Total
15984 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2025-6339 | 2025-06-23 | 7.5 HIGH | 7.3 HIGH | ||
A vulnerability was found in ponaravindb Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /func3.php. The manipulation of the argument username1 leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-6276 | 2025-06-23 | 6.5 MEDIUM | 6.3 MEDIUM | ||
A vulnerability was found in Brilliance Golden Link Secondary System up to 20250609. It has been rated as critical. Affected by this issue is some unknown functionality of the file /storagework/rentTakeInfoPage.htm. The manipulation of the argument custTradeName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-52822 | 2025-06-23 | N/A | 8.5 HIGH | ||
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WP Roadmap allows SQL Injection. This issue affects WP Roadmap: from n/a through 2.1.3. | |||||
CVE-2024-36428 | 1 Orangehrm | 1 Orangehrm | 2025-06-23 | N/A | 8.1 HIGH |
OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection. | |||||
CVE-2025-28056 | 1 Ruifang-tech | 1 Rebuild | 2025-06-23 | N/A | 9.8 CRITICAL |
rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component. | |||||
CVE-2024-40570 | 1 Seacms | 1 Seacms | 2025-06-23 | N/A | 6.5 MEDIUM |
SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component. | |||||
CVE-2025-4734 | 1 Campcodes | 1 Sales And Inventory System | 2025-06-21 | 7.5 HIGH | 7.3 HIGH |
A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/ci_update.php. The manipulation of the argument id/name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2024-25312 | 1 Code-projects | 1 Simple School Management System | 2025-06-20 | N/A | 8.8 HIGH |
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5." | |||||
CVE-2024-25310 | 1 Code-projects | 1 Simple School Management System | 2025-06-20 | N/A | 8.8 HIGH |
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5." | |||||
CVE-2024-25307 | 1 Code-projects | 1 Cinema Seat Reservation System | 2025-06-20 | N/A | 9.8 CRITICAL |
Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1." | |||||
CVE-2024-24015 | 1 Xxyopen | 1 Novel-plus | 2025-06-20 | N/A | 9.8 CRITICAL |
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL via /sys/user/exit | |||||
CVE-2023-46350 | 1 Innovadeluxe | 1 Manufacturer Or Supplier Alphabetical Search | 2025-06-20 | N/A | 9.8 CRITICAL |
SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods IdxrmanufacturerFunctions::getCornersLink, IdxrmanufacturerFunctions::getManufacturersLike and IdxrmanufacturerFunctions::getSuppliersLike. | |||||
CVE-2023-51951 | 1 Stock Management System Project | 1 Stock Management System | 2025-06-20 | N/A | 9.8 CRITICAL |
SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file. | |||||
CVE-2024-23751 | 1 Llamaindex | 1 Llamaindex | 2025-06-20 | N/A | 9.8 CRITICAL |
LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQueryEngine, NLSQLRetriever, RetrieverQueryEngine, and PGVectorSQLQueryEngine. For example, an attacker might be able to delete this year's student records via "Drop the Students table" within English language input. | |||||
CVE-2023-48118 | 1 Quest-analytics | 1 Iqcrm | 2025-06-20 | N/A | 9.8 CRITICAL |
SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code via a crafted request to the Common.svc WSDL page. | |||||
CVE-2023-46351 | 1 Mypresta | 1 Manufacturers \(brands\) Images Block | 2025-06-20 | N/A | 9.8 CRITICAL |
In the module mib < 1.6.1 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The methods `mib::getManufacturersByCategory()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection. | |||||
CVE-2022-43216 | 1 Abrhil | 1 Lista De Asistencia | 2025-06-20 | N/A | 9.1 CRITICAL |
AbrhilSoft Employee's Portal before v5.6.2 was discovered to contain a SQL injection vulnerability in the login page. | |||||
CVE-2024-29390 | 1 Anujk305 | 1 Daily Expenses Management System | 2025-06-20 | N/A | 7.3 HIGH |
Daily Expenses Management System version 1.0, developed by PHP Gurukul, contains a time-based blind SQL injection vulnerability in the 'add-expense.php' page. An attacker can exploit the 'item' parameter in a POST request to execute arbitrary SQL commands in the backend database. This can be done by injecting specially crafted SQL queries that make the database perform time-consuming operations, thereby confirming the presence of the SQL injection vulnerability based on the delay in the server's response. | |||||
CVE-2024-22627 | 1 Campcodes | 1 Supplier Management System | 2025-06-20 | N/A | 7.2 HIGH |
Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_distributor.php?id=. | |||||
CVE-2023-51810 | 1 Stackideas | 1 Easydiscuss | 2025-06-20 | N/A | 7.5 HIGH |
SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted request to the search parameter in the Users module. |