Vulnerabilities (CVE)

Filtered by CWE-89
Angry Yack Logo
Total 18012 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-34735 1 Property Cloud Platform Management Center Project 1 Property Cloud Platform Management Center 2024-11-21 N/A 9.8 CRITICAL
Property Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection.
CVE-2023-34659 1 Jeecg 1 Jeecg Boot 2024-11-21 N/A 9.8 CRITICAL
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
CVE-2023-34635 1 Wifi-soft 1 Unibox Administration 2024-11-21 N/A 9.8 CRITICAL
Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page.
CVE-2023-34626 1 Piwigo 1 Piwigo 2024-11-21 N/A 4.3 MEDIUM
Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function.
CVE-2023-34601 1 Jeesite 1 Jeesite 2024-11-21 N/A 9.8 CRITICAL
Jeesite before commit 10742d3 was discovered to contain a SQL injection vulnerability via the component ${businessTable} at /act/ActDao.xml.
CVE-2023-34581 1 Oretnom23 1 Service Provider Management System 2024-11-21 N/A 9.8 CRITICAL
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2
CVE-2023-34577 1 Planned Popup Project 1 Planned Popup 2024-11-21 N/A 9.8 CRITICAL
SQL injection vulnerability in Prestashop opartplannedpopup 1.4.11 and earlier allows remote attackers to run arbitrary SQL commands via OpartPlannedPopupModuleFrontController::prepareHook() method.
CVE-2023-34576 1 Opartfaq Project 1 Opartfaq 2024-11-21 N/A 9.8 CRITICAL
SQL injection vulnerability in updatepos.php in PrestaShop opartfaq through 1.0.3 allows remote attackers to run arbitrary SQL commands via unspedified vector.
CVE-2023-34575 1 Op\'art Save Cart Project 1 Op\'art Save Cart 2024-11-21 N/A 9.8 CRITICAL
SQL injection vulnerability in PrestaShop opartsavecart through 2.0.7 allows remote attackers to run arbitrary SQL commands via OpartSaveCartDefaultModuleFrontController::initContent() and OpartSaveCartDefaultModuleFrontController::displayAjaxSendCartByEmail() methods.
CVE-2023-34545 1 Cskaza 1 Cszcms 2024-11-21 N/A 9.8 CRITICAL
A SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers to run arbitrary SQL commands via p parameter or the search URL.
CVE-2023-34487 1 Online Hotel Management System Project 1 Online Hotel Management System 2024-11-21 N/A 9.8 CRITICAL
itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to SQL Injection. SQL injection points exist in the login password input box. This vulnerability can be exploited through time-based blind injection.
CVE-2023-34477 1 Braincert 1 Virtual Classroom 2024-11-21 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
CVE-2023-34476 1 Mooj 1 Proforms 2024-11-21 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
CVE-2023-34418 1 Lenovo 1 Xclarity Administrator 2024-11-21 N/A 8.1 HIGH
A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API.
CVE-2023-34383 1 Wedevs 1 Wp Project Manager 2024-11-21 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This issue affects WP Project Manager: from n/a through 2.6.0.
CVE-2023-34249 1 Pybb Project 1 Pybb 2024-11-21 N/A 9.8 CRITICAL
benjjvi/PyBB is an open source bulletin board. Prior to commit dcaeccd37198ecd3e41ea766d1099354b60d69c2, benjjvi/PyBB is vulnerable to SQL Injection. This vulnerability has been fixed as of commit dcaeccd37198ecd3e41ea766d1099354b60d69c2. As a workaround, a user may be able to update the software manually to avoid this problem by sanitizing user queries to `BulletinDatabaseModule.py`.
CVE-2023-34210 1 Easyuse 1 Mailhunter Ultimate 2024-11-21 N/A 7.7 HIGH
SQL Injection in create customer group function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to execute arbitrary SQL commands via the ctl00$ContentPlaceHolder1$txtCustSQL parameter.
CVE-2023-34179 1 Groundhogg 1 Groundhogg 2024-11-21 N/A 7.2 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Inc. Groundhogg allows SQL Injection.This issue affects Groundhogg: from n/a through 2.7.11.
CVE-2023-34168 1 Esiteq 1 Wp Report Post 2024-11-21 N/A 7.6 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Raven WP Report Post allows SQL Injection.This issue affects WP Report Post: from n/a through 2.1.2.
