CVE z tagiem sql-injection — 200 wyników. ← Wszystkie tagi

CVE-2016-2386 🔴 Łataj teraz KEV

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

9.8 CVSS
44.5% EPSS
CVE-2026-21643 🔴 Łataj teraz KEV
network

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via sp…

9.8 CVSS
33.9% EPSS
CVE-2026-9082 🔴 Łataj teraz KEV

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 befor…

6.5 CVSS
12.6% EPSS
sql-injection 2026-05-20
CVE-2014-2323 🔴 Łataj teraz
os

SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.

9.8 CVSS
90.4% EPSS
CVE-2023-5204 🔴 Łataj teraz

The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparat…

9.8 CVSS
87.0% EPSS
CVE-2022-1768 🔴 Łataj teraz

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. …

9.8 CVSS
86.1% EPSS
CVE-2022-1453 🔴 Łataj teraz

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it…

9.8 CVSS
62.1% EPSS
CVE-2013-4467 ⚪ Do wiadomości

Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to execute arbitrary SQL commands via the ca…

6.5 CVSS
78.3% EPSS
CVE-2024-49681 🔴 Łataj teraz

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Se…

9.3 CVSS
51.3% EPSS
sql-injection 2024-10-24
CVE-2014-0763 🟡 Monitoruj

An attacker using SQL injection may use arguments to construct queries without proper sanitization. The DBVisitor.dll is exposed through SOAP interfaces, and the exposed functions are vulnerable to SOAP injection. Thi…

7.5 CVSS
57.9% EPSS
CVE-2023-3197 🔴 Łataj teraz

The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameters and lac…

9.8 CVSS
36.8% EPSS
CVE-2024-50491 🔴 Łataj teraz

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME rsvp-me allows SQL Injection.This issue affects RSVP ME: from n/a through <= 1.9.9.

9.3 CVSS
37.7% EPSS
CVE-2022-44588 🔴 Łataj teraz

Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.

9.9 CVSS
34.0% EPSS
CVE-2022-45805 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paytm Paytm Payment Gateway paytm-payments allows SQL Injection.This issue affects Paytm Payment Gateway: from n/a thr…

8.2 CVSS
39.4% EPSS
paytmsql-injection 2023-11-03
CVE-2023-28787 🔴 Łataj teraz

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4.

9.3 CVSS
32.0% EPSS
sql-injection 2024-03-26
CVE-2014-2238 ⚪ Do wiadomości

SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 allows remote authenticated administrators to execute arbitrary SQL commands via the filter_config_id…

6.5 CVSS
45.4% EPSS
CVE-2024-2387 ⚪ Do wiadomości

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, an…

6.1 CVSS
36.6% EPSS
sql-injection 2024-03-20
CVE-2023-32590 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category.This issue affects Subscribe to Category: from n/a thro…

9.3 CVSS
19.3% EPSS
CVE-2023-50839 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support…

9.3 CVSS
16.3% EPSS
CVE-2023-24000 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GamiPress gamipress allows SQL Injection.This issue affects GamiPress: from n/a through 2.5.7.

8.2 CVSS
21.2% EPSS
CVE-2017-5611 🟠 Łataj w tym tygodniu
appsos

SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that…

9.8 CVSS
12.4% EPSS
oraclesql-injection 2017-01-30
CVE-2023-3047 🔴 Łataj teraz

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allows SQL Injection.This issue affects Lockcell: before 15.

9.8 CVSS
9.0% EPSS
CVE-2006-5344 🟠 Łataj w tym tygodniu
appsos

Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdo_3gl, aka Vu…

9.0 CVSS
10.5% EPSS
CVE-2026-3018 🟡 Monitoruj

The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to, and including, 4.13 due to insufficient escaping on the user supplied parameter …

7.5 CVSS
17.6% EPSS
sql-injection 2026-06-10
CVE-2023-45657 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSIMYTH Nexter allows SQL Injection.This issue affects Nexter: from n/a through 2.0.3.

