CWE-564 · 10 записей
SQL Injection: Hibernate
CVE этого класса
10 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2024-58352Эксплойта нет | Landray OA Unauthenticated HQL Injection via wechatLoginHelper.doshenzhen landray software co., ltd. · landry office automation (oa) · CWE-564 | Высокая8,7 | — | 0,9 % | 2 июл. 2026 г. |
30Наблюдать | CVE-2024-48988Эксплойта нет | Apache StreamPark: SQL injection vulnerabilityapache · streampark · CWE-564 | Высокая7,6 | — | 0,6 % | 22 авг. 2025 г. |
27Наблюдать | CVE-2026-23959Эксплойта нет | CoreShop Vulnerable to SQL Injection via Admin customer-company-modifiercoreshop · coreshop · CWE-564 | Средняя6,9 | — | 0,4 % | 21 янв. 2026 г. |
26Наблюдать | CVE-2025-0959Эксплойта нет | Eventer - WordPress Event & Booking Manager Plugin <= 3.9.9.2 - Authenticated (Subscriber+) SQL Injection via reg_idimithemes · eventer · CWE-564 | Средняя6,5 | — | 0,4 % | 7 мар. 2025 г. |
21Наблюдать | CVE-2025-67280Эксплойта нет | In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged usertim-solutions · tim flow · CWE-564 | Средняя5,4 | — | 0,2 % | 9 янв. 2026 г. |
20Наблюдать | CVE-2026-13337Эксплойта нет | CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when schneider electric · netbotz 5 - 750/755 · CWE-564 | Средняя5,1 | — | 0,2 % | 1 сент. 2026 г. |
19Наблюдать | CVE-2026-76451Эксплойта нет | Cisco Identity Services Engine Certificate Management SQL Injection Vulnerabilitycisco · identity services engine passive identity connector · CWE-564 | Средняя4,9 | — | 0,4 % | 16 сент. 2026 г. |
19Наблюдать | CVE-2026-76450Эксплойта нет | Cisco Identity Services Engine SQL Injection Vulnerabilitycisco · identity services engine · CWE-564 | Средняя4,9 | — | 0,4 % | 16 сент. 2026 г. |
19Наблюдать | CVE-2026-22242Эксплойта нет | CoreShop Vulnerable to SQL Injection via Admin Reportscoreshop · coreshop · CWE-564 | Средняя4,9 | — | 0,4 % | 8 янв. 2026 г. |
4Наблюдать | CVE-2025-8052Эксплойта нет | HQL Injection vulnerability has been discovered in Opentext Flipper.opentext · flipper · CWE-564 | Низкая1,0 | — | 0,4 % | 20 окт. 2025 г. |
- CVE-2024-5835234Наблюдать
Landray OA Unauthenticated HQL Injection via wechatLoginHelper.do
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %shenzhen landray software co., ltd. · landry office automation (oa)2 июл. 2026 г.
- CVE-2024-4898830Наблюдать
Apache StreamPark: SQL injection vulnerability
ВысокаяCVSS 7,6Эксплойта нетEPSS 1 %apache · streampark22 авг. 2025 г.
- CVE-2026-2395927Наблюдать
CoreShop Vulnerable to SQL Injection via Admin customer-company-modifier
СредняяCVSS 6,9Эксплойта нетEPSS 0 %coreshop · coreshop21 янв. 2026 г.
- CVE-2025-095926Наблюдать
Eventer - WordPress Event & Booking Manager Plugin <= 3.9.9.2 - Authenticated (Subscriber+) SQL Injection via reg_id
СредняяCVSS 6,5Эксплойта нетEPSS 0 %imithemes · eventer7 мар. 2025 г.
- CVE-2025-6728021Наблюдать
In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged user
СредняяCVSS 5,4Эксплойта нетEPSS 0 %tim-solutions · tim flow9 янв. 2026 г.
- CVE-2026-1333720Наблюдать
CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when
СредняяCVSS 5,1Эксплойта нетEPSS 0 %schneider electric · netbotz 5 - 750/7551 сент. 2026 г.
- CVE-2026-7645119Наблюдать
Cisco Identity Services Engine Certificate Management SQL Injection Vulnerability
СредняяCVSS 4,9Эксплойта нетEPSS 0 %cisco · identity services engine passive identity connector16 сент. 2026 г.
- CVE-2026-7645019Наблюдать
Cisco Identity Services Engine SQL Injection Vulnerability
СредняяCVSS 4,9Эксплойта нетEPSS 0 %cisco · identity services engine16 сент. 2026 г.
- CVE-2026-2224219Наблюдать
CoreShop Vulnerable to SQL Injection via Admin Reports
СредняяCVSS 4,9Эксплойта нетEPSS 0 %coreshop · coreshop8 янв. 2026 г.
- CVE-2025-80524Наблюдать
HQL Injection vulnerability has been discovered in Opentext Flipper.
НизкаяCVSS 1,0Эксплойта нетEPSS 0 %opentext · flipper20 окт. 2025 г.