Total
18012 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-49750 | 1 Spoonthemes | 1 Couponis | 2024-11-21 | N/A | 9.3 CRITICAL |
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoonthemes Couponis - Affiliate & Submitting Coupons WordPress Theme.This issue affects Couponis - Affiliate & Submitting Coupons WordPress Theme: from n/a before 2.2.
|
|||||
| CVE-2023-49708 | 1 Joomstar | 1 Starshop | 2024-11-21 | N/A | 9.8 CRITICAL |
|
SQLi vulnerability in Starshop component for Joomla.
|
|||||
| CVE-2023-49707 | 1 Joomlart | 1 S5 Register | 2024-11-21 | N/A | 9.8 CRITICAL |
|
SQLi vulnerability in S5 Register module for Joomla.
|
|||||
| CVE-2023-49689 | 1 Kashipara | 1 Job Portal | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'JobId' parameter of the Employer/DeleteJob.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-49688 | 1 Kashipara | 1 Job Portal | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtUser' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-49681 | 1 Kashipara | 1 Job Portal | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cmbQual' parameter of the Employer/InsertWalkin.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-49677 | 1 Kashipara | 1 Job Portal | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cmbQual' parameter of the Employer/InsertJob.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-49665 | 1 Kashipara | 1 Billing Software | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'quantity[]' parameter of the submit_delivery_list.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-49658 | 1 Kashipara | 1 Billing Software | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'bank_details' parameter of the party_submit.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-49639 | 1 Kashipara | 1 Billing Software | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'customer_details' parameter of the buyer_invoice_submit.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-49633 | 1 Kashipara | 1 Billing Software | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'buyer_address' parameter of the buyer_detail_submit.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-49625 | 1 Kashipara | 1 Billing Software | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partylist_edit_submit.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-49624 | 1 Kashipara | 1 Billing Software | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter of the material_bill.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-49622 | 1 Kashipara | 1 Billing Software | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'itemnameid' parameter of the material_bill.php?action=itemRelation resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-49581 | 1 Sap | 1 Netweaver Application Server Abap | 2024-11-21 | N/A | 4.1 MEDIUM |
|
SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to write data to a database table. By doing so the attacker could increase response times of the AS ABAP, leading to mild impact on availability.
|
|||||
| CVE-2023-49429 | 1 Tenda | 2 Ax9, Ax9 Firmware | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.
|
|||||
| CVE-2023-49371 | 1 Ruoyi | 1 Ruoyi | 2024-11-21 | N/A | 9.8 CRITICAL |
|
RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.
|
|||||
| CVE-2023-49363 | 1 Rockoa | 1 Rockoa | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Rockoa <2.3.3 is vulnerable to SQL Injection. The problem exists in the indexAction method in reimpAction.php.
|
|||||
| CVE-2023-49166 | 1 Magiclogix | 1 Msync | 2024-11-21 | N/A | 7.6 HIGH |
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Magic Logix MSync.This issue affects MSync: from n/a through 1.0.0.
|
|||||
| CVE-2023-49161 | 1 Guelbetech | 1 Bravo Translate | 2024-11-21 | N/A | 7.6 HIGH |
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Guelben Bravo Translate.This issue affects Bravo Translate: from n/a through 1.2.
|
|||||
| CVE-2023-49085 | 1 Cacti | 1 Cacti | 2024-11-21 | N/A | 8.8 HIGH |
|
Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script. An authorized user may be able to execute arbitrary SQL code. The vulnerable component is the `pollers.php`. Impact of the vulnerability - arbitrary SQL code execution. As of time of publication, a patch does not appear to exist.
|
|||||
| CVE-2023-49030 | 1 32ns | 1 Klive | 2024-11-21 | N/A | 7.5 HIGH |
|
SQL Injection vulnerability in32ns KLive v.2019-1-19 and before allows a remote attacker to obtain sensitive information via a crafted script to the web/user.php component.
|
|||||
| CVE-2023-48987 | 1 Cusg | 1 Content Management System | 2024-11-21 | N/A | 7.5 HIGH |
|
Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the pages.php component.
|
|||||
| CVE-2023-48925 | 1 Buy-addons | 1 Bavideotab | 2024-11-21 | N/A | 9.8 CRITICAL |
|
SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run().
|
|||||
| CVE-2023-48893 | 1 Slims | 1 Senayan Library Management System Bulian | 2024-11-21 | N/A | 8.8 HIGH |
|
SLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staff_act.php SQL Injection via startDate or untilDate.
|
|||||
| CVE-2023-48823 | 1 Mayurik | 1 Courier Management System | 2024-11-21 | N/A | 9.8 CRITICAL |
|
A Blind SQL injection issue in ajax.php in GaatiTrack Courier Management System 1.0 allows an unauthenticated attacker to inject a payload via the email parameter during login.
|
|||||
| CVE-2023-48813 | 1 Slims | 1 Senayan Library Management System Bulian | 2024-11-21 | N/A | 8.8 HIGH |
|
Senayan Library Management Systems (Slims) 9 Bulian v9.6.1 is vulnerable to SQL Injection via admin/modules/reporting/customs/fines_report.php.
|
|||||
| CVE-2023-48764 | 1 Guardgiant | 1 Guardgiant | 2024-11-21 | N/A | 7.6 HIGH |
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GuardGiant Brute Force Protection WordPress Brute Force Protection – Stop Brute Force Attacks.This issue affects WordPress Brute Force Protection – Stop Brute Force Attacks: from n/a through 2.2.5.
|
|||||
| CVE-2023-48742 | 1 Wpexperts | 1 License Manager For Woocommerce | 2024-11-21 | N/A | 7.6 HIGH |
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LicenseManager License Manager for WooCommerce license-manager-for-woocommerce allows SQL Injection.This issue affects License Manager for WooCommerce: from n/a through 2.2.10.
|
|||||
| CVE-2023-48738 | 1 Portotheme | 1 Functionality | 2024-11-21 | N/A | 9.3 CRITICAL |
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Porto Theme Porto Theme - Functionality.This issue affects Porto Theme - Functionality: from n/a before 2.12.1.
|
|||||
| CVE-2023-48722 | 1 Phpgurukul | 1 Student Result Management System | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-48720 | 1 Phpgurukul | 1 Student Result Management System | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-48718 | 1 Phpgurukul | 1 Student Result Management System | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-48716 | 1 Projectworlds | 1 Student Result Management System | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_id' parameter of the add_classes.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-48689 | 1 Projectworlds | 1 Railway Reservation System | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'byname' parameter of the train.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-48687 | 1 Projectworlds | 1 Railway Reservation System | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'from' parameter of the reservation.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-48685 | 1 Projectworlds | 1 Railway Reservation System | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'psd' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-48434 | 1 Projectworlds | 1 Online Voting System Project | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the reg_action.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-48433 | 1 Projectworlds | 1 Online Voting System Project | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the login_action.php resource does not validate the characters received and they are sent unfiltered to the database.
|
|||||
| CVE-2023-48395 | 1 Kaifa | 1 Webitr Attendance System | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Kaifa Technology WebITR is an online attendance system, it has insufficient validation for user input within a special function. A remote attacker with regular user privilege can exploit this vulnerability to inject arbitrary SQL commands to read database.
|
|||||