8.5 CVSS
12.2% EPSS
CVE-2026-3396 🟡 Monitoruj

WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter in all versions up to, and including, 4.2.3 due to insufficient escaping on the user supplied param…

7.5 CVSS
17.0% EPSS
sql-injection 2026-04-08
CVE-2023-5412 🟠 Łataj w tym tygodniu

The Image horizontal reel scroll slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.2 due to insufficient escaping on the user supplied parameter…

8.8 CVSS
9.8% EPSS
CVE-2015-8974 🟠 Łataj w tym tygodniu

SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execu…

10.0 CVSS
3.7% EPSS
mybbsql-injection 2017-01-31
CVE-2012-10047 ⚪ Do wiadomości

Cyclope Employee Surveillance Solution versions 6.x are vulnerable to a SQL injection flaw in its login mechanism. The username parameter in the auth-login POST request is not properly sanitized, allowing attackers to in…

0.0 CVSS
53.2% EPSS
rcesql-injection 2025-08-08
CVE-2016-9402 🟠 Łataj w tym tygodniu

SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

9.8 CVSS
3.7% EPSS
mybbsql-injection 2017-01-31
CVE-2016-9416 🟠 Łataj w tym tygodniu

SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

9.8 CVSS
3.7% EPSS
mybbsql-injection 2017-01-31
CVE-2022-1505 🟠 Łataj w tym tygodniu

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This…

9.8 CVSS
3.4% EPSS
CVE-2017-5574 🟠 Łataj w tym tygodniu

SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows unauthenticated users to execute arbitrary SQL commands via the activation parameter.

9.8 CVSS
3.4% EPSS
CVE-2017-14851 🟠 Łataj w tym tygodniu

A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authentication validation process contains an insecure SELECT query. The attack a…

9.8 CVSS
3.1% EPSS
CVE-2026-42647 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects JoomSport: from n/a through 5.7.7.

9.3 CVSS
5.2% EPSS
sql-injection 2026-06-11
CVE-2006-5675 🟠 Łataj w tym tygodniu

Multiple unspecified vulnerabilities in Pentaho Business Intelligence (BI) Suite before 1.2 RC3 (1.2.0.470-RC3) have unknown impact and attack vectors, related to "MySQL Scripts need changes for security," possibly SQL i…

10.0 CVSS
1.6% EPSS
CVE-2022-34132 🟠 Łataj w tym tygodniu

Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php.

9.8 CVSS
1.9% EPSS
joranisql-injection 2022-06-28
CVE-2024-27304 🟠 Łataj w tym tygodniu

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one …

9.8 CVSS
1.9% EPSS
jackcsql-injection 2024-03-06
CVE-2022-32224 🔴 Łataj teraz

A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (vi…

9.8 CVSS
1.8% EPSS
CVE-2017-5569 🟠 Łataj w tym tygodniu

An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and wh…

9.8 CVSS
1.4% EPSS
CVE-2023-25960 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – Global Dropshipping zendrop-dropshipping-and-fulfillment allows SQL Injection.This issue affects Zen…

10.0 CVSS
0.3% EPSS
CVE-2025-4285 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Information Technologies Agentis allows SQL Injection. This issue affects Agentis: before 4.32.

10.0 CVSS
0.2% EPSS
sql-injection 2025-07-22
CVE-2024-1711 🟠 Łataj w tym tygodniu

The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.9.4 due to insufficient escaping on the user supplied parameter and lack of suffi…

9.8 CVSS
1.2% EPSS
sql-injection 2024-03-20
CVE-2024-13152 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection. This issue affects Mobuy Online Machinery …

10.0 CVSS
0.1% EPSS
sql-injection 2025-02-14
CVE-2017-5517 🔴 Łataj teraz

SQL injection vulnerability in author.control.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the type parameter.

9.8 CVSS
1.1% EPSS
CVE-2017-5519 🔴 Łataj teraz

SQL injection vulnerability in Posts.class.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the id parameter.

9.8 CVSS
1.1% EPSS
CVE-2016-5742 🟠 Łataj w tym tygodniu

SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open Source 5.2.13 and earlier allows remote attackers to execute arbitrary S…

9.8 CVSS
1.0% EPSS
CVE-2021-39302 🟠 Łataj w tym tygodniu

MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.

