Export limit exceeded: 18755 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (18755 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-41767 | 3 Ibm, Linux, Microsoft | 4 Engineering Lifecycle Optimization - Publishing, Engineering Lifecycle Optimization Publishing, Linux Kernel and 1 more | 2025-03-21 | 7.3 High |
| IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | ||||
| CVE-2024-54920 | 1 Lopalopa | 1 E-learning Management System | 2025-03-20 | 9.8 Critical |
| A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters. | ||||
| CVE-2024-42573 | 2 Arajajyothibabu, School Management System Project | 2 School Management System, School Management System | 2025-03-20 | 9.8 Critical |
| School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php. | ||||
| CVE-2024-31506 | 2 Online Graduate Tracer System Project, Tamparongj03 | 2 Online Graduate Tracer System, Online Graduate Tracer System | 2025-03-20 | 4.9 Medium |
| Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "id" parameter in admin/admin_cs.php. | ||||
| CVE-2021-38239 | 1 Dataease | 1 Dataease | 2025-03-20 | 7.5 High |
| SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10. | ||||
| CVE-2021-34117 | 1 Seopanel | 1 Seo Panel | 2025-03-20 | 7.5 High |
| SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.api.php in function getUserName in the username parameter, allows attackers to gain sensitive information. | ||||
| CVE-2021-33925 | 1 Cms-corephp Project | 1 Cms-corephp | 2025-03-20 | 9.8 Critical |
| SQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May 19, 2021) allows unauthenticated attackers to gain escilated privledges via a crafted login. | ||||
| CVE-2020-21120 | 1 Uqcms | 1 Uqcms | 2025-03-20 | 9.8 Critical |
| SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num. | ||||
| CVE-2020-21119 | 1 Kliqqi | 1 Kliqqi Cms | 2025-03-20 | 9.8 Critical |
| SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code. | ||||
| CVE-2023-23459 | 2 Microsoft, Priority-software | 2 Windows, Priority | 2025-03-19 | 9.1 Critical |
| Priority Windows may allow Command Execution via SQL Injection using an unspecified method. | ||||
| CVE-2022-38868 | 1 Ehoney Project | 1 Ehoney | 2025-03-19 | 7.2 High |
| SQL Injection vulnerability in Ehoney version 2.0.0 in models/protocol.go and models/images.go, allows attackers to execute arbitrary code. | ||||
| CVE-2024-57162 | 1 Campcodes | 1 Cybercafe Management System | 2025-03-19 | 7.2 High |
| Campcodes Cybercafe Management System v1.0 is vulnerable to SQL Injection in /ccms/view-user-detail.php. | ||||
| CVE-2024-47487 | 1 Hikvision | 1 Hikcentral Professional | 2025-03-19 | 8.8 High |
| There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user to execute arbitrary SQL queries. | ||||
| CVE-2024-32602 | 1 Onthegosystems | 2 Sitepress-multilingual-cms, Woocommerce Multilingual \& Multicurrency | 2025-03-19 | 7.6 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OnTheGoSystems WooCommerce Multilingual & Multicurrency.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through 5.3.3.1. | ||||
| CVE-2024-32139 | 1 Podlove | 1 Podlove Podcast Publisher | 2025-03-19 | 8.5 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.12. | ||||
| CVE-2024-30163 | 1 Invisioncommunity | 1 Invisioncommunity | 2025-03-19 | 9.8 Critical |
| Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries. This can be exploited by unauthenticated attackers to carry out Blind SQL Injection attacks. | ||||
| CVE-2021-32441 | 1 Exponentcms | 1 Exponent Cms | 2025-03-19 | 7.5 High |
| SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive information via the selectValue function in the expConfig class. | ||||
| CVE-2023-7180 | 1 Tongda2000 | 1 Office Anywhere | 2025-03-19 | 5.5 Medium |
| A vulnerability has been found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this vulnerability is an unknown functionality of the file general/project/proj/delete.php. The manipulation of the argument PROJ_ID_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-249367. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2023-7020 | 1 Tongda2000 | 1 Office Anywhere | 2025-03-19 | 6.3 Medium |
| A vulnerability was found in Tongda OA 2017 up to 11.9 and classified as critical. This issue affects some unknown processing of the file general/wiki/cp/ct/view.php. The manipulation of the argument TEMP_ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-248567. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2023-7023 | 1 Tongda2000 | 1 Office Anywhere | 2025-03-19 | 6.3 Medium |
| A vulnerability was found in Tongda OA 2017 up to 11.9. It has been rated as critical. Affected by this issue is some unknown functionality of the file general/vehicle/query/delete.php. The manipulation of the argument VU_ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-248570 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||