CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 1mo ago | 9.8 | SQL Injection exists in the SquadManagement 1.0.3 component for Joomla! via the id parameter. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the Saxum Numerology 3.0.4 component for Joomla! via the publicid parameter. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or filter_events_cat parameter. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers action, or the map parameter in a layout=default action. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the InviteX 3.0.5 component for Joomla! via the invite_type parameter in a view=invites action. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the Fastball 2.5 component for Joomla! via the season parameter in a view=player action. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the JB Bus 2.3 component for Joomla! via the order_number parameter. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under the all-offers/ URI. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the JS Autoz 1.0.9 component for Joomla! via the vtype, pre, or prs parameter. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the File Download Tracker 3.0 component for Joomla! via the dynfield[phone] or sess parameter. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or the ta parameter in a view_resume request. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the Aist through 2.0 component for Joomla! via the id parameter in a view=showvacancy request. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the Staff Master through 1.0 RC 1 component for Joomla! via the name parameter in a view=staff request. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerability than CVE-2015-2798. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011-5099. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id parameter in a task=getlikeinfo action, the ends parameter in a view=gift action, the category parameter in a view=home action, the uid parameter in a view=pindisplay action, the searchVal parameter in a view=search action, or the uid parameter in a view=likes action. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= request. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the Solidres 2.5.1 component for Joomla! via the direction parameter in a hub.search action. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the Smart Shoutbox 3.0.0 component for Joomla! via the shoutauthor parameter to the archive URI. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array parameter. |
| Exploit 1mo ago | 9.8 | SQL Injection exists in the JGive 2.0.9 component for Joomla! via the filter_org_ind_type or campaign_countries parameter. |