Export limit exceeded: 18755 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (18755 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-22974 | 1 Seacms | 1 Seacms | 2025-03-25 | 9.8 Critical |
| SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component. | ||||
| CVE-2011-10003 | 1 Xpressengine | 1 Xpressengine | 2025-03-25 | 5.5 Medium |
| A vulnerability was found in XpressEngine up to 1.4.4. It has been rated as critical. This issue affects some unknown processing of the component Update Query Handler. The manipulation leads to sql injection. Upgrading to version 1.4.5 is able to address this issue. The patch is named c6e94449f21256d6362450b29c7847305e756ad5. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-220247. | ||||
| CVE-2022-45526 | 1 Institutional Management Website Project | 1 Institutional Management Website | 2025-03-25 | 9.8 Critical |
| SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php. | ||||
| CVE-2024-3039 | 2 Shanghai Brad Technology Bladex Project, Shanghi Brad Technology | 2 Shanghai Brad Technology Bladex, Bladex | 2025-03-25 | 6.3 Medium |
| A vulnerability classified as critical has been found in Shanghai Brad Technology BladeX 3.4.0. Affected is an unknown function of the file /api/blade-user/export-user of the component API. The manipulation with the input updatexml(1,concat(0x3f,md5(123456),0x3f),1)=1 leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258426 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2024-3085 | 1 Phpgurukul | 1 Emergency Ambulance Hiring Portal | 2025-03-25 | 7.3 High |
| A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/login.php of the component Admin Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258678 is the identifier assigned to this vulnerability. | ||||
| CVE-2024-3552 | 1 Salephpscripts | 1 Web Directory Free | 2025-03-25 | 9.8 Critical |
| The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based. | ||||
| CVE-2022-45089 | 1 Gruparge | 1 Smartpower Web | 2025-03-24 | 8.8 High |
| Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection.This issue affects Smartpower Web: before 23.01.01. | ||||
| CVE-2022-45090 | 1 Gruparge | 1 Smartpower Web | 2025-03-24 | 8.8 High |
| Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection.This issue affects Smartpower Web: before 23.01.01. | ||||
| CVE-2023-24685 | 1 Churchcrm | 1 Churchcrm | 2025-03-24 | 7.2 High |
| ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Event Attendance reports module. | ||||
| CVE-2023-24684 | 1 Churchcrm | 1 Churchcrm | 2025-03-24 | 7.2 High |
| ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the EID parameter at GetText.php. | ||||
| CVE-2023-0758 | 1 Jfinaloa Project | 1 Jfinaloa | 2025-03-24 | 6.3 Medium |
| A vulnerability was found in glorylion JFinalOA 1.0.2 and classified as critical. This issue affects some unknown processing of the file src/main/java/com/pointlion/mvc/common/model/SysOrg.java. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220469 was assigned to this vulnerability. | ||||
| CVE-2022-4557 | 1 Gruparge | 1 Smartpower | 2025-03-24 | 9.8 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection.This issue affects Smartpower Web: before 23.01.01. | ||||
| CVE-2024-57031 | 1 Wegia | 1 Wegia | 2025-03-24 | 9.8 Critical |
| WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter. | ||||
| CVE-2025-2684 | 1 Phpgurukul | 1 Bank Locker Management System | 2025-03-24 | 7.3 High |
| A vulnerability, which was classified as critical, has been found in PHPGurukul Bank Locker Management System 1.0. This issue affects some unknown processing of the file /search-report-details.php. The manipulation of the argument searchinput leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2023-0771 | 1 Ampache | 1 Ampache | 2025-03-24 | 8.8 High |
| SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop. | ||||
| CVE-2021-25069 | 1 W3eden | 1 Download Manager | 2025-03-21 | 8.8 High |
| The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue | ||||
| CVE-2023-24084 | 1 Chikoi Project | 1 Chikoi | 2025-03-21 | 9.8 Critical |
| ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function. | ||||
| CVE-2022-45962 | 1 Os4ed | 1 Opensis | 2025-03-21 | 6.5 Medium |
| Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php. | ||||
| CVE-2022-4546 | 1 Conceptbeans | 1 Mapwiz | 2025-03-21 | 7.2 High |
| The Mapwiz WordPress plugin through 1.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. | ||||
| CVE-2025-24974 | 1 Dataease | 1 Dataease | 2025-03-21 | 6.5 Medium |
| DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated users can read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been fixed in v2.10.6. No known workarounds are available. | ||||