Total
14859 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-40877 | 1 Exam Reviewer Management System Project | 1 Exam Reviewer Management System | 2025-05-21 | N/A | 9.8 CRITICAL |
Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter. | |||||
CVE-2022-40354 | 1 Online Tours \& Travels Management System Project | 1 Online Tours \& Travels Management System | 2025-05-21 | N/A | 7.2 HIGH |
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php. | |||||
CVE-2022-3323 | 1 Advantech | 1 Iview | 2025-05-21 | N/A | 7.5 HIGH |
An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a special column_value parameter in the setConfiguration action to bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform SQL injection. For example, the attacker can exploit the vulnerability to retrieve the iView admin password. | |||||
CVE-2021-41433 | 1 Resumes Management And Job Application Website Application Project | 1 Resumes Management And Job Application Website Application | 2025-05-21 | N/A | 9.8 CRITICAL |
SQL Injection vulnerability exists in version 1.0 of the Resumes Management and Job Application Website application login form by EGavilan Media that allows authentication bypass through login.php. | |||||
CVE-2025-4773 | 1 Phpgurukul | 1 Online Course Registration | 2025-05-21 | 7.5 HIGH | 7.3 HIGH |
A vulnerability was found in PHPGurukul Online Course Registration 3.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/level.php. The manipulation of the argument level leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-4777 | 1 Phpgurukul | 1 Park Ticketing Management System | 2025-05-21 | 6.5 MEDIUM | 6.3 MEDIUM |
A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been classified as critical. This affects an unknown part of the file /view-foreigner-ticket.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-39481 | 1 Imithemes | 1 Eventer | 2025-05-21 | N/A | 9.3 CRITICAL |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in imithemes Eventer allows Blind SQL Injection. This issue affects Eventer: from n/a through 3.9.6. | |||||
CVE-2025-4771 | 1 Phpgurukul | 1 Online Course Registration | 2025-05-21 | 7.5 HIGH | 7.3 HIGH |
A vulnerability, which was classified as critical, was found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/course.php. The manipulation of the argument coursecode leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-4911 | 1 Phpgurukul | 1 Zoo Management System | 2025-05-21 | 7.5 HIGH | 7.3 HIGH |
A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/view-foreigner-ticket.php. The manipulation of the argument viewid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-4925 | 1 Phpgurukul | 1 Daily Expense Tracker System | 2025-05-21 | 7.5 HIGH | 7.3 HIGH |
A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /expense-monthwise-reports-detailed.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-4927 | 1 Phpgurukul | 1 Online Marriage Registration System | 2025-05-21 | 7.5 HIGH | 7.3 HIGH |
A vulnerability was found in PHPGurukul Online Marriage Registration System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/between-dates-application-report.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2022-41440 | 1 Billing System Project Project | 1 Billing System Project | 2025-05-20 | N/A | 7.2 HIGH |
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editcategory.php. | |||||
CVE-2022-41439 | 1 Billing System Project Project | 1 Billing System Project | 2025-05-20 | N/A | 7.2 HIGH |
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php. | |||||
CVE-2022-40887 | 1 Best Student Result Management System Project | 1 Best Student Result Management System | 2025-05-20 | N/A | 9.8 CRITICAL |
SourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection. | |||||
CVE-2022-33880 | 1 Hospital Management System Mini-project Project | 1 Hospital Management System Mini-project | 2025-05-20 | N/A | 9.8 CRITICAL |
hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the type parameter. | |||||
CVE-2024-29169 | 1 Dell | 1 Secure Connect Gateway | 2025-05-20 | N/A | 5.4 MEDIUM |
Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST API. A remote authenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing potential unauthorized access and modification of application data. | |||||
CVE-2022-40944 | 1 Phpgurukul | 1 Dairy Farm Shop Management System | 2025-05-20 | N/A | 9.8 CRITICAL |
Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file. | |||||
CVE-2022-40315 | 2 Fedoraproject, Moodle | 3 Extra Packages For Enterprise Linux, Fedora, Moodle | 2025-05-20 | N/A | 9.8 CRITICAL |
A limited SQL injection risk was identified in the "browse list of users" site administration page. | |||||
CVE-2022-41532 | 1 Open Source Sacco Management System Project | 1 Open Source Sacco Management System | 2025-05-20 | N/A | 7.2 HIGH |
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_plan. | |||||
CVE-2022-40943 | 1 Phpgurukul | 1 Dairy Farm Shop Management System | 2025-05-20 | N/A | 9.8 CRITICAL |
Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file. |