Vulnerabilities (CVE)

Filtered by CWE-89
Total 15371 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-40954 1 Gmarczynski 1 Dynamic Progress Bar 2024-11-21 N/A 9.8 CRITICAL
A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component.
CVE-2023-40946 1 Schoolmate Project 1 Schoolmate 2024-11-21 N/A 9.8 CRITICAL
Schoolmate 1.3 is vulnerable to SQL Injection in the variable $username from SESSION in ValidateLogin.php.
CVE-2023-40945 1 Doctor Appointment System Project 1 Doctor Appointment System 2024-11-21 N/A 9.8 CRITICAL
Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php.
CVE-2023-40944 1 Schoolmate Project 1 Schoolmate 2024-11-21 N/A 9.8 CRITICAL
Schoolmate 1.3 is vulnerable to SQL Injection in the variable $schoolname from Database at ~\header.php.
CVE-2023-40934 1 Nagios 1 Nagios Xi 2024-11-21 N/A 7.2 HIGH
A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.
CVE-2023-40933 1 Nagios 1 Nagios Xi 2024-11-21 N/A 8.8 HIGH
A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.
CVE-2023-40931 1 Nagios 1 Nagios Xi 2024-11-21 N/A 6.5 MEDIUM
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php
CVE-2023-40923 1 Myprestamodules 1 Orders \(csv\, Excel\) Export 2024-11-21 N/A 8.8 HIGH
MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and save_setting parameters.
CVE-2023-40922 1 Kerawen 1 Kerawen 2024-11-21 N/A 9.8 CRITICAL
kerawen before v2.5.1 was discovered to contain a SQL injection vulnerability via the ocs_id_cart parameter at KerawenDeliveryModuleFrontController::initContent().
CVE-2023-40921 1 Common-services 1 Soliberte 2024-11-21 N/A 9.8 CRITICAL
SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters.
CVE-2023-40920 1 Prixan 1 Prixanconnect 2024-11-21 N/A 9.8 CRITICAL
Prixan prixanconnect up to v1.62 was discovered to contain a SQL injection vulnerability via the component CartsGuruCatalogModuleFrontController::importProducts().
CVE-2023-40852 1 User Registration \& Login And User Management System With Admin Panel Project 1 User Registration \& Login And User Management System With Admin Panel 2024-11-21 N/A 9.8 CRITICAL
SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page.
CVE-2023-40787 1 Bladex 1 Springblade 2024-11-21 N/A 9.8 CRITICAL
In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection.
CVE-2023-40771 1 Dataease 1 Dataease 2024-11-21 N/A 7.5 HIGH
SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function.
CVE-2023-40749 1 Phpjabbers 1 Food Delivery Script 2024-11-21 N/A 9.8 CRITICAL
PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.
CVE-2023-40748 1 Phpjabbers 1 Food Delivery Script 2024-11-21 N/A 9.8 CRITICAL
PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.
CVE-2023-40629 1 King-products 1 Lms King Lite 2024-11-21 N/A 9.8 CRITICAL
SQLi vulnerability in LMS Lite component for Joomla.
CVE-2023-40609 1 Rocklobster 1 Contact Form 7 Custom Validation 2024-11-21 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aiyaz, maheshpatel Contact form 7 Custom validation allows SQL Injection.This issue affects Contact form 7 Custom validation: from n/a through 1.1.3.
CVE-2023-40215 1 Superwhite 1 Demon Image Annotation 2024-11-21 N/A 7.2 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Demonisblack demon image annotation allows SQL Injection.This issue affects demon image annotation: from n/a through 5.1.
CVE-2023-40207 1 Rednao 1 Donations Made Easy - Smart Donations 2024-11-21 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedNao Donations Made Easy – Smart Donations allows SQL Injection.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12.