0 MEDIUM 7.5 HIGH
participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-based SQL injection vulnerability via the ascdesc, list_filter_count, or sortBy parameters. It is possible to exfiltrate data and potentially execute code (if certain conditions are met).
CVE-2020-8592 1 Eginnovations 1 Eg Manager 2024-11-21 7.5 HIGH 9.8 CRITICAL
eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password feature).
CVE-2020-8521 1 Phpzag 1 Phpzag 2024-11-21 7.5 HIGH 9.8 CRITICAL
SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql
CVE-2020-8520 1 Phpzag 1 Phpzag 2024-11-21 7.5 HIGH 9.8 CRITICAL
SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql
CVE-2020-8519 1 Phpzag 1 Phpzag 2024-11-21 7.5 HIGH 9.8 CRITICAL
SQL injection with the search parameter in Records.php for phpzag live add edit delete data tables records with ajax php mysql
CVE-2020-8435 1 Metagauss 1 Registrationmagic 2024-11-21 5.5 MEDIUM 8.1 HIGH
An issue was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress. There is SQL injection via the rm_analytics_show_form rm_form_id parameter.
CVE-2020-8427 1 Unitrends 1 Backup 2024-11-21 7.5 HIGH 9.8 CRITICAL
In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an authentication bypass.
CVE-2020-8242 1 Expressionengine 1 Expressionengine 2024-11-21 6.5 MEDIUM 7.2 HIGH
Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin control panel access to execute the attack.
CVE-2020-8211 1 Citrix 1 Xenmobile Server 2024-11-21 7.5 HIGH 9.8 CRITICAL
Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.
CVE-2020-7981 1 Rubygeocoder 1 Geocoder 2024-11-21 7.5 HIGH 9.8 CRITICAL
sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.
CVE-2020-7939 1 Plone 1 Plone 2024-11-21 6.5 MEDIUM 8.8 HIGH
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)
CVE-2020-7819 2 Microsoft, Ntracker 2 Windows, Ntracker Usb Enterprise 2024-11-21 5.0 MEDIUM 9.3 CRITICAL
A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information.
CVE-2020-7759 1 Pimcore 1 Pimcore 2024-11-21 6.5 MEDIUM 6.5 MEDIUM
The package pimcore/pimcore from 6.7.2 and before 6.8.3 are vulnerable to SQL Injection in data classification functionality in ClassificationstoreController. This can be exploited by sending a specifically-crafted input in the relationIds parameter as demonstrated by the following request: http://vulnerable.pimcore.example/admin/classificationstore/relations?relationIds=[{"keyId"%3a"''","groupId"%3a"'asd'))+or+1%3d1+union+(select+1,2,3,4,5,6,name,8,password,'',11,12,'',14+from+users)+--+"}]
CVE-2020-7577 1 Siemens 1 Opcenter Execution Core 2024-11-21 5.5 MEDIUM 8.1 HIGH
A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Through the use of several vulnerable fields of the application, an authenticated user could perform an SQL Injection attack by passing a modified SQL query downstream to the back-end server. The exploit of this vulnerability could be used to read, and potentially modify application data to which the user has access to.
CVE-2020-7500 1 Schneider-electric 12 Mtn6260-0310, Mtn6260-0310 Firmware, Mtn6260-0315 and 9 more 2024-11-21 7.5 HIGH 9.8 CRITICAL
A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause arbitrary code to be executed when a malicious command is entered.
CVE-2020-7493 1 Schneider-electric 1 Ecostruxure Operator Terminal Expert 2024-11-21 6.8 MEDIUM 7.8 HIGH
A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.
CVE-2020-7471 1 Djangoproject 1 Django 2024-11-21 7.5 HIGH 9.8 CRITICAL
Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column delimiter). By passing a suitably crafted delimiter to a contrib.postgres.aggregates.StringAgg instance, it was possible to break escaping and inject malicious SQL.
CVE-2020-7383 1 Rapid7 1 Nexpose 2024-11-21 5.5 MEDIUM 6.5 MEDIUM
A SQL Injection issue in Rapid7 Nexpose version prior to 6.6.49 that may have allowed an authenticated user with a low permission level to access resources & make changes they should not have been able to access.