9.8 CVSS
0.9% EPSS
CVE-2021-4340 🔴 Łataj teraz

The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of suff…

9.8 CVSS
0.8% EPSS
CVE-2026-52785 🟠 Łataj w tym tygodniu

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to request historic work…

9.9 CVSS
0.2% EPSS
sql-injection 2026-06-26
CVE-2017-5575 🟠 Łataj w tym tygodniu

SQL injection vulnerability in inc/lib/Options.class.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the modules parameter.

9.8 CVSS
0.7% EPSS
CVE-2023-36529 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme allows SQL Injection.This issue affects Houzez - Real Estate WordPress…

9.9 CVSS
0.2% EPSS
CVE-2006-5603 🔴 Łataj teraz

SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details ar…

9.8 CVSS
0.7% EPSS
CVE-2026-46624 🔴 Łataj teraz

Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack. If Postgres user is a …

9.9 CVSS
0.2% EPSS
CVE-2026-34612 🔴 Łataj teraz

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execution (RCE) in the fo…

9.9 CVSS
0.2% EPSS
CVE-2017-5879 🟠 Łataj w tym tygodniu

An issue was discovered in Exponent CMS 2.4.1. This is a blind SQL injection that can be exploited by un-authenticated users via an HTTP GET request and which can be used to dump database data out to a malicious server, …

9.8 CVSS
0.6% EPSS
CVE-2023-1863 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Injection.This issue affects Water Metering So…

9.8 CVSS
0.6% EPSS
eskomsql-injection 2023-04-14
CVE-2026-54419 🟠 Łataj w tym tygodniu

claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) contains multiple unauthenticated SQL injection vulnerabilities. The applica…

9.8 CVSS
0.6% EPSS
sql-injection 2026-06-18
CVE-2024-8950 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arne Informatics Piramit Automation allows Blind SQL Injection. This issue affects Piramit Automation: before 27.09.2…

9.9 CVSS
0.1% EPSS
sql-injection 2024-12-25
CVE-2026-23696 🟠 Łataj w tym tygodniu

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. A…

9.9 CVSS
0.1% EPSS
sql-injection 2026-04-07
CVE-2021-27130 🔴 Łataj teraz

Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a reverse shell upload.

9.8 CVSS
0.5% EPSS
CVE-2024-29667 🟠 Łataj w tym tygodniu

SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate privileges and obtain sensitive information via the ids parameter.

9.8 CVSS
0.5% EPSS
sql-injection 2024-03-29
CVE-2026-40906 🔴 Łataj teraz

Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL injection, allowing any authenticated user to read, write, and des…

9.9 CVSS
0.0% EPSS
CVE-2024-2804 🟠 Łataj w tym tygodniu

The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up to, and including, 2.0.11 due to insufficient escaping on the user supplied parameter and lack of su…

9.8 CVSS
0.5% EPSS
sql-injection 2024-04-09
CVE-2023-1091 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Warehousing Automation System allows Command Line Execution through SQL Injection. This issue affects…

9.8 CVSS
0.5% EPSS
CVE-2023-2449 🟠 Łataj w tym tygodniu

The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. This is due to the plugin using native password reset functionality, with insufficient validation on …

9.8 CVSS
0.5% EPSS
CVE-2023-1153 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Pacsrapor: before 1.…

9.8 CVSS
0.5% EPSS
CVE-2026-25544 🟠 Łataj w tym tygodniu

Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blind SQL injection attac…

9.8 CVSS
0.4% EPSS
CVE-2022-3792 🔴 Łataj teraz

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye terminal operating system allows SQL Injection. This issue affects GullsEye terminal operating syst…

9.8 CVSS
0.4% EPSS
CVE-2026-45779 🟠 Łataj w tym tygodniu

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated remote attacker to execute arbitrary SQ…

9.8 CVSS
0.4% EPSS
CVE-2026-41460 🔴 Łataj teraz

SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated…

9.8 CVSS
0.4% EPSS
CVE-2026-25241 🟠 Łataj w tym tygodniu

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<package>/<version> endpoint allows remote attackers to execute arbitrary SQL…

