Export limit exceeded: 399173 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 399173 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 399173 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 29998 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (42703 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-35441 1 Fangfa 1 Fdcms 2024-11-21 9.8 Critical
FDCMS (aka Fangfa Content Management System) 4.0 contains a front-end SQL injection via Admin/Lib/Action/FloginAction.class.php.
CVE-2020-35430 1 Inxedu 1 Inxedu 2024-11-21 9.8 Critical
SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsystem.
CVE-2020-35427 1 Phpgurukul 1 Employee Record Management System 2024-11-21 9.8 Critical
SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
CVE-2020-35382 1 Classroombookings 1 Classroombookings 2024-11-21 7.2 High
SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user.
CVE-2020-35378 1 Online Bus Ticket Reservation Project 1 Online Bus Ticket Reservation 2024-11-21 9.8 Critical
SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.
CVE-2020-35337 1 Thinksaas 1 Thinksaas 2024-11-21 9.8 Critical
ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows remote attackers to execute arbitrary SQL commands.
CVE-2020-35329 1 Courier Management System Project 1 Courier Management System 2024-11-21 6.5 Medium
Courier Management System 1.0 1.0 is affected by SQL Injection via 'MULTIPART street '.
CVE-2020-35327 1 Courier Management System Project 1 Courier Management System 2024-11-21 6.5 Medium
SQL injection vulnerability was discovered in Courier Management System 1.0, which can be exploited via the ref_no (POST) parameter to admin_class.php
CVE-2020-35276 1 Egavilanmedia 1 Ecm Address Book 2024-11-21 9.8 Critical
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
CVE-2020-35270 1 Student Result Management System Project 1 Student Result Management System 2024-11-21 9.1 Critical
Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of Admin Panel and manage every account of Result.
CVE-2020-35263 1 Egavilanmedia 1 User Registration And Login System With Admin Panel 2024-11-21 9.8 Critical
EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.
CVE-2020-35245 1 Flamingo Project 1 Flamingo 2024-11-21 9.8 Critical
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser.
CVE-2020-35244 1 Flamingo Project 1 Flamingo 2024-11-21 9.8 Critical
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addGroup.
CVE-2020-35243 1 Flamingo Project 1 Flamingo 2024-11-21 9.8 Critical
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb.
CVE-2020-35242 1 Flamingo Project 1 Flamingo 2024-11-21 9.8 Critical
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAndMemory.
CVE-2020-35151 1 Phpgurukul 1 Online Marriage Registration System 2024-11-21 8.8 High
The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.
CVE-2020-35136 1 Dolibarr 1 Dolibarr Erp\/crm 2024-11-21 7.2 High
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.
CVE-2020-35122 1 Keysight 1 Keysight Database Connector 2024-11-21 7.5 High
An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could bypass the access controls for using a saved database connection profile to submit arbitrary SQL against a saved database connection.
CVE-2020-35012 1 Pixelite 1 Events Manager 2024-11-21 7.2 High
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection
CVE-2020-2907 2 Opensuse, Oracle 2 Leap, Vm Virtualbox 2024-11-21 7.5 High
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).