Total
9311 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-24206 | 1 Tongda2000 | 1 Tongda Oa | 2022-02-18 | 7.5 HIGH | 9.8 CRITICAL |
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter. | |||||
CVE-2021-46458 | 1 Victor Cms Project | 1 Victor Cms | 2022-02-18 | 5.0 MEDIUM | 7.5 HIGH |
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post. This vulnerability can be exploited through a crafted POST request via the post_title parameter. | |||||
CVE-2021-34235 | 1 Tsg-solutions | 1 Tokheim Profleet Dialog | 2022-02-18 | 10.0 HIGH | 9.8 CRITICAL |
Tokheim Profleet DiaLOG 11.005.02 is affected by SQL Injection. The component is the Field__UserLogin parameter on the logon page. | |||||
CVE-2022-24646 | 1 Hospital Management System Project | 1 Hospital Management System | 2022-02-16 | 7.8 HIGH | 7.5 HIGH |
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters. | |||||
CVE-2022-24263 | 1 Hospital Management System Project | 1 Hospital Management System | 2022-02-11 | 7.5 HIGH | 9.8 CRITICAL |
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter. | |||||
CVE-2022-23046 | 1 Phpipam | 1 Phpipam | 2022-02-11 | 6.5 MEDIUM | 7.2 HIGH |
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php | |||||
CVE-2021-25114 | 1 Strangerstudios | 1 Paid Memberships Pro | 2022-02-10 | 7.5 HIGH | 9.8 CRITICAL |
The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection | |||||
CVE-2021-43927 | 1 Synology | 1 Diskstation Manager | 2022-02-10 | 7.5 HIGH | 9.8 CRITICAL |
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors. | |||||
CVE-2021-43926 | 1 Synology | 1 Diskstation Manager | 2022-02-10 | 7.5 HIGH | 9.8 CRITICAL |
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors. | |||||
CVE-2021-43925 | 1 Synology | 1 Diskstation Manager | 2022-02-10 | 7.5 HIGH | 9.8 CRITICAL |
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management functionality in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to inject SQL commands via unspecified vectors. | |||||
CVE-2020-5722 | 1 Grandstream | 2 Ucm6200, Ucm6200 Firmware | 2022-02-09 | 10.0 HIGH | 9.8 CRITICAL |
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17. | |||||
CVE-2022-23379 | 1 Emlog | 1 Emlog | 2022-02-09 | 7.5 HIGH | 9.8 CRITICAL |
Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid(). | |||||
CVE-2021-44866 | 1 Projectworlds | 1 Online Movie Ticket Booking System | 2022-02-09 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database. | |||||
CVE-2021-44779 | 1 \[gwa\] Autoresponder Project | 1 \[gwa\] Autoresponder | 2022-02-08 | 7.5 HIGH | 9.8 CRITICAL |
Unauthenticated SQL Injection (SQLi) vulnerability discovered in [GWA] AutoResponder WordPress plugin (versions <= 2.3), vulnerable at (&listid). No patched version available, plugin closed. | |||||
CVE-2022-24121 | 2 Centos, Unifiedoffice | 2 Centos, Total Connect Now | 2022-02-08 | 5.0 MEDIUM | 7.5 HIGH |
SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information through a cookie parameter. | |||||
CVE-2022-23873 | 1 Victor Cms Project | 1 Victor Cms | 2022-02-08 | 6.5 MEDIUM | 8.8 HIGH |
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter. | |||||
CVE-2021-42633 | 1 Printerlogic | 1 Web Stack | 2022-02-07 | 5.0 MEDIUM | 5.3 MEDIUM |
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records. | |||||
CVE-2021-46459 | 1 Victor Cms Project | 1 Victor Cms | 2022-02-04 | 5.0 MEDIUM | 7.5 HIGH |
Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source=add_user. These vulnerabilities can be exploited through a crafted POST request via the user_name, user_firstname,user_lastname, or user_email parameters. | |||||
CVE-2021-24919 | 1 Wickedplugins | 1 Wicked Folders | 2022-02-04 | 6.5 MEDIUM | 8.8 HIGH |
The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection | |||||
CVE-2021-43509 | 1 Simple Client Management System Project | 1 Simple Client Management System | 2022-02-04 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php. |