CWE-564 · 10 kayıt
SQL Injection: Hibernate
Bu sınıftaki CVE’ler
10 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2024-58352İstismar yok | Landray OA Unauthenticated HQL Injection via wechatLoginHelper.doshenzhen landray software co., ltd. · landry office automation (oa) · CWE-564 | Yüksek8,7 | — | %0,9 | 2 Tem 2026 |
30İzleyin | CVE-2024-48988İstismar yok | Apache StreamPark: SQL injection vulnerabilityapache · streampark · CWE-564 | Yüksek7,6 | — | %0,6 | 22 Ağu 2025 |
27İzleyin | CVE-2026-23959İstismar yok | CoreShop Vulnerable to SQL Injection via Admin customer-company-modifiercoreshop · coreshop · CWE-564 | Orta6,9 | — | %0,4 | 21 Oca 2026 |
26İzleyin | CVE-2025-0959İstismar yok | Eventer - WordPress Event & Booking Manager Plugin <= 3.9.9.2 - Authenticated (Subscriber+) SQL Injection via reg_idimithemes · eventer · CWE-564 | Orta6,5 | — | %0,4 | 7 Mar 2025 |
21İzleyin | CVE-2025-67280İstismar yok | In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged usertim-solutions · tim flow · CWE-564 | Orta5,4 | — | %0,2 | 9 Oca 2026 |
20İzleyin | CVE-2026-13337İstismar yok | CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when schneider electric · netbotz 5 - 750/755 · CWE-564 | Orta5,1 | — | %0,2 | 1 Eyl 2026 |
19İzleyin | CVE-2026-22242İstismar yok | CoreShop Vulnerable to SQL Injection via Admin Reportscoreshop · coreshop · CWE-564 | Orta4,9 | — | %0,4 | 8 Oca 2026 |
19İzleyin | CVE-2026-76450İstismar yok | Cisco Identity Services Engine SQL Injection Vulnerabilitycisco · identity services engine · CWE-564 | Orta4,9 | — | %0,4 | 16 Eyl 2026 |
19İzleyin | CVE-2026-76451İstismar yok | Cisco Identity Services Engine Certificate Management SQL Injection Vulnerabilitycisco · identity services engine passive identity connector · CWE-564 | Orta4,9 | — | %0,4 | 16 Eyl 2026 |
4İzleyin | CVE-2025-8052İstismar yok | HQL Injection vulnerability has been discovered in Opentext Flipper.opentext · flipper · CWE-564 | Düşük1,0 | — | %0,4 | 20 Eki 2025 |
- CVE-2024-5835234İzleyin
Landray OA Unauthenticated HQL Injection via wechatLoginHelper.do
YüksekCVSS 8,7İstismar yokEPSS %1shenzhen landray software co., ltd. · landry office automation (oa)2 Tem 2026
- CVE-2024-4898830İzleyin
Apache StreamPark: SQL injection vulnerability
YüksekCVSS 7,6İstismar yokEPSS %1apache · streampark22 Ağu 2025
- CVE-2026-2395927İzleyin
CoreShop Vulnerable to SQL Injection via Admin customer-company-modifier
OrtaCVSS 6,9İstismar yokEPSS %0coreshop · coreshop21 Oca 2026
- CVE-2025-095926İzleyin
Eventer - WordPress Event & Booking Manager Plugin <= 3.9.9.2 - Authenticated (Subscriber+) SQL Injection via reg_id
OrtaCVSS 6,5İstismar yokEPSS %0imithemes · eventer7 Mar 2025
- CVE-2025-6728021İzleyin
In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged user
OrtaCVSS 5,4İstismar yokEPSS %0tim-solutions · tim flow9 Oca 2026
- CVE-2026-1333720İzleyin
CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when
OrtaCVSS 5,1İstismar yokEPSS %0schneider electric · netbotz 5 - 750/7551 Eyl 2026
- CVE-2026-2224219İzleyin
CoreShop Vulnerable to SQL Injection via Admin Reports
OrtaCVSS 4,9İstismar yokEPSS %0coreshop · coreshop8 Oca 2026
- CVE-2026-7645019İzleyin
Cisco Identity Services Engine SQL Injection Vulnerability
OrtaCVSS 4,9İstismar yokEPSS %0cisco · identity services engine16 Eyl 2026
- CVE-2026-7645119İzleyin
Cisco Identity Services Engine Certificate Management SQL Injection Vulnerability
OrtaCVSS 4,9İstismar yokEPSS %0cisco · identity services engine passive identity connector16 Eyl 2026
- CVE-2025-80524İzleyin
HQL Injection vulnerability has been discovered in Opentext Flipper.
DüşükCVSS 1,0İstismar yokEPSS %0opentext · flipper20 Eki 2025