Total
16215 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2025-31466 | 2025-03-28 | N/A | 8.5 HIGH | ||
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Falcon Solutions Duplicate Page and Post allows Blind SQL Injection. This issue affects Duplicate Page and Post: from n/a through 1.0. | |||||
CVE-2025-31099 | 2025-03-28 | N/A | 7.6 HIGH | ||
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bestwebsoft Slider by BestWebSoft allows SQL Injection. This issue affects Slider by BestWebSoft: from n/a through 1.1.0. | |||||
CVE-2025-22523 | 2025-03-28 | N/A | 9.3 CRITICAL | ||
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Schedule allows Blind SQL Injection. This issue affects Schedule: from n/a through 1.0.0. | |||||
CVE-2024-11504 | 2025-03-28 | N/A | N/A | ||
Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, which might be exploited by an authenticated remote attacker. This issue was fixed in 18.1.376.37 version of the software. | |||||
CVE-2025-26898 | 2025-03-28 | N/A | 9.3 CRITICAL | ||
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler.This issue affects Traveler: from n/a through 3.1.8. | |||||
CVE-2022-46499 | 1 Phpgurukul | 1 Hospital Management System | 2025-03-28 | N/A | 8.8 HIGH |
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php. | |||||
CVE-2022-46498 | 1 Phpgurukul | 1 Hospital Management System | 2025-03-28 | N/A | 2.7 LOW |
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php. | |||||
CVE-2022-46497 | 1 Phpgurukul | 1 Hospital Management System | 2025-03-28 | N/A | 8.1 HIGH |
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php. | |||||
CVE-2022-48011 | 1 Opencats | 1 Opencats | 2025-03-28 | N/A | 9.8 CRITICAL |
Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function. | |||||
CVE-2025-25514 | 1 Seacms | 1 Seacms | 2025-03-28 | N/A | 6.5 MEDIUM |
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php. | |||||
CVE-2025-25515 | 1 Seacms | 1 Seacms | 2025-03-28 | N/A | 8.8 HIGH |
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database. | |||||
CVE-2025-25516 | 1 Seacms | 1 Seacms | 2025-03-28 | N/A | 9.8 CRITICAL |
Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php. | |||||
CVE-2025-25517 | 1 Seacms | 1 Seacms | 2025-03-28 | N/A | 9.8 CRITICAL |
Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php. | |||||
CVE-2025-25519 | 1 Seacms | 1 Seacms | 2025-03-28 | N/A | 9.8 CRITICAL |
Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php. | |||||
CVE-2025-25520 | 1 Seacms | 1 Seacms | 2025-03-28 | N/A | 9.8 CRITICAL |
Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php. | |||||
CVE-2025-25521 | 1 Seacms | 1 Seacms | 2025-03-28 | N/A | 9.8 CRITICAL |
Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php. | |||||
CVE-2024-12969 | 1 Fabianros | 1 Hospital Management System | 2025-03-28 | 7.5 HIGH | 7.3 HIGH |
A vulnerability, which was classified as critical, has been found in code-projects Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/index.php of the component Login. The manipulation of the argument username/password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2024-29275 | 1 Seacms | 1 Seacms | 2025-03-28 | N/A | 9.8 CRITICAL |
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php. | |||||
CVE-2024-53438 | 1 Churchcrm | 1 Churchcrm | 2025-03-28 | N/A | 9.8 CRITICAL |
EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands. | |||||
CVE-2024-55104 | 1 Phpgurukul | 1 Online Nurse Hiring System | 2025-03-28 | N/A | 7.2 HIGH |
Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters. |