9.8 CVSS
0.4% EPSS
pearsql-injection 2026-02-03
CVE-2026-44172 🟠 Łataj w tym tygodniu

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the datab…

9.8 CVSS
0.4% EPSS
CVE-2026-48114 🟠 Łataj w tym tygodniu

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthenticated SQL injection in the /harvesterRegistration endpoint. HarvesterRegist…

9.8 CVSS
0.4% EPSS
sql-injection 2026-06-15
CVE-2026-55740 🟠 Łataj w tym tygodniu

Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php. The busid parameter received via HTTP POST is …

9.8 CVSS
0.4% EPSS
sql-injection 2026-06-18
CVE-2026-39893 🟠 Łataj w tym tygodniu

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into a RLIKE SQL clause without sanitization. The endpoint does not require …

9.8 CVSS
0.4% EPSS
cactisql-injection 2026-06-24
CVE-2025-9953 🟠 Łataj w tym tygodniu

Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Software allows SQL Injection. This issue affects Databank Accreditation So…

9.8 CVSS
0.3% EPSS
sql-injection 2026-02-19
CVE-2025-4784 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella allows SQL Injection. This issue affects Tourtella: before 26.05.2025.

9.8 CVSS
0.3% EPSS
CVE-2026-25993 🟠 Łataj w tym tygodniu

EverShop is a TypeScript-first eCommerce platform. During category update and deletion event handling, the application embeds path / request_path values—derived from the url_key stored in the database—into SQL statements…

9.8 CVSS
0.3% EPSS
CVE-2026-39955 🟠 Łataj w tym tygodniu

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php. This issue has been fixed in ve…

9.8 CVSS
0.3% EPSS
cactisql-injection 2026-06-24
CVE-2024-28389 🟠 Łataj w tym tygodniu

SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail(…

9.8 CVSS
0.3% EPSS
sql-injection 2024-03-19
CVE-2023-1508 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection. This issue affects Mobilmen Terminal …

9.8 CVSS
0.3% EPSS
CVE-2022-4422 🟠 Łataj w tym tygodniu

Call Center System developed by Bulutses Information Technologies before version 3.0 has an unauthenticated Sql Injection vulnerability. This has been fixed in the version 3.0

9.8 CVSS
0.3% EPSS
CVE-2023-1873 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faturamatik Bircard allows SQL Injection.This issue affects Bircard: before 23.04.05.

9.8 CVSS
0.3% EPSS
CVE-2024-25910 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.

9.8 CVSS
0.3% EPSS
CVE-2020-29297 🔴 Łataj teraz

Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0.

9.8 CVSS
0.3% EPSS
CVE-2026-38812 🟠 Łataj w tym tygodniu

RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges to access sensitive …

9.8 CVSS
0.3% EPSS
sql-injection 2026-06-15
CVE-2023-34575 🔴 Łataj teraz

SQL injection vulnerability in PrestaShop opartsavecart through 2.0.7 allows remote attackers to run arbitrary SQL commands via OpartSaveCartDefaultModuleFrontController::initContent() and OpartSaveCartDefaultModuleFront…

9.8 CVSS
0.3% EPSS
CVE-2026-25236 🟠 Łataj w tym tygodniu

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to unsafe literal substitution for an IN (...) list. This issue has been …

9.8 CVSS
0.3% EPSS
pearsql-injection 2026-02-03
CVE-2026-25238 🟠 Łataj w tym tygodniu

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription deletion may allow attackers to inject SQL via a crafted email value. Th…

9.8 CVSS
0.3% EPSS
pearsql-injection 2026-02-03
CVE-2026-25240 🟠 Łataj w tym tygodniu

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::maintains() when role filters are provided as an array and interpolated i…

9.8 CVSS
0.3% EPSS
pearsql-injection 2026-02-03
CVE-2022-29650 🟠 Łataj w tym tygodniu

Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php.

9.8 CVSS
0.3% EPSS
CVE-2021-3854 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Useroam Hotspot allows SQL Injection. This issue affects Useroam Hotspot: before 5.1.0.15.

9.8 CVSS
0.3% EPSS
gloxsql-injection 2023-03-02
CVE-2022-4557 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before …

9.8 CVSS
0.3% EPSS
CVE-2022-2807 🟠 Łataj w tym tygodniu

SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection. This issue affects Prens Student Information System: before 2.1.11.

