Total
11593 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-21915 | 1 Advantech | 1 R-seenet | 2022-05-13 | 6.5 MEDIUM | 8.8 HIGH |
| An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery. | |||||
| CVE-2022-28461 | 1 Mingyuefusu Project | 1 Mingyuefusu | 2022-05-13 | 7.5 HIGH | 9.8 CRITICAL |
| mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection. | |||||
| CVE-2022-27360 | 1 Bladex | 1 Springblade | 2022-05-13 | 7.5 HIGH | 9.8 CRITICAL |
| SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment. | |||||
| CVE-2022-29938 | 1 Librehealth | 1 Librehealth Ehr | 2022-05-12 | 6.5 MEDIUM | 8.8 HIGH |
| In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection. | |||||
| CVE-2022-24707 | 1 Anuko | 1 Time Tracker | 2022-05-12 | 6.5 MEDIUM | 8.8 HIGH |
| Anuko Time Tracker is an open source, web-based time tracking application written in PHP. UNION SQL injection and time-based blind injection vulnerabilities existed in Time Tracker Puncher plugin in versions of anuko timetracker prior to 1.20.0.5642. This was happening because the Puncher plugin was reusing code from other places and was relying on an unsanitized date parameter in POST requests. Because the parameter was not checked, it was possible to craft POST requests with malicious SQL for Time Tracker database. This issue has been resolved in in version 1.20.0.5642. Users unable to upgrade are advised to add their own checks to input. | |||||
| CVE-2022-25491 | 1 Hospital Management System Project | 1 Hospital Management System | 2022-05-12 | 7.5 HIGH | 7.5 HIGH |
| HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php. | |||||
| CVE-2022-25004 | 1 Hospital\'s Patient Records Management System Project | 1 Hospital\'s Patient Records Management System | 2022-05-12 | 7.5 HIGH | 9.8 CRITICAL |
| Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php. | |||||
| CVE-2022-25490 | 1 Hospital Management System Project | 1 Hospital Management System | 2022-05-12 | 7.5 HIGH | 9.8 CRITICAL |
| HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php. | |||||
| CVE-2022-25492 | 1 Hospital Management System Project | 1 Hospital Management System | 2022-05-12 | 7.5 HIGH | 9.8 CRITICAL |
| HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php. | |||||
| CVE-2022-28079 | 1 College Management System Project | 1 College Management System | 2022-05-12 | 6.5 MEDIUM | 8.8 HIGH |
| College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter. | |||||
| CVE-2022-28080 | 1 Event Management System Project | 1 Event Management System | 2022-05-12 | 6.5 MEDIUM | 8.8 HIGH |
| Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter. | |||||
| CVE-2020-6145 | 1 Frappe | 1 Erpnext | 2022-05-12 | 6.5 MEDIUM | 8.8 HIGH |
| An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |||||
| CVE-2020-6114 | 1 Icehrm | 1 Icehrm | 2022-05-12 | 6.5 MEDIUM | 7.2 HIGH |
| An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |||||
| CVE-2022-27413 | 1 Hospital Management System Project | 1 Hospital Management System | 2022-05-12 | 7.5 HIGH | 9.8 CRITICAL |
| Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php. | |||||
| CVE-2021-42185 | 1 Wdja | 1 Wdja | 2022-05-12 | 7.5 HIGH | 9.8 CRITICAL |
| wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function. | |||||
| CVE-2022-28552 | 1 Chshcms | 1 Cscms | 2022-05-12 | 6.5 MEDIUM | 8.8 HIGH |
| Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin. | |||||
| CVE-2022-28512 | 1 Fantastic Blog Project | 1 Fantastic Blog | 2022-05-12 | 7.5 HIGH | 9.8 CRITICAL |
| A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters. | |||||
| CVE-2022-0657 | 1 5 Stars Rating Funnel Project | 1 5 Stars Rating Funnel | 2022-05-12 | 7.5 HIGH | 9.8 CRITICAL |
| The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an attempt to sanitise the input, using sanitize_text_field(), however such function is not intended to prevent SQL injections. | |||||
| CVE-2022-28099 | 1 Poultry Farm Management System Project | 1 Poultry Farm Management System | 2022-05-12 | 6.5 MEDIUM | 8.8 HIGH |
| Poultry Farm Management System v1.0 was discovered to contain a SQL injection vulnerability via the Item parameter at /farm/store.php. | |||||
| CVE-2022-28530 | 1 Covid-19 Directory On Vaccination System Project | 1 Covid-19 Directory On Vaccination System | 2022-05-11 | 7.5 HIGH | 9.8 CRITICAL |
| Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory. | |||||
