Total
17599 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-25515 | 1 Seacms | 1 Seacms | 2025-03-28 | 8.8 High |
| Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database. | ||||
| CVE-2025-25516 | 1 Seacms | 1 Seacms | 2025-03-28 | 9.8 Critical |
| Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php. | ||||
| CVE-2025-25517 | 1 Seacms | 1 Seacms | 2025-03-28 | 9.8 Critical |
| Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php. | ||||
| CVE-2025-25519 | 1 Seacms | 1 Seacms | 2025-03-28 | 9.8 Critical |
| Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php. | ||||
| CVE-2025-25520 | 1 Seacms | 1 Seacms | 2025-03-28 | 9.8 Critical |
| Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php. | ||||
| CVE-2025-25521 | 1 Seacms | 1 Seacms | 2025-03-28 | 9.8 Critical |
| Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php. | ||||
| CVE-2024-29275 | 1 Seacms | 1 Seacms | 2025-03-28 | 9.8 Critical |
| SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php. | ||||
| CVE-2021-36880 | 1 Stylemixthemes | 1 Ulisting | 2025-03-28 | 8.6 High |
| Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom. | ||||
| CVE-2021-36916 | 1 Wpwave | 1 Hide My Wp | 2025-03-28 | 8.6 High |
| The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function "hmwp_get_user_ip" tries to retrieve the IP address from multiple headers, including IP address headers that the user can spoof, such as "X-Forwarded-For." As a result, the malicious payload supplied in one of these IP address headers will be directly inserted into the SQL query, making SQL injection possible. | ||||
| CVE-2024-53438 | 1 Churchcrm | 1 Churchcrm | 2025-03-28 | 9.8 Critical |
| EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands. | ||||
| CVE-2024-55104 | 1 Phpgurukul | 1 Online Nurse Hiring System | 2025-03-28 | 7.2 High |
| Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters. | ||||
| CVE-2024-55103 | 1 Phpgurukul | 1 Online Nurse Hiring System | 2025-03-28 | 7.2 High |
| Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter. | ||||
| CVE-2023-0529 | 1 Online Tours \& Travels Management System Project | 1 Online Tours \& Travels Management System | 2025-03-28 | 4.7 Medium |
| A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/add_payment.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-219598 is the identifier assigned to this vulnerability. | ||||
| CVE-2023-0532 | 1 Online Tours \& Travels Management System Project | 1 Online Tours \& Travels Management System | 2025-03-28 | 4.7 Medium |
| A vulnerability classified as critical was found in SourceCodester Online Tours & Travels Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/disapprove_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-219601 was assigned to this vulnerability. | ||||
| CVE-2023-22324 | 1 Contec | 1 Conprosys Hmi System | 2025-03-28 | 6.5 Medium |
| SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in the database may be obtained. | ||||
| CVE-2022-44298 | 1 Sscms | 1 Siteserver Cms | 2025-03-28 | 9.8 Critical |
| SiteServer CMS 7.1.3 is vulnerable to SQL Injection. | ||||
| CVE-2024-27746 | 1 Mayurik | 1 Petrol Pump Management | 2025-03-28 | 9.8 Critical |
| SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component. | ||||
| CVE-2023-49546 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 8.8 High |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php. | ||||
| CVE-2023-49547 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 9.8 Critical |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login. | ||||
| CVE-2023-49548 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | 8.8 High |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user. | ||||