Total
18012 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-10657 | 1 Tongda2000 | 1 Office Anywhere | 2024-11-04 | 6.5 MEDIUM | 9.8 CRITICAL |
|
A vulnerability classified as critical has been found in Tongda OA up to 11.10. Affected is an unknown function of the file /pda/approve_center/prcs_info.php. The manipulation of the argument RUN_ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10658 | 1 Tongda2000 | 1 Office Anywhere | 2024-11-04 | 6.5 MEDIUM | 9.8 CRITICAL |
|
A vulnerability classified as critical was found in Tongda OA up to 11.10. Affected by this vulnerability is an unknown functionality of the file /pda/approve_center/check_seal.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10602 | 1 Tongda2000 | 1 Office Anywhere | 2024-11-04 | 6.5 MEDIUM | 9.8 CRITICAL |
|
A vulnerability was found in Tongda OA 2017 up to 11.9 and classified as critical. Affected by this issue is some unknown functionality of the file /general/approve_center/list/input_form/data_picker_link.php. The manipulation of the argument dataSrc leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10601 | 1 Tongda2000 | 1 Office Anywhere | 2024-11-04 | 6.5 MEDIUM | 9.8 CRITICAL |
|
A vulnerability has been found in Tongda OA 2017 up to 11.10 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /general/address/private/address/query/delete.php. The manipulation of the argument where_repeat leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10600 | 1 Tongda2000 | 1 Office Anywhere | 2024-11-04 | 7.5 HIGH | 9.8 CRITICAL |
|
A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.6. Affected is an unknown function of the file pda/appcenter/submenu.php. The manipulation of the argument appid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-48733 | 2024-11-04 | N/A | 8.8 HIGH | ||
|
SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to execute arbitrary SQL commands via the POST body request. NOTE: this is disputed by the vendor because SQL statement execution is allowed for authorized users.
|
|||||
| CVE-2024-10615 | 1 Tongda2000 | 1 Office Anywhere | 2024-11-04 | 6.5 MEDIUM | 9.8 CRITICAL |
|
A vulnerability was found in Tongda OA 2017 up to 11.10. It has been rated as critical. Affected by this issue is some unknown functionality of the file /general/approve_center/query/list/input_form/delete_data_attach.php. The manipulation of the argument RUN_ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10616 | 1 Tongda2000 | 1 Office Anywhere | 2024-11-04 | 6.5 MEDIUM | 9.8 CRITICAL |
|
A vulnerability classified as critical has been found in Tongda OA up to 11.9. This affects an unknown part of the file /pda/workflow/webSignSubmit.php. The manipulation of the argument saleId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10617 | 1 Tongda2000 | 1 Office Anywhere | 2024-11-04 | 6.5 MEDIUM | 9.8 CRITICAL |
|
A vulnerability classified as critical was found in Tongda OA up to 11.10. This vulnerability affects unknown code of the file /pda/workflow/check_seal.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10732 | 1 Tongda2000 | 1 Office Anywhere | 2024-11-04 | 6.5 MEDIUM | 9.8 CRITICAL |
|
A vulnerability has been found in Tongda OA 2017 up to 11.10 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /module/word_model/view/index.php. The manipulation of the argument query_str leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10731 | 1 Tongda2000 | 1 Office Anywhere | 2024-11-04 | 6.5 MEDIUM | 9.8 CRITICAL |
|
A vulnerability, which was classified as critical, was found in Tongda OA up to 11.10. Affected is an unknown function of the file /pda/appcenter/check_seal.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10730 | 1 Tongda2000 | 1 Office Anywhere | 2024-11-04 | 6.5 MEDIUM | 9.8 CRITICAL |
|
A vulnerability, which was classified as critical, has been found in Tongda OA up to 11.6. This issue affects some unknown processing of the file /pda/appcenter/web_show.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10619 | 1 Tongda2000 | 1 Office Anywhere | 2024-11-04 | 6.5 MEDIUM | 9.8 CRITICAL |
|
A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /pda/reportshop/next_detail.php. The manipulation of the argument repid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10618 | 1 Tongda2000 | 1 Office Anywhere | 2024-11-04 | 6.5 MEDIUM | 9.8 CRITICAL |
|
A vulnerability, which was classified as critical, has been found in Tongda OA 2017 up to 11.10. This issue affects some unknown processing of the file /pda/reportshop/record_detail.php. The manipulation of the argument repid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10540 | 1 Reputeinfosystems | 1 Bookingpress | 2024-11-04 | N/A | 6.5 MEDIUM |
|
The Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to SQL Injection via the 'service' parameter of the bookingpress_form shortcode in all versions up to, and including, 1.1.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already ex ...