9.8 CVSS
0.3% EPSS
algansql-injection 2022-12-02
CVE-2022-2504 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Software SDD-Baro allows SQL Injection. This issue affects SDD-Baro: before 2.8.432.

9.8 CVSS
0.3% EPSS
CVE-2022-3760 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mia Technology Mia-Med. This issue affects Mia-Med: before 1.0.0.58.

9.8 CVSS
0.3% EPSS
CVE-2023-1723 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veragroup Mobile Assistant allows SQL Injection.This issue affects Mobile Assistant: before 21.S.2343.

9.8 CVSS
0.3% EPSS
CVE-2023-1251 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akinsoft Wolvox. This issue affects Wolvox: before 8.02.03.

9.8 CVSS
0.3% EPSS
CVE-2023-1198 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities allows SQL Injection. This issue affects Starcities: through 1.3.

9.8 CVSS
0.3% EPSS
saysissql-injection 2023-03-10
CVE-2023-1152 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies Persolus allows SQL Injection. This issue affects Persolus: before 2.03.93.

9.8 CVSS
0.3% EPSS
utaritsql-injection 2023-03-17
CVE-2023-1050 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in As Koc Energy Web Report System allows SQL Injection. This issue affects Web Report System: before 23.03.10.

9.8 CVSS
0.3% EPSS
askocsql-injection 2023-03-23
CVE-2026-25234 🟠 Łataj w tym tygodniu

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion can allow an attacker with access to the category manager workflow to i…

9.8 CVSS
0.3% EPSS
pearsql-injection 2026-02-03
CVE-2022-36759 🟠 Łataj w tym tygodniu

Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=.

9.8 CVSS
0.2% EPSS
CVE-2023-2297 🔴 Łataj teraz

The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password res…

9.8 CVSS
0.2% EPSS
CVE-2023-4661 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saphira Saphira Connect allows SQL Injection. This issue affects Saphira Connect: before 9.

9.8 CVSS
0.2% EPSS
adobesql-injection 2023-09-15
CVE-2024-12143 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobilteg Mobile Informatics Mikro Hand Terminal - MikroDB allows SQL Injection. This issue affects Mikro Hand Termina…

9.8 CVSS
0.2% EPSS
sql-injection 2025-06-27
CVE-2024-12150 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eron Software Wowwo CRM allows Blind SQL Injection. This issue affects Wowwo CRM.  NOTE: The vendor did not inform a…

9.8 CVSS
0.2% EPSS
sql-injection 2025-06-27
CVE-2024-12364 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yeşil Software Guest Tracking Software allows SQL Injection. This issue affects Guest Tracking Software.  NOTE:…

9.8 CVSS
0.2% EPSS
sql-injection 2025-06-27
CVE-2024-11739 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Case Informatics Case ERP allows SQL Injection. This issue affects Case ERP: before V2.0.1.

9.8 CVSS
0.2% EPSS
sql-injection 2025-06-27
CVE-2024-10244 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ISDO Software Web Software allows SQL Injection. This issue affects Web Software: before 3.6.

9.8 CVSS
0.2% EPSS
sql-injection 2024-12-19
CVE-2025-4738 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yirmibes Software MY ERP allows SQL Injection. This issue affects MY ERP: before 1.170.

9.8 CVSS
0.2% EPSS
sql-injection 2025-06-19
CVE-2025-6918 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection. This issue affects Virtual PBX Software: before 09.07.2025.

9.8 CVSS
0.2% EPSS
sql-injection 2025-07-28
CVE-2023-5047 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DRD Fleet Leasing DRDrive allows SQL Injection. This issue affects DRDrive: before 20231006.

9.8 CVSS
0.2% EPSS
drdsql-injection 2023-11-22
CVE-2025-2812 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics Ticket Sales Automation allows Blind SQL Injection. This issue affects Ticket Sales Automation: be…

9.8 CVSS
0.2% EPSS
mydatasql-injection 2025-05-02
CVE-2024-6401 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting InsureE GL allows SQL Injection. This issue affects InsureE GL: before 4.6.2.

