Total
16050 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2025-22700 | 2025-02-04 | N/A | 8.5 HIGH | ||
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Traveler Code. This issue affects Traveler Code: from n/a through 3.1.0. | |||||
CVE-2024-55593 | 1 Fortinet | 1 Fortiweb | 2025-02-03 | N/A | 2.7 LOW |
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries | |||||
CVE-2024-52969 | 1 Fortinet | 1 Fortisiem | 2025-02-03 | N/A | 4.1 MEDIUM |
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiSIEM ersion 7.1.7 and below, version 7.1.0, version 7.0.3 and below, version 6.7.9 and below, 6.7.8, version 6.6.5 and below, version 6.5.3 and below, version 6.4.4 and below Update/Create Case feature may allow an authenticated attacker to extract database information via crafted requests. | |||||
CVE-2012-5872 | 1 Arc2 Project | 1 Arc2 | 2025-02-03 | N/A | 9.8 CRITICAL |
ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause. | |||||
CVE-2023-27843 | 1 Ask For A Quote Project | 1 Ask For A Quote | 2025-02-03 | N/A | 9.8 CRITICAL |
SQL injection vulnerability found in PrestaShop askforaquote v.5.4.2 and before allow a remote attacker to gain privileges via the QuotesProduct::deleteProduct component. | |||||
CVE-2025-22976 | 2025-02-03 | N/A | 7.1 HIGH | ||
SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a local attacker to execute arbitrary code via not filtering the content correctly at the "checkOrder.php" shopId module. | |||||
CVE-2025-22964 | 2025-02-03 | N/A | 8.1 HIGH | ||
DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "table" parameter. This flaw allows attackers to inject malicious SQL queries by directly incorporating user-supplied input into database queries without proper escaping or validation. Exploiting this issue enables unauthorized access, manipulation of data, or exposure of sensitive information, posing significant risks to the integrity and confidentiality of the application. | |||||
CVE-2023-30211 | 1 Ourphp | 1 Ourphp | 2025-02-03 | N/A | 9.8 CRITICAL |
OURPHP <= 7.2.0 is vulnerable to SQL Injection. | |||||
CVE-2023-30112 | 1 Medicine Tracker System Project | 1 Medicine Tracker System | 2025-02-03 | N/A | 7.5 HIGH |
Medicine Tracker System in PHP 1.0.0 is vulnerable to SQL Injection. | |||||
CVE-2025-22691 | 2025-02-03 | N/A | 7.6 HIGH | ||
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel allows SQL Injection. This issue affects WP Travel: from n/a through 10.1.0. | |||||
CVE-2019-19245 | 1 Napc | 1 Xinet Elegant 6 Asset Library | 2025-02-02 | 7.5 HIGH | 9.8 CRITICAL |
NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used. | |||||
CVE-2022-4118 | 1 Coinmarketstats | 1 Bitcoin \/ Altcoin Payment Gateway For Woocommerce | 2025-01-31 | N/A | 9.8 CRITICAL |
The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users | |||||
CVE-2024-57775 | 1 Jfinaloa Project | 1 Jfinaloa | 2025-01-31 | N/A | 8.8 HIGH |
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid. | |||||
CVE-2025-0861 | 1 Vruiz | 1 Vr-frases | 2025-01-31 | N/A | 4.9 MEDIUM |
The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to SQL Injection via several parameters in all versions up to, and including, 3.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | |||||
CVE-2023-37777 | 2025-01-31 | N/A | 9.8 CRITICAL | ||
A SQL injection vulnerability exists in Synnefo Internet Management Software (IMS) version 2023 and earlier. This vulnerability occurs due to improper input validation in a specific API endpoint parameter allowing an attacker to manipulate SQL queries via crafted input. Successful exploitation could lead to unauthorized access to database records with DB administrator privileges which can be leveraged to escalate privileges further and execute arbitrary OS commands. | |||||
CVE-2024-13596 | 1 Modalsurvey | 1 Wordpress Survey And Poll | 2025-01-31 | N/A | 6.5 MEDIUM |
The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'survey' shortcode in all versions up to, and including, 1.7.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | |||||
CVE-2023-26813 | 1 Wang.market | 1 Wangmarket Cms | 2025-01-31 | N/A | 9.8 CRITICAL |
SQL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java in wangmarket CMS 4.10 allows remote attackers to run arbitrary SQL commands via the TableName parameter to /plugin/dataDictionary/tableView.do. | |||||
CVE-2023-26781 | 1 Chshcms | 1 Mccms | 2025-01-31 | N/A | 9.8 CRITICAL |
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search. | |||||
CVE-2024-35278 | 1 Fortinet | 1 Fortiportal | 2025-01-31 | N/A | 4.3 MEDIUM |
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special elements in said request. | |||||
CVE-2024-35275 | 1 Fortinet | 4 Fortianalyzer, Fortianalyzer Cloud, Fortimanager and 1 more | 2025-01-31 | N/A | 6.6 MEDIUM |
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests. |