Total
18012 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-25149 | 1 Veronalabs | 1 Wp Statistics | 2024-11-21 | 5.0 MEDIUM | 9.8 CRITICAL |
|
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.
|
|||||
| CVE-2022-25148 | 1 Veronalabs | 1 Wp Statistics | 2024-11-21 | 5.0 MEDIUM | 9.8 CRITICAL |
|
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.
|
|||||
| CVE-2022-25125 | 1 Mingsoft | 1 Mcms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
|
|||||
| CVE-2022-25096 | 1 Home Owners Collection Management System Project | 1 Home Owners Collection Management System | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php.
|
|||||
| CVE-2022-25004 | 1 Hospital\'s Patient Records Management System Project | 1 Hospital\'s Patient Records Management System | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php.
|
|||||
| CVE-2022-25003 | 1 Hospital\'s Patient Records Management System Project | 1 Hospital\'s Patient Records Management System | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php.
|
|||||
| CVE-2022-24956 | 1 Shopware | 1 B2b Suite | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2border and b2borderlist allows SQL injection. Possible techniques are boolean-based blind, time-based blind, and potentially stacked queries. The vulnerability allows a remote authenticated attacker to dump the underlying database.
|
|||||
| CVE-2022-24848 | 1 Dhis2 | 1 Dhis 2 | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
DHIS2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability affects the `/api/programs/orgUnits?programs=` API endpoint in DHIS2 versions prior to 2.36.10.1 and 2.37.6.1. The system is vulnerable to attack only from users that are logged in to DHIS2, and there is no known way of exploiting the vulnerability without first being logged in as a DHIS2 user. The vulnerability is not exposed to a non-malicious user and re ...
Show More |
|||||
| CVE-2022-24844 | 2 Gin-vue-admin Project, Postgresql | 2 Gin-vue-admin, Postgresql | 2024-11-21 | 6.5 MEDIUM | 8.1 HIGH |
|
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. The problem occurs in the following code in server/service/system/sys_auto_code_pgsql.go, which means that PostgreSQL must be used as the database for this vulnerability to occur. Users must: Require JWT login) and be using PostgreSQL to be affected. This issue has been resolved in version 2.5.1. There are no known workarounds.
|
|||||
| CVE-2022-24831 | 1 Openclinica | 1 Openclinica | 2024-11-21 | 7.5 HIGH | 8.3 HIGH |
|
OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). Versions prior to 3.16.1 are vulnerable to SQL injection due to the use of string concatenation to create SQL queries instead of prepared statements. No known workarounds exist. This issue has been patched in 3.16.1, 3.15.9, 3.14.1, and 3.13.1 and users are advised to upgrade.
|
|||||
| CVE-2022-24827 | 1 Elide | 1 Elide | 2024-11-21 | 6.8 MEDIUM | 8.1 HIGH |
|
Elide is a Java library that lets you stand up a GraphQL/JSON-API web service with minimal effort. When leveraging the following together: Elide Aggregation Data Store for Analytic Queries, Parameterized Columns (A column that requires a client provided parameter), and a parameterized column of type TEXT. There is the potential for a hacker to provide a carefully crafted query that would bypass server side authorization filters through SQL injection. A recent patch to Elide 6.1.2 allowed the '-' ...
Show More |
|||||
| CVE-2022-24815 | 1 Jhipster | 1 Generator-jhipster | 2024-11-21 | 6.8 MEDIUM | 8.1 HIGH |
|
JHipster is a development platform to quickly generate, develop, & deploy modern web applications & microservice architectures. SQL Injection vulnerability in entities for applications generated with the option "reactive with Spring WebFlux" enabled and an SQL database using r2dbc. Applications created without "reactive with Spring WebFlux" and applications with NoSQL databases are not affected. Users who have generated a microservice Gateway using the affected version may be impacted as Gateway ...
Show More |
|||||
| CVE-2022-24752 | 1 Sylius | 1 Syliusgridbundle | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly to the database. The maintainers do not know if this could lead to direct SQL injections but took steps to remediate the vulnerability. The issue is fixed in versions 1.10.1 and 1.11-rc2. As a workaround, overwrite the`Sylius\Component\Grid\Sorting\Sorter.php` class and register it in the container. More information abo ...
