Total
12997 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-10380 | 1 Mayurik | 1 Petrol Pump Management | 2024-11-01 | 6.3 Medium |
A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/ajax_product.php. The manipulation of the argument drop_services leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-35750 | 1 Wpdevart | 1 Gallery | 2024-11-01 | 8.5 High |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevart Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3. | ||||
CVE-2024-6479 | 2024-11-01 | 6.5 Medium | ||
The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions up to, and including, 1.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
CVE-2024-6480 | 2024-11-01 | 6.4 Medium | ||
The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
CVE-2024-48573 | 1 Aquila | 1 Cms | 2024-11-01 | 9.8 Critical |
A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature. | ||||
CVE-2024-46531 | 1 Phpgurukul | 1 Vehicle Record Management System | 2024-11-01 | 6.3 Medium |
phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchinputdata parameter at /index.php. | ||||
CVE-2024-48307 | 1 Jeecg | 1 Jeecgboot | 2024-11-01 | 9.8 Critical |
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData. | ||||
CVE-2024-10546 | 1 Shanghai Gedan Network Technology | 1 Teaching | 2024-11-01 | 6.3 Medium |
A vulnerability classified as critical was found in open-scratch Teaching 在线教学平台 up to 2.7. This vulnerability affects unknown code of the file /api/sys/ng-alain/getDictItemsByTable/ of the component URL Handler. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
CVE-2024-10331 | 1 Phpgurukul | 1 Vehicle Record System | 2024-11-01 | 6.3 Medium |
A vulnerability, which was classified as critical, has been found in PHPGurukul Vehicle Record System 1.0. This issue affects some unknown processing of the file /admin/search-vehicle.php. The manipulation of the argument searchinputdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-24093 | 1 Code-projects | 1 Scholars Tracking System | 2024-10-31 | 9.8 Critical |
SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information. | ||||
CVE-2024-3592 | 1 Expresstech | 1 Quiz And Survey Master | 2024-10-31 | 9.9 Critical |
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' parameter in all versions up to, and including, 9.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
CVE-2024-28303 | 1 Sourcecodester | 1 Open Source Medicine Ordering System | 2024-10-31 | 9.8 Critical |
Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php. | ||||
CVE-2024-7042 | 2 Langchain, Langchain-ai | 2 Langchain, Langchainjs | 2024-10-31 | 9.8 Critical |
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability permits unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across different tenants, and compromise the integrity of the database. | ||||
CVE-2024-25325 | 2024-10-31 | 7.1 High | ||
SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to the txtemail parameter in the login.php. | ||||
CVE-2023-35070 | 1 Vegagroup | 1 Web Collection | 2024-10-31 | 9.8 Critical |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VegaGroup Web Collection allows SQL Injection.This issue affects Web Collection: before 31197. | ||||
CVE-2024-48230 | 1 Funadmin | 1 Funadmin | 2024-10-31 | 9.8 Critical |
funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php. | ||||
CVE-2024-48229 | 1 Funadmin | 1 Funadmin | 2024-10-31 | 9.8 Critical |
funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin. | ||||
CVE-2024-48223 | 1 Funadmin | 1 Funadmin | 2024-10-31 | 9.8 Critical |
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist. | ||||
CVE-2024-48222 | 1 Funadmin | 1 Funadmin | 2024-10-31 | 9.8 Critical |
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit. | ||||
CVE-2024-48218 | 1 Funadmin | 1 Funadmin | 2024-10-31 | 9.8 Critical |
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list. |