Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-09-20 | CVE-2023-40043 | SQL Injection vulnerability in Progress Moveit Transfer In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer web interface that could allow a MOVEit system administrator account to gain unauthorized access to the MOVEit Transfer database. | 7.2 |
2023-09-20 | CVE-2023-42660 | SQL Injection vulnerability in Progress Moveit Transfer In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer machine interface that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer database. | 8.8 |
2023-09-19 | CVE-2023-40931 | SQL Injection vulnerability in Nagios XI A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php | 6.5 |
2023-09-19 | CVE-2023-40933 | SQL Injection vulnerability in Nagios XI A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function. | 8.8 |
2023-09-19 | CVE-2023-40934 | SQL Injection vulnerability in Nagios XI A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings. | 7.2 |
2023-09-19 | CVE-2023-4092 | SQL Injection vulnerability in Fujitsu Arconte Aurea 1.5.0.0 SQL injection vulnerability in Arconte Áurea, in its 1.5.0.0 version. | 9.8 |
2023-09-19 | CVE-2023-29245 | SQL Injection vulnerability in Nozominetworks CMC and Guardian A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, may allow an unauthenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application by sending specially crafted malicious network packets. Malicious users with extensive knowledge on the underlying system may be able to extract arbitrary information from the DBMS in an uncontrolled way, alter its structure and data, and/or affect its availability. | 7.4 |
2023-09-19 | CVE-2023-2567 | SQL Injection vulnerability in Nozominetworks CMC and Guardian A SQL Injection vulnerability has been found in Nozomi Networks Guardian and CMC, due to improper input validation in certain parameters used in the Query functionality. Authenticated users may be able to execute arbitrary SQL statements on the DBMS used by the web application. | 8.8 |
2023-09-19 | CVE-2023-41387 | SQL Injection vulnerability in Patreon Flutter Downloader A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. | 9.1 |
2023-09-19 | CVE-2021-26837 | SQL Injection vulnerability in Fortra Delivernow SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information. | 9.8 |