Show More |
|||||
| CVE-2022-24707 | 1 Anuko | 1 Time Tracker | 2024-11-21 | 6.5 MEDIUM | 7.4 HIGH |
|
Anuko Time Tracker is an open source, web-based time tracking application written in PHP. UNION SQL injection and time-based blind injection vulnerabilities existed in Time Tracker Puncher plugin in versions of anuko timetracker prior to 1.20.0.5642. This was happening because the Puncher plugin was reusing code from other places and was relying on an unsanitized date parameter in POST requests. Because the parameter was not checked, it was possible to craft POST requests with malicious SQL for ...
Show More |
|||||
| CVE-2022-24691 | 1 Dsk | 1 Dsknet | 2024-11-21 | N/A | 7.1 HIGH |
|
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A SQL Injection vulnerability allows authenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean based.
|
|||||
| CVE-2022-24690 | 1 Dsk | 1 Dsknet | 2024-11-21 | N/A | 8.2 HIGH |
|
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A PresAbs.php SQL Injection vulnerability allows unauthenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean based. (An unauthenticated attacker can discover the endpoint by abusing a Broken Access Control issue with further SQL injection attacks to gather all user's badge numbers and PIN codes.)
|
|||||
| CVE-2022-24646 | 1 Phpgurukul | 1 Hospital Management System | 2024-11-21 | 7.8 HIGH | 7.5 HIGH |
|
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.
|
|||||
| CVE-2022-24607 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php.
|
|||||
| CVE-2022-24606 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php.
|
|||||
| CVE-2022-24605 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.
|
|||||
| CVE-2022-24604 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.
|
|||||
| CVE-2022-24603 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php.
|
|||||
| CVE-2022-24602 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.
|
|||||
| CVE-2022-24601 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
Luocms v2.0 is affected by SQL Injection in /admin/manager/admin_mod.php. An attacker can obtain sensitive information through SQL injection statements.
|
|||||
| CVE-2022-24600 | 1 Luocms Project | 1 Luocms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements.
|
|||||
| CVE-2022-24571 | 1 Car Driving School Management System Project | 1 Car Driving School Management System | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access.
|
|||||
| CVE-2022-24407 | 5 Cyrusimap, Debian, Fedoraproject and 2 more | 8 Cyrus-sasl, Debian Linux, Fedora and 5 more | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
|
|||||
| CVE-2022-24391 | 1 Fidelissecurity | 2 Deception, Network | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Vulnerability in Fidelis Network and Deception CommandPost enables SQL injection through the web interface by an attacker with user level access. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.
|
|||||
| CVE-2022-24281 | 1 Siemens | 1 Sinec Network Management System | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
A vulnerability has been identified in SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). A privileged authenticated attacker could execute arbitrary commands in the local database by sending specially crafted requests to the webserver of the affected application.
|
|||||
| CVE-2022-24266 | 1 Cuppacms | 1 Cuppacms | 2024-11-21 | 7.8 HIGH | 7.5 HIGH |
|
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.
|
|||||
| CVE-2022-24265 | 1 Cuppacms | 1 Cuppacms | 2024-11-21 | 7.8 HIGH | 7.5 HIGH |
|
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.
|
|||||
| CVE-2022-24264 | 1 Cuppacms | 1 Cuppacms | 2024-11-21 | 7.8 HIGH | 7.5 HIGH |
|
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.
|
|||||
| CVE-2022-24263 | 1 Phpgurukul | 1 Hospital Management System | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
|
|||||
| CVE-2022-24260 | 1 Voipmonitor | 1 Voipmonitor | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
|
A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.
|
|||||
| CVE-2022-24240 | 1 Aceware | 1 Aceweb Online Portal | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.
|
|||||
| CVE-2022-24231 | 1 Simple Student Information System Project | 1 Simple Student Information System | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
|
Simple Student Information System v1.0 was discovered to contain a SQL injection vulnerability via add/Student.
|
|||||
| CVE-2022-24226 | 1 Phpgurukul | 1 Hospital Management System | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php.
|
|||||
| CVE-2022-24223 | 1 Thedigitalcraft | 1 Atomcms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
|
|||||
| CVE-2022-24222 | 1 Elitecms | 1 Elite Cms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.
|
|||||
| CVE-2022-24221 | 1 Elitecms | 1 Elite Cms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.
|
|||||