Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-09-07 | CVE-2015-4724 | SQL Injection vulnerability in Concretecms Concrete CMS 5.7.3.1 SQL injection vulnerability in Concrete5 5.7.3.1. | 8.8 |
2017-09-07 | CVE-2015-4627 | SQL Injection vulnerability in Pragyan CMS Project Pragyan CMS 3.0 SQL injection vulnerability in Pragyan CMS 3.0. | 9.8 |
2017-09-07 | CVE-2015-3314 | SQL Injection vulnerability in Tune Library Project Tune Library SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5. | 8.1 |
2017-09-07 | CVE-2015-3313 | SQL Injection vulnerability in Community Events Project Community Events SQL injection vulnerability in WordPress Community Events plugin before 1.4. | 9.8 |
2017-09-07 | CVE-2017-9834 | SQL Injection vulnerability in Calendarscripts Watupro SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the watupro_questions parameter in a watupro_submit action to wp-admin/admin-ajax.php. | 9.8 |
2017-09-05 | CVE-2017-14145 | SQL Injection vulnerability in Helpdezk 1.1.1 HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function. | 9.8 |
2017-08-31 | CVE-2016-10509 | SQL Injection vulnerability in Opencart SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 allows remote authenticated administrators to execute arbitrary SQL commands via a carrier (aka courier_id) parameter to openbay.php. | 7.2 |
2017-08-31 | CVE-2017-14076 | SQL Injection vulnerability in Nexusphp 1.5 SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the id parameter to linksmanage.php in an editlink action. | 9.8 |
2017-08-31 | CVE-2017-14069 | SQL Injection vulnerability in Nexusphp 1.5 SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the usernw array parameter to nowarn.php. | 9.8 |
2017-08-30 | CVE-2017-12710 | SQL Injection vulnerability in Advantech Webaccess A SQL Injection issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. | 7.5 |