Total
18508 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-41262 | 1 Plixer | 1 Scrutinizer | 2024-11-21 | 9.8 Critical |
| An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV is vulnerable to SQL injection through the sorting parameter, allowing an unauthenticated user to execute arbitrary SQL statements in the context of the application's backend database server. | ||||
| CVE-2023-40989 | 1 Jeecg | 1 Jeecg Boot | 2024-11-21 | 9.8 Critical |
| SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component. | ||||
| CVE-2023-40970 | 1 Slims | 1 Senayan Library Management System | 2024-11-21 | 8.8 High |
| Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php. | ||||
| CVE-2023-40958 | 1 Didotech | 1 Engineering \& Lifecycle Management | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the query parameter in models/base_client.py component. | ||||
| CVE-2023-40957 | 1 Didotech | 1 Engineering \& Lifecycle Management | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the request parameter in models/base_client.py component. | ||||
| CVE-2023-40956 | 1 Cloudroits | 1 Wesite Job Search | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability in Cloudroits Website Job Search v.15.0 allows a remote authenticated attacker to execute arbitrary code via the name parameter in controllers/main.py component. | ||||
| CVE-2023-40955 | 1 Didotech | 1 Engineering \& Lifecycle Management | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the select parameter in models/base_client.py component. | ||||
| CVE-2023-40954 | 1 Gmarczynski | 1 Dynamic Progress Bar | 2024-11-21 | 9.8 Critical |
| A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component. | ||||
| CVE-2023-40946 | 1 Schoolmate Project | 1 Schoolmate | 2024-11-21 | 9.8 Critical |
| Schoolmate 1.3 is vulnerable to SQL Injection in the variable $username from SESSION in ValidateLogin.php. | ||||
| CVE-2023-40945 | 1 Doctor Appointment System Project | 1 Doctor Appointment System | 2024-11-21 | 9.8 Critical |
| Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php. | ||||
| CVE-2023-40944 | 1 Schoolmate Project | 1 Schoolmate | 2024-11-21 | 9.8 Critical |
| Schoolmate 1.3 is vulnerable to SQL Injection in the variable $schoolname from Database at ~\header.php. | ||||
| CVE-2023-40934 | 1 Nagios | 1 Nagios Xi | 2024-11-21 | 7.2 High |
| A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings. | ||||
| CVE-2023-40933 | 1 Nagios | 1 Nagios Xi | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function. | ||||
| CVE-2023-40931 | 1 Nagios | 1 Nagios Xi | 2024-11-21 | 6.5 Medium |
| A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php | ||||
| CVE-2023-40922 | 1 Kerawen | 1 Kerawen | 2024-11-21 | 9.8 Critical |
| kerawen before v2.5.1 was discovered to contain a SQL injection vulnerability via the ocs_id_cart parameter at KerawenDeliveryModuleFrontController::initContent(). | ||||
| CVE-2023-40921 | 1 Common-services | 1 Soliberte | 2024-11-21 | 9.8 Critical |
| SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters. | ||||
| CVE-2023-40920 | 1 Prixan | 1 Prixanconnect | 2024-11-21 | 9.8 Critical |
| Prixan prixanconnect up to v1.62 was discovered to contain a SQL injection vulnerability via the component CartsGuruCatalogModuleFrontController::importProducts(). | ||||
| CVE-2023-40852 | 1 User Registration \& Login And User Management System With Admin Panel Project | 1 User Registration \& Login And User Management System With Admin Panel | 2024-11-21 | 9.8 Critical |
| SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page. | ||||
| CVE-2023-40787 | 1 Bladex | 1 Springblade | 2024-11-21 | 9.8 Critical |
| In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection. | ||||
| CVE-2023-40771 | 1 Dataease | 1 Dataease | 2024-11-21 | 7.5 High |
| SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function. | ||||