V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
Filters

All vulnerabilities

4033 / 4033
Preset: exploit×Has exploit×CWE: CWE-89×Clear all
7.5
CVE-2014-3704DEB
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 doe…
2014-01-01
EPSS100.0%
pct 99
7.5
CVE-2015-7297CVE
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbi…
2015-01-01
EPSS100.0%
pct 99
8.8
CVE-2024-29824ANC KEV
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allo…
2024-01-01KEV
EPSS100.0%
pct 99
9.8
CVE-2023-34362CVE KEV
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 202…
2023-01-01KEV
EPSS99.9%
pct 99
7.5
CVE-2019-7481CVE KEV
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauth…
2019-01-01KEV
EPSS99.9%
pct 99
9.8
CVE-2017-8917CVE
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary…
2017-01-01Pre-auth
EPSS99.8%
pct 99
9.8
CVE-2020-10220CVE
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection…
2020-01-01Pre-auth
EPSS99.7%
pct 99
9.2
CVE-2024-9465CVE KEV
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attac…
2024-01-01KEV
EPSS99.6%
pct 99
9.8
CVE-2023-48788CVE KEV
A improper neutralization of special elements used in an sql command ('sql injection') in Forti…
2023-01-01KEV
EPSS98.5%
pct 99
9.8
CVE-2020-35847CVE
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword…
2020-01-01Pre-auth
EPSS98.3%
pct 99
7.5
CVE-2022-21661DEB
WordPress is a free and open-source content management system written in PHP and paired with a …
2022-01-01Pre-auth
EPSS97.8%
pct 99
9.8
CVE-2025-25257CVE KEV
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnera…
2025-01-01KEV
EPSS96.7%
pct 99
9.8
CVE-2020-11530CVE
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulner…
2020-01-01Pre-auth
EPSS95.7%
pct 99
9.8
CVE-2024-6670CVE KEV
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unau…
2024-01-01KEV
EPSS94.7%
pct 99
9.8
CVE-2019-12989CVE KEV
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injectio…
2019-01-01KEV
EPSS94.4%
pct 99
9.8
CVE-2026-21643CVE KEV
An improper neutralization of special elements used in an sql command ('sql injection') vulnera…
2026-01-01KEV
EPSS94.1%
pct 99
9.8
CVE-2024-27956CVE
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerabil…
2024-01-01Pre-auth
EPSS94.0%
pct 99
9.8
CVE-2020-17506CVE
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain we…
2020-01-01Pre-auth
EPSS94.0%
pct 99
7.5
CVE-2015-7857CVE
SQL injection vulnerability in the getListQuery function in administrator/components/com_conten…
2015-01-01
EPSS93.9%
pct 99
9.8
CVE-2020-35846CVE
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check functio…
2020-01-01Pre-auth
EPSS93.2%
pct 99
9.3
CVE-2026-42208CVE KEV
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From vers…
2026-01-01KEV
EPSS93.1%
pct 99
9.8
CVE-2023-23488CVE
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated S…
2023-01-01Pre-auth
EPSS92.5%
pct 99
9.8
CVE-2020-17463CVE KEV
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, …
2020-01-01KEV
EPSS90.0%
pct 99
9.8
CVE-2024-1071ANC
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction …
2024-01-01Pre-auth
EPSS89.4%
pct 99
10.0
CVE-2011-1653CVE
Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total …
2011-01-01
EPSS88.7%
pct 99
9.8
CVE-2023-39361DEB
Cacti is an open source operational monitoring and fault management framework. Affected version…
2023-01-01Pre-auth
EPSS87.6%
pct 99
10.0
CVE-2025-57819CVE KEV
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints …
2025-01-01KEV
EPSS87.4%
pct 99
9.8
CVE-2021-24762CVE
The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id G…
2021-01-01Pre-auth
EPSS86.9%
pct 99
9.8
CVE-2017-18362CVE KEV
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthentica…
2017-01-01KEV
EPSS86.7%
pct 99
7.2
CVE-2020-14295DEB
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter…
2020-01-01
EPSS86.3%
pct 99
9.8
CVE-2025-24799ANC
GLPI is a free asset and IT management software package. An unauthenticated user can perform a …
2025-01-01Pre-auth
EPSS86.2%
pct 99
9.8
CVE-2023-25157CVE
GeoServer is an open source software server written in Java that allows users to share and edit…
2023-01-01Pre-auth
EPSS85.2%
pct 99
9.8
CVE-2019-20361CVE
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that al…
2019-01-01Pre-auth
EPSS85.1%
pct 99
7.5
CVE-2015-7858CVE
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbi…
2015-01-01
EPSS84.8%
pct 99
9.8
CVE-2020-8656CVE
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injec…
2020-01-01Pre-auth
EPSS84.6%
pct 99
9.3
CVE-2025-32429ANC
XWiki Platform is a generic wiki platform offering runtime services for applications built on t…
2025-01-01Pre-auth
EPSS84.6%
pct 99
9.8
CVE-2018-17552CVE
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authe…
2018-01-01Pre-auth
EPSS84.1%
pct 99
9.8
CVE-2020-5722CVE KEV
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote…
2020-01-01KEV
EPSS84.0%
pct 99
9.8
CVE-2018-17254CVE
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links…
2018-01-01Pre-auth
EPSS83.0%
pct 99
7.5
CVE-2024-10400ANC
The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ param…
2024-01-01Pre-auth
EPSS82.6%
pct 99
Select a vulnerability on the left to open the preview.