CVE-2023-33993 1 Sap 1 Business One 2024-11-21 N/A 7.1 HIGH
B1i module of SAP Business One - version 10.0, application allows an authenticated user with deep knowledge to send crafted queries over the network to read or modify the SQL data. On successful exploitation, the attacker can cause high impact on confidentiality, integrity and availability of the application.
CVE-2023-33967 1 Megaease 1 Easeprobe 2024-11-21 N/A 8.2 HIGH
EaseProbe is a tool that can do health/status checking. An SQL injection issue was discovered in EaseProbe before 2.1.0 when using MySQL/PostgreSQL data checking. This problem has been fixed in v2.1.0.
CVE-2023-33927 1 Themeisle 1 Multiple Page Generator 2024-11-21 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple Page Generator Plugin – MPG multiple-pages-generator-by-porthas allows SQL Injection.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.3.19.
CVE-2023-33924 1 Felixwelberg 1 Sis Handball 2024-11-21 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Felix Welberg SIS Handball allows SQL Injection.This issue affects SIS Handball: from n/a through 1.0.45.
CVE-2023-33852 1 Ibm 1 Security Guardium 2024-11-21 N/A 7.6 HIGH
IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 257614.
CVE-2023-33817 1 Digitaldruid 1 Hoteldruid 2024-11-21 N/A 8.8 HIGH
hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability.
CVE-2023-33666 1 Ai-dev 1 Aioptimizedcombinations 2024-11-21 N/A 9.8 CRITICAL
ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.
CVE-2023-33665 1 Ai-dev 1 Ai-table 2024-11-21 N/A 9.8 CRITICAL
ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.
CVE-2023-33664 1 Ai-dev 1 Declinaisons A La Volee 2024-11-21 N/A 8.8 HIGH
ai-dev aicombinationsonfly before v0.3.1 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.
CVE-2023-33663 1 Ai-dev 1 Aicustomfee 2024-11-21 N/A 9.8 CRITICAL
In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can perform SQL injection up to 0.2.0. Release 0.2.1 fixed this security issue.
CVE-2023-33592 1 Oretnom23 1 Lost And Found Information System 2024-11-21 N/A 9.8 CRITICAL
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.
CVE-2023-33584 1 Enrollment System Project 1 Enrollment System 2024-11-21 N/A 9.8 CRITICAL
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields during the login process, enabling an attacker to inject malicious SQL code.
CVE-2023-33481 1 Remoteclinic 1 Remote Clinic 2024-11-21 N/A 9.8 CRITICAL
RemoteClinic 2.0 is vulnerable to a time-based blind SQL injection attack in the 'start' GET parameter of patients/index.php.
CVE-2023-33479 1 Remoteclinic 1 Remote Clinic 2024-11-21 N/A 9.8 CRITICAL
RemoteClinic version 2.0 contains a SQL injection vulnerability in the /staff/edit.php file.
CVE-2023-33478 1 Remoteclinic 1 Remote Clinic 2024-11-21 N/A 9.8 CRITICAL
RemoteClinic 2.0 has a SQL injection vulnerability in the ID parameter of /medicines/stocks.php.
CVE-2023-33367 1 Assaabloy 1 Control Id Idsecure 2024-11-21 N/A 9.8 CRITICAL
A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in remote code execution.
CVE-2023-33366 1 Supremainc 1 Biostar 2 2024-11-21 N/A 8.8 HIGH
A SQL injection vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows authenticated users to inject arbitrary SQL directives into an SQL statement and execute arbitrary SQL commands.
CVE-2023-33331 1 Woo 1 Product Vendors 2024-11-21 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce Product Vendors allows SQL Injection.This issue affects Product Vendors: from n/a through 2.1.76.
CVE-2023-33330 1 Woocommerce 1 Automatewoo 2024-11-21 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a through 4.9.50.
CVE-2023-33209 1 Crawlspider 1 Seo Change Monitor 2024-11-21 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CrawlSpider SEO Change Monitor – Track Website Changes.This issue affects SEO Change Monitor – Track Website Changes: from n/a through 1.2.
CVE-2023-33180 1 Xibosignage 1 Xibo 2024-11-21 N/A 6.5 MEDIUM
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.2 in the `/display/map` API route inside the CMS. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values in to the `bounds` parameter. Users should upgrade to version 3.3.5, which fixes this issue. There are no known workarounds aside from upgrading.