9.8 CVSS
0.2% EPSS
sfssql-injection 2024-09-16
CVE-2023-34576 🟠 Łataj w tym tygodniu

SQL injection vulnerability in updatepos.php in PrestaShop opartfaq through 1.0.3 allows remote attackers to run arbitrary SQL commands via unspedified vector.

9.8 CVSS
0.2% EPSS
CVE-2023-6441 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UNI-PA University Marketing & Computer Internet Trade Inc. University Information System allows SQL Injection. This i…

9.8 CVSS
0.2% EPSS
unipasql-injection 2024-02-14
CVE-2023-6436 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics Website Template allows SQL Injection. This issue affects Website Template: through 20231215.

9.8 CVSS
0.2% EPSS
CVE-2024-4228 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive Information to an Unauthorized Actor, CWE - 522 - Insufficiently Protected Credentials vulnerability…

9.8 CVSS
0.2% EPSS
sql-injection 2024-06-26
CVE-2023-1765 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akbim Computer Panon allows SQL Injection.This issue affects Panon: before 1.0.2.

9.8 CVSS
0.2% EPSS
akbimsql-injection 2023-04-03
CVE-2023-1267 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ulkem Company PtteM Kart. This issue affects PtteM Kart: before 2.1.

9.8 CVSS
0.2% EPSS
CVE-2024-7076 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Blind SQL Injection. This issue affects Semtek Sempo…

9.8 CVSS
0.2% EPSS
CVE-2024-7078 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows SQL Injection. This issue affects Semtek Sempos: thr…

9.8 CVSS
0.2% EPSS
CVE-2023-5634 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ArslanSoft Education Portal allows SQL Injection. This issue affects Education Portal: before v1.1.

9.8 CVSS
0.2% EPSS
CVE-2023-1064 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighbridge Automation Software allows SQL Injection. This issue affects Weighbridge Automation Software:…

9.8 CVSS
0.2% EPSS
CVE-2024-1100 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vadi Corporate Information Systems DIGIKENT GIS allows SQL Injection. This issue affects DIGIKENT GIS: through 2.23.5…

9.8 CVSS
0.2% EPSS
sql-injection 2024-05-30
CVE-2026-3843 🟠 Łataj w tym tygodniu

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST reques…

9.8 CVSS
0.2% EPSS
CVE-2023-4541 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ween Software Admin Panel allows SQL Injection. This issue affects Admin Panel: through 20231229.  NOTE: The vendor …

9.8 CVSS
0.2% EPSS
weensql-injection 2023-12-29
CVE-2023-4231 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cevik Informatics Online Payment System allows SQL Injection. This issue affects Online Payment System: before 4.09.

9.8 CVSS
0.2% EPSS
ceviksql-injection 2023-09-15
CVE-2023-3651 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digital Ant E-Commerce Software allows SQL Injection. This issue affects E-Commerce Software: before 11.

9.8 CVSS
0.2% EPSS
CVE-2023-4737 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hedef Tracking Admin Panel allows SQL Injection. This issue affects Admin Panel: before 1.2.

9.8 CVSS
0.2% EPSS
CVE-2023-35071 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection.This issue affects Logging Administration Panel: before 202…

9.8 CVSS
0.2% EPSS
mrvsql-injection 2023-09-27
CVE-2023-0939 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Technologies Online Services Software allows SQL Injection. This issue affects Online Services Softwa…

9.8 CVSS
0.2% EPSS
CVE-2024-6919 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Blind SQL Injection. This issue affects NACPremium: through 0108…

9.8 CVSS
0.2% EPSS
nacsql-injection 2024-09-02
CVE-2023-4833 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Besttem Network Marketing Software allows SQL Injection. This issue affects Network Marketing Software: before 1.0.23…

9.8 CVSS
0.2% EPSS
CVE-2023-3898 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mAyaNet E-Commerce Software allows SQL Injection. This issue affects E-Commerce Software: before 1.1.

9.8 CVSS
0.2% EPSS
CVE-2023-3717 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farmakom Remote Administration Console allows SQL Injection. This issue affects Remote Administration Console: before…

9.8 CVSS
0.2% EPSS
CVE-2023-3716 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Online Collection Software allows SQL Injection. This issue affects Online Collection Software: before 1.0.1.

