Explore CVEs related to SQL Injection vulnerabilities, filtered by published year. This list is sorted by most recent disclosures first and supports filtering by CVSS and EPSS risk scores.
Includes the most recent vulnerability disclosures and trends, helping security teams quickly identify high-risk issues and exploitation likelihood.
You're viewing SQL Injection CVEs published in 2018. View full CVE list
| CVE | Description | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|
| CVE-2018-19281 | Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection. | 9.8 | 1.76% | 2018-11-14 | 2026-06-16 |
| CVE-2018-19271 | Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL Injection via the main.php searchH parameter. | 8.8 | 2.12% | 2018-11-14 | 2026-06-16 |
| CVE-2018-16850 | postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges. | 9.8 | 5.15% | 2018-11-13 | 2026-06-16 |
| CVE-2018-19221 | An issue was discovered in LAOBANCMS 2.0. It allows SQL Injection via the admin/login.php guanliyuan parameter. | 9.8 | 1.20% | 2018-11-12 | 2026-06-16 |
| CVE-2018-15447 | A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected application. | 6.5 | 1.73% | 2018-11-08 | 2026-06-16 |
| CVE-2018-19061 | DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter. | 9.8 | 1.76% | 2018-11-07 | 2026-06-16 |
| CVE-2018-18963 | Busca.aspx.cs in Degrau Publicidade e Internet Plataforma de E-commerce allows SQL Injection via the busca/ URI. | 9.8 | 1.53% | 2018-11-06 | 2026-06-16 |
| CVE-2018-18949 | Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings. | 9.8 | 24.50% | 2018-11-05 | 2026-06-16 |
| CVE-2018-18887 | S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field). | 9.8 | 1.14% | 2018-10-31 | 2026-06-16 |
| CVE-2018-18832 | admin/check.asp in DKCMS 9.4 allows SQL Injection via an ASPSESSIONID cookie to admin/admin.asp. | 9.8 | 1.31% | 2018-10-30 | 2026-06-16 |
| CVE-2018-18822 | Grapixel New Media v2.0 allows SQL Injection via the pages.aspx pageref parameter. | 9.8 | 1.59% | 2018-10-30 | 2026-06-16 |
| CVE-2018-18792 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie. | 9.8 | 1.20% | 2018-10-29 | 2026-06-16 |
| CVE-2018-18791 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie. | 9.8 | 1.54% | 2018-10-29 | 2026-06-16 |
| CVE-2018-18790 | An issue was discovered in zzcms 8.3. SQL Injection exists in admin/special_add.php via a zxbigclassid cookie. (This needs an admin user login.) | 7.2 | 1.06% | 2018-10-29 | 2026-06-16 |
| CVE-2018-18789 | An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php. | 9.8 | 1.20% | 2018-10-29 | 2026-06-16 |
| CVE-2018-18788 | An issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This needs an admin user login.) | 7.2 | 1.06% | 2018-10-29 | 2026-06-16 |
| CVE-2018-18787 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie. | 9.8 | 1.20% | 2018-10-29 | 2026-06-16 |
| CVE-2018-18786 | An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie. | 9.8 | 1.20% | 2018-10-29 | 2026-06-16 |
| CVE-2018-18785 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php. | 9.8 | 1.20% | 2018-10-29 | 2026-06-16 |
| CVE-2018-18784 | An issue was discovered in zzcms 8.3. SQL Injection exists in admin/tagmanage.php via the tabletag parameter. (This needs an admin user login.) | 7.2 | 1.06% | 2018-10-29 | 2026-06-16 |