Search Results (18717 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-30870 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2025-04-04 8.8 High
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/address_interpret.php.
CVE-2024-30871 1 Netentsec 3 Application Security Gateway, Ns-asg, Ns-asg Firmware 2025-04-04 8.8 High
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/applyhardware.php.
CVE-2024-30872 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2025-04-04 5.1 Medium
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php.
CVE-2024-30864 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2025-04-04 6.3 Medium
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupTimePolicy.php.
CVE-2024-30865 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2025-04-04 9.8 Critical
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php.
CVE-2024-30866 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2025-04-04 5.4 Medium
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/menu.php.
CVE-2023-0281 1 Online Flight Booking Management System Project 1 Online Flight Booking Management System 2025-04-04 6.3 Medium
A vulnerability was found in SourceCodester Online Flight Booking Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file judge_panel.php. The manipulation of the argument subevent_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-218276.
CVE-2024-48283 1 Phpgurukul 2 User Registration \& Login And User Management System, User Registration And Login And User Management System 2025-04-04 9.8 Critical
Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter.
CVE-2024-46531 1 Phpgurukul 2 Vehicle Record Management System, Vehicle Record System 2025-04-04 6.3 Medium
phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchinputdata parameter at /index.php.
CVE-2024-34955 1 Code-projects 1 Budget Management 2025-04-04 9.8 Critical
Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.
CVE-2022-47745 1 Easycorp 1 Zentao 2025-04-04 8.8 High
ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.
CVE-2022-47740 1 Seltmann-webdesign 1 Content Management System 2025-04-04 9.8 Critical
Seltmann GmbH Content Management System 6 is vulnerable to SQL Injection via /index.php.
CVE-2024-30938 1 Sem-cms 1 Semcms 2025-04-04 9.8 Critical
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component.
CVE-2024-31077 1 Incsub 1 Forminator 2025-04-04 7.2 High
Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain and alter any information in the database and cause a denial-of-service (DoS) condition.
CVE-2023-23492 1 Idehweb 1 Login With Phone Number 2025-04-03 8.8 High
The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.
CVE-2023-23490 1 Ays-pro 1 Survey Maker 2025-04-03 8.8 High
The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' action.
CVE-2023-23489 1 Sandhillsdev 1 Easy Digital Downloads 2025-04-03 9.8 Critical
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's' parameter of its 'edd_download_search' action.
CVE-2023-23488 1 Strangerstudios 1 Paid Memberships Pro 2025-04-03 9.8 Critical
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.
CVE-2022-48152 1 Remoteclinic 1 Remote Clinic 2025-04-03 9.8 Critical
SQL Injection vulnerability in RemoteClinic 2.0 allows attackers to execute arbitrary commands and gain sensitive information via the id parameter to /medicines/profile.php.
CVE-2022-46887 1 Nexusphp 1 Nexusphp 2025-04-03 9.8 Critical
Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php.