Export limit exceeded: 18274 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (18274 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-31099 | 2025-03-28 | 7.6 High | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bestwebsoft Slider by BestWebSoft allows SQL Injection. This issue affects Slider by BestWebSoft: from n/a through 1.1.0. | ||||
| CVE-2025-31466 | 2025-03-28 | 8.5 High | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Falcon Solutions Duplicate Page and Post allows Blind SQL Injection. This issue affects Duplicate Page and Post: from n/a through 1.0. | ||||
| CVE-2022-46499 | 2 Codeastro, Phpgurukul | 2 Hospital Management System, Hospital Management System | 2025-03-28 | 8.8 High |
| Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php. | ||||
| CVE-2022-46498 | 2 Codeastro, Phpgurukul | 2 Hospital Management System, Hospital Management System | 2025-03-28 | 2.7 Low |
| Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php. | ||||
| CVE-2022-46497 | 2 Codeastro, Phpgurukul | 2 Hospital Management System, Hospital Management System | 2025-03-28 | 8.1 High |
| Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php. | ||||
| CVE-2022-48011 | 1 Opencats | 1 Opencats | 2025-03-28 | 9.8 Critical |
| Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function. | ||||
| CVE-2025-25514 | 1 Seacms | 1 Seacms | 2025-03-28 | 6.5 Medium |
| Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php. | ||||
| CVE-2025-25515 | 1 Seacms | 1 Seacms | 2025-03-28 | 8.8 High |
| Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database. | ||||
| CVE-2025-25516 | 1 Seacms | 1 Seacms | 2025-03-28 | 9.8 Critical |
| Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php. | ||||
| CVE-2025-25517 | 1 Seacms | 1 Seacms | 2025-03-28 | 9.8 Critical |
| Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php. | ||||
| CVE-2025-25519 | 1 Seacms | 1 Seacms | 2025-03-28 | 9.8 Critical |
| Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php. | ||||
| CVE-2025-25520 | 1 Seacms | 1 Seacms | 2025-03-28 | 9.8 Critical |
| Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php. | ||||
| CVE-2025-25521 | 1 Seacms | 1 Seacms | 2025-03-28 | 9.8 Critical |
| Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php. | ||||
| CVE-2024-29275 | 1 Seacms | 1 Seacms | 2025-03-28 | 9.8 Critical |
| SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php. | ||||
| CVE-2021-36880 | 1 Stylemixthemes | 1 Ulisting | 2025-03-28 | 8.6 High |
| Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom. | ||||
| CVE-2021-36916 | 1 Wpwave | 1 Hide My Wp | 2025-03-28 | 8.6 High |
| The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function "hmwp_get_user_ip" tries to retrieve the IP address from multiple headers, including IP address headers that the user can spoof, such as "X-Forwarded-For." As a result, the malicious payload supplied in one of these IP address headers will be directly inserted into the SQL query, making SQL injection possible. | ||||
| CVE-2024-53438 | 1 Churchcrm | 1 Churchcrm | 2025-03-28 | 9.8 Critical |
| EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands. | ||||
| CVE-2024-55104 | 1 Phpgurukul | 1 Online Nurse Hiring System | 2025-03-28 | 7.2 High |
| Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters. | ||||
| CVE-2024-55103 | 1 Phpgurukul | 1 Online Nurse Hiring System | 2025-03-28 | 7.2 High |
| Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter. | ||||
| CVE-2023-0529 | 1 Online Tours \& Travels Management System Project | 1 Online Tours \& Travels Management System | 2025-03-28 | 4.7 Medium |
| A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/add_payment.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-219598 is the identifier assigned to this vulnerability. | ||||