Export limit exceeded: 347481 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 18858 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (18858 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-42923 | 1 Formalms | 1 Formalms | 2025-05-06 | 8.3 High |
| Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an authenticated attacker (with the role of student) to perform a SQL injection on the 'id' parameter in the 'appCore/index.php?r=adm/mediagallery/delete' function in order to dump the entire database or delete all contents from the 'core_user_file' table. | ||||
| CVE-2024-10297 | 1 Anujk305 | 1 Medical Card Generation System | 2025-05-06 | 4.7 Medium |
| A vulnerability was found in PHPGurukul Medical Card Generation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/changeimage.php of the component Managecard Edit Image Page. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2025-2362 | 1 Phpgurukul | 1 Pre-school Enrollment System | 2025-05-06 | 7.3 High |
| A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/contact-us.php. The manipulation of the argument mobnum leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. | ||||
| CVE-2025-2379 | 1 Phpgurukul | 1 Apartment Visitors Management System | 2025-05-06 | 7.3 High |
| A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /create-pass.php. The manipulation of the argument visname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2025-2380 | 1 Phpgurukul | 1 Apartment Visitors Management System | 2025-05-06 | 7.3 High |
| A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin-profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2025-2381 | 1 Phpgurukul | 1 Curfew E-pass Management System | 2025-05-06 | 7.3 High |
| A vulnerability classified as critical has been found in PHPGurukul Curfew e-Pass Management System 1.0. Affected is an unknown function of the file /admin/search-pass.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2022-40839 | 1 Ndk-design | 1 Ndkadvancedcustomizationfields | 2025-05-06 | 7.5 High |
| A SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers to exfiltrate database data. | ||||
| CVE-2022-3254 | 1 Strategy11 | 1 Awp Classifieds | 2025-05-06 | 9.8 Critical |
| The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection | ||||
| CVE-2024-42765 | 2 Kashipara, Kjayvik | 2 Bus Ticket Reservation System, Bus Ticket Reservation System | 2025-05-06 | 9.8 Critical |
| A SQL injection vulnerability in "/login.php" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the "email" or "password" Login page parameters. | ||||
| CVE-2022-43352 | 1 Sanitization Management System Project | 1 Sanitization Management System | 2025-05-05 | 7.2 High |
| Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_quote. | ||||
| CVE-2022-3059 | 1 Schoolbox | 1 Schoolbox | 2025-05-05 | 8.6 High |
| The application was vulnerable to multiple instances of SQL injection (authenticated and unauthenticated) through a vulnerable parameter. Due to the stacked query support, complex SQL commands could be crafted and injected into the vulnerable parameter and using a sleep based inferential SQL injection it was possible to extract data from the database. | ||||
| CVE-2022-43350 | 1 Sanitization Management System Project | 1 Sanitization Management System | 2025-05-05 | 7.2 High |
| Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_inquiry. | ||||
| CVE-2022-43052 | 1 Online Diagnostic Lab Management System Project | 1 Online Diagnostic Lab Management System | 2025-05-05 | 7.2 High |
| Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete. | ||||
| CVE-2022-43051 | 1 Online Diagnostic Lab Management System Project | 1 Online Diagnostic Lab Management System | 2025-05-05 | 7.2 High |
| Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete_test. | ||||
| CVE-2022-43049 | 1 Canteen Management System Project | 1 Canteen Management System | 2025-05-05 | 7.2 High |
| Canteen Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the component /youthappam/add-food.php. | ||||
| CVE-2022-42990 | 1 Oretnom23 | 1 Food Ordering Management System | 2025-05-05 | 7.2 High |
| Food Ordering Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /foms/all-orders.php?status=Cancelled%20by%20Customer. | ||||
| CVE-2020-20122 | 1 Wuzhicms | 1 Wuzhicms | 2025-05-05 | 9.8 Critical |
| Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php. | ||||
| CVE-2018-11528 | 1 Wuzhicms | 1 Wuzhicms | 2025-05-05 | N/A |
| WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI. | ||||
| CVE-2022-27431 | 1 Wuzhicms | 1 Wuzhicms | 2025-05-05 | 9.8 Critical |
| Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php. | ||||
| CVE-2024-25288 | 2 Slims, Slims Project | 2 Senayan Library Management System, Slims | 2025-05-05 | 4.9 Medium |
| SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php. | ||||