Export limit exceeded: 18850 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (18850 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-30865 | 1 Netentsec | 2 Ns-asg, Ns-asg Firmware | 2025-04-04 | 9.8 Critical |
| netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php. | ||||
| CVE-2024-30866 | 1 Netentsec | 2 Ns-asg, Ns-asg Firmware | 2025-04-04 | 5.4 Medium |
| netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/menu.php. | ||||
| CVE-2023-0281 | 1 Online Flight Booking Management System Project | 1 Online Flight Booking Management System | 2025-04-04 | 6.3 Medium |
| A vulnerability was found in SourceCodester Online Flight Booking Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file judge_panel.php. The manipulation of the argument subevent_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-218276. | ||||
| CVE-2024-48283 | 1 Phpgurukul | 2 User Registration \& Login And User Management System, User Registration And Login And User Management System | 2025-04-04 | 9.8 Critical |
| Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter. | ||||
| CVE-2024-46531 | 1 Phpgurukul | 2 Vehicle Record Management System, Vehicle Record System | 2025-04-04 | 6.3 Medium |
| phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchinputdata parameter at /index.php. | ||||
| CVE-2024-34955 | 1 Code-projects | 1 Budget Management | 2025-04-04 | 9.8 Critical |
| Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter. | ||||
| CVE-2022-47745 | 1 Easycorp | 1 Zentao | 2025-04-04 | 8.8 High |
| ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice. | ||||
| CVE-2022-47740 | 1 Seltmann-webdesign | 1 Content Management System | 2025-04-04 | 9.8 Critical |
| Seltmann GmbH Content Management System 6 is vulnerable to SQL Injection via /index.php. | ||||
| CVE-2024-30938 | 1 Sem-cms | 1 Semcms | 2025-04-04 | 9.8 Critical |
| SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component. | ||||
| CVE-2024-31077 | 1 Incsub | 1 Forminator | 2025-04-04 | 7.2 High |
| Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain and alter any information in the database and cause a denial-of-service (DoS) condition. | ||||
| CVE-2023-23492 | 1 Idehweb | 1 Login With Phone Number | 2025-04-03 | 8.8 High |
| The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action. | ||||
| CVE-2023-23490 | 1 Ays-pro | 1 Survey Maker | 2025-04-03 | 8.8 High |
| The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' action. | ||||
| CVE-2023-23489 | 1 Sandhillsdev | 1 Easy Digital Downloads | 2025-04-03 | 9.8 Critical |
| The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action. | ||||
| CVE-2023-23488 | 1 Strangerstudios | 1 Paid Memberships Pro | 2025-04-03 | 9.8 Critical |
| The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route. | ||||
| CVE-2022-48152 | 1 Remoteclinic | 1 Remote Clinic | 2025-04-03 | 9.8 Critical |
| SQL Injection vulnerability in RemoteClinic 2.0 allows attackers to execute arbitrary commands and gain sensitive information via the id parameter to /medicines/profile.php. | ||||
| CVE-2022-46887 | 1 Nexusphp | 1 Nexusphp | 2025-04-03 | 9.8 Critical |
| Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php. | ||||
| CVE-2022-47105 | 1 Jeecg | 1 Jeecg Boot | 2025-04-03 | 9.8 Critical |
| Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData. | ||||
| CVE-2012-10006 | 1 Sigeprosi Project | 1 Sigeprosi | 2025-04-03 | 5.5 Medium |
| A vulnerability classified as critical has been found in ale7714 sigeprosi. This affects an unknown part. The manipulation leads to sql injection. The identifier of the patch is 5291886f6c992316407c376145d331169c55f25b. It is recommended to apply a patch to fix this issue. The identifier VDB-218493 was assigned to this vulnerability. | ||||
| CVE-2021-26644 | 2 Mangboard, Microsoft | 2 Mangboard Wp, Windows | 2025-04-03 | 8.8 High |
| SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is running. | ||||
| CVE-2024-55509 | 1 Codeastro | 1 Complaint Management System | 2025-04-03 | 9.8 Critical |
| SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of the delete.php component. | ||||