Export limit exceeded: 18858 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (18858 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-43227 1 Online Diagnostic Lab Management System Project 1 Online Diagnostic Lab Management System 2025-05-02 7.2 High
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/admin/?page=appointments/view_appointment.
CVE-2022-3494 1 Really-simple-plugins 1 Complianz 2025-05-01 8.8 High
The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco Translate or WPML.
CVE-2022-3481 1 Opmc 1 Woocommerce Dropshipping 2025-05-01 9.8 Critical
The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection
CVE-2022-41671 1 Schneider-electric 2 Ecostruxure Operator Terminal Expert, Pro-face Blue 2025-05-01 7 High
A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries with local user privileges to craft a malicious SQL query and execute as part of project migration which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
CVE-2024-37376 1 Ivanti 1 Endpoint Manager 2025-05-01 7.2 High
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-34784 1 Ivanti 1 Endpoint Manager 2025-05-01 7.2 High
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-34782 1 Ivanti 1 Endpoint Manager 2025-05-01 7.2 High
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-34781 1 Ivanti 1 Endpoint Manager 2025-05-01 7.2 High
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2020-12507 1 Badgermeter 1 Moni\ 2025-05-01 8.8 High
In s::can moni::tools before version 4.2 an authenticated attacker could get full access to the database through SQL injection. This may result in loss of confidentiality, loss of integrity and DoS.
CVE-2025-26200 1 Slims 1 Senayan Library Management System 2025-05-01 7.2 High
SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.
CVE-2022-43292 1 Canteen Management System Project 1 Canteen Management System 2025-05-01 7.2 High
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editfood.php.
CVE-2022-43291 1 Canteen Management System Project 1 Canteen Management System 2025-05-01 7.2 High
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editclient.php.
CVE-2022-43290 1 Canteen Management System Project 1 Canteen Management System 2025-05-01 7.2 High
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editcategory.php.
CVE-2022-43278 1 Canteen Management System Project 1 Canteen Management System 2025-05-01 7.2 High
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the categoriesId parameter at /php_action/fetchSelectedCategories.php.
CVE-2022-43058 1 Online Diagnostic Lab Management System Project 1 Online Diagnostic Lab Management System 2025-05-01 9.8 Critical
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity.
CVE-2024-33124 1 Roothub 1 Roothub 2025-05-01 9.8 Critical
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function..
CVE-2024-33122 1 Roothub 1 Roothub 2025-05-01 6.3 Medium
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.
CVE-2022-44727 1 Lineagrafica 1 Eu Cookie Law Gdpr 2025-05-01 9.1 Critical
The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).
CVE-2022-43672 1 Zohocorp 3 Manageengine Access Manager Plus, Manageengine Pam360, Manageengine Password Manager Pro 2025-05-01 9.8 Critical
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.
CVE-2022-43671 1 Zohocorp 3 Manageengine Access Manager Plus, Manageengine Pam360, Manageengine Password Manager Pro 2025-05-01 9.8 Critical
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.