Export limit exceeded: 18837 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (18837 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-7180 | 1 Tongda2000 | 1 Office Anywhere | 2025-03-19 | 5.5 Medium |
| A vulnerability has been found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this vulnerability is an unknown functionality of the file general/project/proj/delete.php. The manipulation of the argument PROJ_ID_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-249367. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2020-29168 | 1 Online Doctor Appointment Booking System Php And Mysql Project | 1 Online Doctor Appointment Booking System Php And Mysql | 2025-03-19 | 9.8 Critical |
| SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint. | ||||
| CVE-2024-25320 | 1 Tongda2000 | 2 Office Anywhere, Office Anywhere 2017 | 2025-03-19 | 9.8 Critical |
| Tongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /affair/delete.php. | ||||
| CVE-2024-40393 | 1 Angeljudesuarez | 1 Online Clinic Management System | 2025-03-18 | 9.8 Critical |
| Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user parameter at login.php. | ||||
| CVE-2021-33948 | 1 Hotels Server Project | 1 Hotels Server | 2025-03-18 | 9.8 Critical |
| SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter. | ||||
| CVE-2024-57035 | 1 Wegia | 1 Wegia | 2025-03-18 | 9.8 Critical |
| WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php. | ||||
| CVE-2023-24221 | 1 Luckyframe | 1 Luckyframeweb | 2025-03-18 | 9.8 Critical |
| LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMapper.xml. | ||||
| CVE-2023-24220 | 1 Luckyframe | 1 Luckyframeweb | 2025-03-18 | 9.8 Critical |
| LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml. | ||||
| CVE-2023-24219 | 1 Luckyframe | 1 Luckyframeweb | 2025-03-18 | 9.8 Critical |
| LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml. | ||||
| CVE-2023-23279 | 1 Canteen Management System Project | 1 Canteen Management System | 2025-03-18 | 9.8 Critical |
| Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php. | ||||
| CVE-2023-23007 | 1 Ecisp | 1 Espcms | 2025-03-18 | 7.2 High |
| An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability in the function node where members are added. | ||||
| CVE-2022-40347 | 1 Intern Record System Project | 1 Intern Record System | 2025-03-18 | 9.8 Critical |
| SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information. | ||||
| CVE-2022-40032 | 1 Simple Task Managing System Project | 1 Simple Task Managing System | 2025-03-18 | 9.8 Critical |
| SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information. | ||||
| CVE-2024-0709 | 1 Coolplugins | 1 Cryptocurrency Widgets | 2025-03-18 | 9.8 Critical |
| The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to 2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2024-54929 | 1 Lopalopa | 1 E-learning Management System | 2025-03-18 | 7.2 High |
| KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php. | ||||
| CVE-2024-25896 | 1 Churchcrm | 1 Churchcrm | 2025-03-17 | 5.3 Medium |
| ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter. | ||||
| CVE-2024-25894 | 1 Churchcrm | 1 Churchcrm | 2025-03-17 | 9.8 Critical |
| ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter. | ||||
| CVE-2024-25893 | 1 Churchcrm | 1 Churchcrm | 2025-03-17 | 9.1 Critical |
| ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter. | ||||
| CVE-2024-25892 | 1 Churchcrm | 1 Churchcrm | 2025-03-17 | 8.1 High |
| ChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter. | ||||
| CVE-2023-26093 | 1 Puzzle | 1 Liima | 2025-03-17 | 9.8 Critical |
| Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter. | ||||