Total
19951 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-44291 | 1 Webtareas Project | 1 Webtareas | 2026-07-09 | N/A | 9.8 CRITICAL |
| webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php. | |||||
| CVE-2022-44290 | 1 Webtareas Project | 1 Webtareas | 2026-07-09 | N/A | 9.8 CRITICAL |
| webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php. | |||||
| CVE-2022-42122 | 1 Liferay | 2 Dxp, Liferay Portal | 2026-07-09 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL. | |||||
| CVE-2022-42121 | 1 Liferay | 3 Digital Experience Platform, Dxp, Liferay Portal | 2026-07-09 | N/A | 8.8 HIGH |
| A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field. | |||||
| CVE-2022-42120 | 1 Liferay | 2 Dxp, Liferay Portal | 2026-07-09 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute. | |||||
| CVE-2022-40839 | 1 Ndk-design | 1 Ndkadvancedcustomizationfields | 2026-07-09 | N/A | 7.5 HIGH |
| A SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers to exfiltrate database data. | |||||
| CVE-2022-40030 | 1 Simple Task Managing System Project | 1 Simple Task Managing System | 2026-07-09 | N/A | 9.8 CRITICAL |
| SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php. | |||||
| CVE-2022-38619 | 1 Bpcbt | 1 Smartvista Front-end | 2026-07-09 | N/A | 9.8 CRITICAL |
| SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf. | |||||
| CVE-2022-38618 | 1 Bpcbt | 1 Smartvista | 2026-07-09 | N/A | 8.8 HIGH |
| SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/country_group.jsf. | |||||
| CVE-2022-38617 | 1 Bpcbt | 1 Smartvista | 2026-07-09 | N/A | 8.8 HIGH |
| SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/voiceaudit.jsf. | |||||
| CVE-2022-38616 | 1 Bpcbt | 1 Smartvista Front-end | 2026-07-09 | N/A | 8.8 HIGH |
| SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.jsf. | |||||
| CVE-2022-38615 | 1 Bpcbt | 1 Smartvista Front-end | 2026-07-09 | N/A | 8.8 HIGH |
| SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf. | |||||
| CVE-2022-37773 | 1 Maarch | 1 Maarch Rm | 2026-07-09 | N/A | 6.5 MEDIUM |
| An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allows the complete disclosure of all databases. | |||||
| CVE-2022-36635 | 1 Zkteco | 1 Zkbiosecurity V5000 | 2026-07-09 | N/A | 8.8 HIGH |
| ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do. | |||||
| CVE-2022-35156 | 1 Phpgurukul | 1 Bus Pass Management System | 2026-07-09 | N/A | 9.8 CRITICAL |
| Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php.. | |||||
| CVE-2022-31384 | 1 Phpgurukul | 1 Directory Management System | 2026-07-09 | 7.5 HIGH | 9.8 CRITICAL |
| Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php. | |||||
| CVE-2022-31383 | 1 Phpgurukul | 1 Directory Management System | 2026-07-09 | 7.5 HIGH | 9.8 CRITICAL |
| Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php. | |||||
| CVE-2022-31382 | 1 Phpgurukul | 1 Directory Management System | 2026-07-09 | 7.5 HIGH | 9.8 CRITICAL |
| Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php. | |||||
| CVE-2022-30490 | 1 Badminton Center Management System Project | 1 Badminton Center Management System | 2026-07-09 | 7.5 HIGH | 9.8 CRITICAL |
| Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php. | |||||
| CVE-2022-29709 | 1 Communilink | 1 Clink Office | 2026-07-09 | N/A | 7.5 HIGH |
| CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters. | |||||
