Search Results (36731 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-29147 1 Wayang-cms Project 1 Wayang-cms 2024-11-21 7.5 High
A SQL injection vulnerability in wy_controlls/wy_side_visitor.php of Wayang-CMS v1.0 allows attackers to obtain sensitive database information.
CVE-2020-29143 1 Open-emr 1 Openemr 2024-11-21 7.2 High
A SQL injection vulnerability in interface/reports/non_reported.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the form_code parameter.
CVE-2020-29142 1 Open-emr 1 Openemr 2024-11-21 7.2 High
A SQL injection vulnerability in interface/usergroup/usergroup_admin.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the schedule_facility parameter when restrict_user_facility=on is in global settings.
CVE-2020-29140 1 Open-emr 1 Openemr 2024-11-21 7.2 High
A SQL injection vulnerability in interface/reports/immunization_report.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the form_code parameter.
CVE-2020-29139 1 Open-emr 1 Openemr 2024-11-21 7.2 High
A SQL injection vulnerability in interface/main/finder/patient_select.php from library/patient.inc in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the searchFields parameter.
CVE-2020-29135 1 Cpanel 1 Cpanel 2024-11-21 4.1 Medium
cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).
CVE-2020-29072 1 Liquidfiles 1 Liquidfiles 2024-11-21 6.1 Medium
A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires user interaction (opening a link) and successful exploitation could lead to encrypted e-mail content leakage via messages/sent?format=js and popup?format=js.
CVE-2020-29020 1 Secomea 2 Sitemanager, Sitemanager Firmware 2024-11-21 9.1 Critical
Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All versions prior to 9.4.620527004 on Hardware.
CVE-2020-29015 1 Fortinet 1 Fortiweb 2024-11-21 9.8 Critical
A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing a malicious SQL statement.
CVE-2020-29011 1 Fortinet 1 Fortisandbox 2024-11-21 8.8 High
Instances of SQL Injection vulnerabilities in the checksum search and MTA-quarantine modules of FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated attacker to execute unauthorized code on the underlying SQL interpreter via specifically crafted HTTP requests.
CVE-2020-29006 1 Misp 1 Misp 2024-11-21 9.8 Critical
MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.
CVE-2020-28994 1 Karenderia Multiple Restaurant System Project 1 Karenderia Multiple Restaurant System 2024-11-21 9.8 Critical
A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifying and leaking all contents of the database.
CVE-2020-28960 1 Cct95 1 Chichen Tech Cms 2024-11-21 9.8 Critical
Chichen Tech CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the file product_list.php via the id and cid parameters.
CVE-2020-28916 3 Debian, Qemu, Redhat 3 Debian Linux, Qemu, Enterprise Linux 2024-11-21 5.5 Medium
hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
CVE-2020-28872 1 Monitorr 1 Monitorr 2024-11-21 9.8 Critical
An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to create valid credentials.
CVE-2020-28860 1 Openasset 1 Digital Asset Management 2024-11-21 8.8 High
OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.
CVE-2020-28702 1 Pybbs Project 1 Pybbs 2024-11-21 7.5 High
A SQL injection vulnerability in TopicMapper.xml of PybbsCMS v5.2.1 allows attackers to access sensitive database information.
CVE-2020-28679 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 8.8 High
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
CVE-2020-28657 1 Bittacora 1 Bpanel 2024-11-21 9.8 Critical
In bPanel 2.0, the administrative ajax endpoints (aka ajax/aj_*.php) are accessible without authentication and allow SQL injections, which could lead to platform compromise.
CVE-2020-28413 1 Mantisbt 1 Mantisbt 2024-11-21 5.3 Medium
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.