Show More |
|||||
| CVE-2024-10595 | 1 Esafenet | 1 Cdg | 2024-11-01 | 6.5 MEDIUM | 9.8 CRITICAL |
|
A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delFile/delDifferCourseList of the file /com/esafenet/servlet/ajax/PublicDocInfoAjax.java. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2024-10509 | 1 Codezips | 1 Online Institute Management System | 2024-11-01 | 7.5 HIGH | 9.8 CRITICAL |
|
A vulnerability, which was classified as critical, has been found in Codezips Online Institute Management System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10556 | 1 Codezips | 1 Pet Shop Management System | 2024-11-01 | 7.5 HIGH | 9.8 CRITICAL |
|
A vulnerability, which was classified as critical, was found in Codezips Pet Shop Management System 1.0. Affected is an unknown function of the file birdsadd.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10561 | 1 Codezips | 1 Pet Shop Management System | 2024-11-01 | 7.5 HIGH | 9.8 CRITICAL |
|
A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file birdsupdate.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-46903 | 1 Trendmicro | 1 Deep Discovery Inspector | 2024-11-01 | N/A | 6.5 MEDIUM |
|
A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
|
|||||
| CVE-2024-8309 | 1 Langchain | 1 Langchain | 2024-11-01 | N/A | 9.8 CRITICAL |
|
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disrupt services, access data across dif ...
Show More |
|||||
| CVE-2024-20472 | 1 Cisco | 1 Secure Firewall Management Center | 2024-11-01 | N/A | 6.5 MEDIUM |
|
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.
This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exp ...
Show More |
|||||
| CVE-2024-20471 | 1 Cisco | 1 Secure Firewall Management Center | 2024-11-01 | N/A | 6.5 MEDIUM |
|
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.
This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exp ...
Show More |
|||||
| CVE-2024-20473 | 1 Cisco | 1 Secure Firewall Management Center | 2024-11-01 | N/A | 6.5 MEDIUM |
|
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.
This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exp ...
Show More |
|||||
| CVE-2024-10446 | 1 Projectworlds | 1 Online Time Table Generator | 2024-11-01 | 6.5 MEDIUM | 7.2 HIGH |
|
A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. Affected is an unknown function of the file /timetable/admin/admindashboard.php?info=add_course. The manipulation of the argument c leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10380 | 1 Mayurik | 1 Petrol Pump Management | 2024-11-01 | 6.5 MEDIUM | 7.5 HIGH |
|
A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/ajax_product.php. The manipulation of the argument drop_services leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10331 | 1 Phpgurukul | 1 Vehicle Record System | 2024-11-01 | 6.5 MEDIUM | 8.8 HIGH |
|
A vulnerability, which was classified as critical, has been found in PHPGurukul Vehicle Record System 1.0. This issue affects some unknown processing of the file /admin/search-vehicle.php. The manipulation of the argument searchinputdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-7042 | 1 Langchain | 1 Langchain | 2024-10-31 | N/A | 9.8 CRITICAL |
|
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability permits unauthorized data manipulation, data exfiltration, denial of service (DoS) by deleting all data, breaches in multi-tenant security environments, and data integrity issues. Attackers can create, update, or delete nodes and relationships without proper authorization, extract sensitive data, disr ...
Show More |
|||||
| CVE-2024-48230 | 1 Funadmin | 1 Funadmin | 2024-10-31 | N/A | 7.2 HIGH |
|
funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.
|
|||||
| CVE-2024-48229 | 1 Funadmin | 1 Funadmin | 2024-10-31 | N/A | 7.2 HIGH |
|
funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.
|
|||||
| CVE-2024-48223 | 1 Funadmin | 1 Funadmin | 2024-10-31 | N/A | 7.2 HIGH |
|
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.
|
|||||
| CVE-2024-48222 | 1 Funadmin | 1 Funadmin | 2024-10-31 | N/A | 7.2 HIGH |
|
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.
|
|||||
| CVE-2024-48218 | 1 Funadmin | 1 Funadmin | 2024-10-31 | N/A | 7.2 HIGH |
|
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.
|
|||||
| CVE-2024-48226 | 1 Funadmin | 1 Funadmin | 2024-10-31 | N/A | 7.2 HIGH |
|
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.
|
|||||
| CVE-2024-50479 | 1 Mansurahamed | 1 Woocommerce Quote Calculator | 2024-10-31 | N/A | 9.8 CRITICAL |
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocommerce Quote Calculator: from n/a through 1.1.
|
|||||
| CVE-2024-10449 | 1 Codezips | 1 Hospital Appointment System | 2024-10-31 | 7.5 HIGH | 9.8 CRITICAL |
|
A vulnerability, which was classified as critical, was found in Codezips Hospital Appointment System 1.0. This affects an unknown part of the file /loginAction.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-50465 | 1 Squirrly | 1 Premium Seo Pack | 2024-10-31 | N/A | 6.5 MEDIUM |
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP SEO – Calin Vingan Premium SEO Pack allows SQL Injection.This issue affects Premium SEO Pack: from n/a through 1.6.001.
|
|||||
| CVE-2024-10447 | 1 Projectworlds | 1 Online Time Table Generator | 2024-10-31 | 6.5 MEDIUM | 8.8 HIGH |
|
A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vulnerability is an unknown functionality of the file /timetable/staff/staffdashboard.php?info=updateprofile. The manipulation of the argument n leads to sql injection. The attack can be launched remotely.
|
|||||
| CVE-2024-48427 | 1 Oretnom23 | 1 Packers And Movers Management System | 2024-10-31 | N/A | 8.8 HIGH |
|
A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id
|
|||||
| CVE-2024-47483 | 1 Dell | 1 Data Lakehouse | 2024-10-31 | N/A | 5.5 MEDIUM |
|
Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
|
|||||