Total
16128 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2018-17397 | 1 Multiplanet | 1 Alphaindex Dictionaries | 2024-11-21 | N/A |
SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter. | ||||
CVE-2018-17394 | 1 Osthemeclub | 1 Timetable Schedule | 2024-11-21 | N/A |
SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter. | ||||
CVE-2018-17393 | 1 Healthnode Hospital Management System Project | 1 Healthnode Hospital Management System | 2024-11-21 | N/A |
SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or dashboard/Patient/patientdetails.php. | ||||
CVE-2018-17391 | 1 Super Cms Blog Pro Project | 1 Super Cms Blog Pro | 2024-11-21 | N/A |
SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter. | ||||
CVE-2018-17388 | 1 Ranksol | 1 Twilio Web To Fax Machine System | 2024-11-21 | N/A |
SQL Injection exists in Twilio WEB To Fax Machine System 1.0 via the email or password parameter to login_check.php, or the id parameter to add_email.php or edit_content.php. | ||||
CVE-2018-17386 | 1 Thephpfactory | 1 Micro Deal Factory | 2024-11-21 | N/A |
SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/. | ||||
CVE-2018-17385 | 1 Thephpfactory | 1 Social Factory | 2024-11-21 | N/A |
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter. | ||||
CVE-2018-17384 | 1 Thephpfactory | 1 Swap Factory | 2024-11-21 | N/A |
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter. | ||||
CVE-2018-17383 | 1 Thephpfactory | 1 Collection Factory | 2024-11-21 | N/A |
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter. | ||||
CVE-2018-17382 | 1 Thephpfactory | 1 Jobs Factory | 2024-11-21 | N/A |
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter. | ||||
CVE-2018-17381 | 1 Thephpfactory | 1 Dutch Auction Factory | 2024-11-21 | N/A |
SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter. | ||||
CVE-2018-17380 | 1 Thephpfactory | 1 Article Factory Manager | 2024-11-21 | N/A |
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter. | ||||
CVE-2018-17379 | 1 Thephpfactory | 1 Raffle Factory | 2024-11-21 | N/A |
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter. | ||||
CVE-2018-17378 | 1 Thephpfactory | 1 Penny Auction Factory | 2024-11-21 | N/A |
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter. | ||||
CVE-2018-17377 | 1 Extensiondeveloper | 1 Questions | 2024-11-21 | N/A |
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter. | ||||
CVE-2018-17376 | 1 Thephpfactory | 1 Reverse Auction Factory | 2024-11-21 | N/A |
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter. | ||||
CVE-2018-17375 | 1 Joomlathat | 1 Music Collection | 2024-11-21 | N/A |
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter. | ||||
CVE-2018-17374 | 1 Thephpfactory | 1 Auction Factory | 2024-11-21 | N/A |
SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter. | ||||
CVE-2018-17283 | 1 Zohocorp | 1 Manageengine Opmanager | 2024-11-21 | N/A |
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter. | ||||
CVE-2018-17254 | 1 Arkextensions | 1 Jck Editor | 2024-11-21 | 9.8 Critical |
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter. |