Total
14188 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-25651 | 1 Zte | 4 Mf286r, Mf286r Firmware, Mf833u1 and 1 more | 2023-12-19 | N/A | 8.0 HIGH |
| There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak. | |||||
| CVE-2023-48084 | 1 Nagios | 1 Nagios Xi | 2023-12-19 | N/A | 9.8 CRITICAL |
| Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool. | |||||
| CVE-2023-40629 | 1 King-products | 1 Lms King Lite | 2023-12-19 | N/A | 9.8 CRITICAL |
| SQLi vulnerability in LMS Lite component for Joomla. | |||||
| CVE-2023-49708 | 1 Joomstar | 1 Starshop | 2023-12-19 | N/A | 9.8 CRITICAL |
| SQLi vulnerability in Starshop component for Joomla. | |||||
| CVE-2023-49707 | 1 Joomlart | 1 S5 Register | 2023-12-19 | N/A | 9.8 CRITICAL |
| SQLi vulnerability in S5 Register module for Joomla. | |||||
| CVE-2023-48925 | 1 Buy-addons | 1 Bavideotab | 2023-12-18 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run(). | |||||
| CVE-2023-46348 | 1 Sunnytoo | 1 Sturls | 2023-12-18 | N/A | 9.8 CRITICAL |
| SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and StUrls::getInstanceId methods. | |||||
| CVE-2023-50563 | 1 Sem-cms | 1 Semcms | 2023-12-18 | N/A | 9.8 CRITICAL |
| Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php. | |||||
| CVE-2023-50073 | 1 Leadscloud | 1 Empirecms | 2023-12-18 | N/A | 9.8 CRITICAL |
| EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php. | |||||
| CVE-2023-43813 | 1 Glpi-project | 1 Glpi | 2023-12-18 | N/A | 8.8 HIGH |
| GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, the saved search feature can be used to perform a SQL injection. Version 10.0.11 contains a patch for the issue. | |||||
| CVE-2023-46727 | 1 Glpi-project | 1 Glpi | 2023-12-18 | N/A | 9.8 CRITICAL |
| GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, GLPI inventory endpoint can be used to drive a SQL injection attack. Version 10.0.11 contains a patch for the issue. As a workaround, disable native inventory. | |||||
| CVE-2023-49363 | 1 Rockoa | 1 Rockoa | 2023-12-18 | N/A | 9.8 CRITICAL |
| Rockoa <2.3.3 is vulnerable to SQL Injection. The problem exists in the indexAction method in reimpAction.php. | |||||
| CVE-2022-24206 | 1 Tongda2000 | 1 Tongda Office Anywhere | 2023-12-16 | 7.5 HIGH | 9.8 CRITICAL |
| Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter. | |||||
| CVE-2022-23902 | 1 Tongda2000 | 1 Tongda Office Anywhere | 2023-12-16 | 7.5 HIGH | 9.8 CRITICAL |
| Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in export_data.php via the d_name parameter. | |||||
| CVE-2023-45800 | 1 Hanbiro | 1 Groupware | 2023-12-15 | N/A | 7.5 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hanbiro Hanbiro groupware allows Information Elicitation.This issue affects Hanbiro groupware: from V3.8.79 before V3.8.81.1. | |||||
| CVE-2023-41623 | 1 Emlog | 1 Emlog | 2023-12-14 | N/A | 7.2 HIGH |
| Emlog version pro2.1.14 was discovered to contain a SQL injection vulnerability via the uid parameter at /admin/media.php. | |||||
| CVE-2023-50429 | 1 Izybat | 1 Orange Casiers | 2023-12-14 | N/A | 9.1 CRITICAL |
| IzyBat Orange casiers before 20230803_1 allows getEnsemble.php ensemble SQL injection. | |||||
| CVE-2023-6035 | 1 Spider-themes | 1 Eazydocs | 2023-12-13 | N/A | 8.8 HIGH |
| The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an SQL statement via an AJAX action, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks. | |||||
| CVE-2023-5761 | 1 Burst-statistics | 1 Burst Statistics | 2023-12-12 | N/A | 7.5 HIGH |
| The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'url' parameter in versions 1.4.0 to 1.4.6.1 (free) and versions 1.4.0 to 1.5.0 (pro) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | |||||
| CVE-2023-5008 | 1 Imsurajghosh | 1 Student Information System | 2023-12-11 | N/A | 9.8 CRITICAL |
| Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'regno' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control. | |||||
