Export limit exceeded: 18747 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (18747 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-1470 | 1 Cisco | 1 Catalyst Sd-wan Manager | 2025-06-24 | 4.9 Medium |
| A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper input validation of SQL queries to an affected system. An attacker could exploit this vulnerability by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on or return values from the vManage database or the underlying operating system.Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. | ||||
| CVE-2025-5913 | 2 Anujk305, Phpgurukul | 2 Vehicle Record Management System, Vehicle Record Management System | 2025-06-24 | 7.3 High |
| A vulnerability was found in PHPGurukul Vehicle Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/search-vehicle.php. The manipulation of the argument searchinputdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2025-4778 | 1 Phpgurukul | 1 Park Ticketing Management System | 2025-06-24 | 6.3 Medium |
| A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been declared as critical. This vulnerability affects unknown code of the file /normal-search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2025-36528 | 2 Manageengine, Zohocorp | 2 Adaudit Plus, Manageengine Adaudit Plus | 2025-06-24 | 8.3 High |
| Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports. | ||||
| CVE-2025-26136 | 2 Mysiteforme, Wangl1989 | 2 Mysiteforme, Mysiteforme | 2025-06-24 | 9.8 Critical |
| A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1. | ||||
| CVE-2024-51165 | 1 Ketr | 1 Jepaas | 2025-06-24 | 7.5 High |
| SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB. | ||||
| CVE-2024-57430 | 1 Phpjabbers | 1 Cinema Booking System | 2025-06-24 | 9.8 Critical |
| An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation. | ||||
| CVE-2024-36428 | 1 Orangehrm | 1 Orangehrm | 2025-06-23 | 8.1 High |
| OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection. | ||||
| CVE-2025-28056 | 1 Ruifang-tech | 1 Rebuild | 2025-06-23 | 9.8 Critical |
| rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component. | ||||
| CVE-2024-40570 | 1 Seacms | 1 Seacms | 2025-06-23 | 6.5 Medium |
| SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component. | ||||
| CVE-2024-25312 | 1 Code-projects | 1 Simple School Management System | 2025-06-20 | 8.8 High |
| Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5." | ||||
| CVE-2024-25310 | 1 Code-projects | 1 Simple School Management System | 2025-06-20 | 8.8 High |
| Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5." | ||||
| CVE-2024-25307 | 1 Code-projects | 1 Cinema Seat Reservation System | 2025-06-20 | 9.8 Critical |
| Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1." | ||||
| CVE-2024-24015 | 1 Xxyopen | 1 Novel-plus | 2025-06-20 | 9.8 Critical |
| A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL via /sys/user/exit | ||||
| CVE-2023-46350 | 1 Innovadeluxe | 1 Manufacturer Or Supplier Alphabetical Search | 2025-06-20 | 9.8 Critical |
| SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods IdxrmanufacturerFunctions::getCornersLink, IdxrmanufacturerFunctions::getManufacturersLike and IdxrmanufacturerFunctions::getSuppliersLike. | ||||
| CVE-2024-23751 | 1 Llamaindex | 1 Llamaindex | 2025-06-20 | 9.8 Critical |
| LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQueryEngine, NLSQLRetriever, RetrieverQueryEngine, and PGVectorSQLQueryEngine. For example, an attacker might be able to delete this year's student records via "Drop the Students table" within English language input. | ||||
| CVE-2023-48118 | 1 Quest-analytics | 1 Iqcrm | 2025-06-20 | 9.8 Critical |
| SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code via a crafted request to the Common.svc WSDL page. | ||||
| CVE-2023-46351 | 1 Mypresta | 1 Manufacturers \(brands\) Images Block | 2025-06-20 | 9.8 Critical |
| In the module mib < 1.6.1 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The methods `mib::getManufacturersByCategory()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection. | ||||
| CVE-2022-43216 | 1 Abrhil | 2 Employees Portal, Lista De Asistencia | 2025-06-20 | 9.1 Critical |
| AbrhilSoft Employee's Portal before v5.6.2 was discovered to contain a SQL injection vulnerability in the login page. | ||||
| CVE-2024-29390 | 2 Anuj Kumar, Anujk305 | 2 Daily Expenses Management System, Daily Expenses Management System | 2025-06-20 | 7.3 High |
| Daily Expenses Management System version 1.0, developed by PHP Gurukul, contains a time-based blind SQL injection vulnerability in the 'add-expense.php' page. An attacker can exploit the 'item' parameter in a POST request to execute arbitrary SQL commands in the backend database. This can be done by injecting specially crafted SQL queries that make the database perform time-consuming operations, thereby confirming the presence of the SQL injection vulnerability based on the delay in the server's response. | ||||