9.8 CVSS
0.2% EPSS
oduyosql-injection 2023-08-08
CVE-2024-7071 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in Brain Information Technologies Inc. Brain Low-Code allows SQL Injection. This i…

9.8 CVSS
0.2% EPSS
CVE-2023-6173 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeoSOFT Software TeoBASE allows SQL Injection. This issue affects TeoBASE: through 27032024. NOTE: The vendor was con…

9.8 CVSS
0.1% EPSS
sql-injection 2024-03-27
CVE-2025-65133 🟠 Łataj w tym tygodniu

A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attacker can supply a crafted HTTP request to the affected endpoint to manip…

9.8 CVSS
0.1% EPSS
sql-injection 2026-04-14
CVE-2023-4832 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aceka Company Management allows SQL Injection. This issue affects Company Management: before 3072 .

9.8 CVSS
0.1% EPSS
CVE-2023-4766 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Movus allows SQL Injection. This issue affects Movus: before 20230913.

9.8 CVSS
0.1% EPSS
movussql-injection 2023-09-14
CVE-2023-0979 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData MedDataPACS allows SQL Injection. This issue affects MedDataPACS : before 2023-03-03.

9.8 CVSS
0.1% EPSS
CVE-2026-39196 🟠 Łataj w tym tygodniu

Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition function. This vulnerability allows attackers to access sensitive databa…

9.8 CVSS
0.1% EPSS
sql-injection 2026-06-15
CVE-2026-50890 🟠 Łataj w tym tygodniu

Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings. This vulnerability allows attackers to access sensitive database information vi…

9.8 CVSS
0.1% EPSS
sql-injection 2026-06-15
CVE-2024-29732 🟠 Łataj w tym tygodniu

A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthenticated user to retrieve, update and delete all the information of database. This vulnerability was f…

9.8 CVSS
0.1% EPSS
sql-injection 2024-03-21
CVE-2023-6145 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Advanced C2C Marketplace Software allows SQL Injecti…

9.8 CVSS
0.1% EPSS
CVE-2023-4673 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sanalogy Turasistan allows SQL Injection. This issue affects Turasistan: before 20230911 .

9.8 CVSS
0.1% EPSS
CVE-2023-4830 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tura Signalix allows SQL Injection. This issue affects Signalix: 7T_0228.

9.8 CVSS
0.1% EPSS
CVE-2023-4670 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Innosa Probbys allows SQL Injection. This issue affects Probbys: before 2.

9.8 CVSS
0.1% EPSS
CVE-2023-4835 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CF Software Oil Management Software allows SQL Injection. This issue affects Oil Management Software: before 20230912…

CVE-2023-2851 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AGT Tech Ceppatron allows Command Line Execution through SQL Injection, SQL Injection.This issue affects all versions …

9.8 CVSS
0.1% EPSS
CVE-2024-13148 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter B2B Login Platform allows SQL Injection. This issue affects B2B Login Platform: before 16.01.2025.

9.8 CVSS
0.1% EPSS
sql-injection 2025-02-27
CVE-2024-8259 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection. This issue affects NatraC…

9.8 CVSS
0.1% EPSS
sql-injection 2024-12-09
CVE-2024-8972 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobil365 Informatics Saha365 App allows SQL Injection. This issue affects Saha365 App: before 30.09.2024.

9.8 CVSS
0.1% EPSS
sql-injection 2024-12-17
CVE-2024-8997 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Configuration Interface allows SQL Injection. This issue affects EVC04 Configuration Interface: before V…

9.8 CVSS
0.1% EPSS
vestelsql-injection 2025-03-18
CVE-2024-6699 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic Inc. Mikafon MA7 allows SQL Injection. This issue affects Mikafon MA7: from v3.0 before v3.1.

9.8 CVSS
0.1% EPSS
CVE-2023-6191 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egehan Security WebPDKS allows SQL Injection. This issue affects WebPDKS: through 20240329. NOTE: The vendor was cont…

9.8 CVSS
0.1% EPSS
CVE-2024-0857 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software Inc. FlexWater Corporate Water Management allows SQL Injection. This issue affects FlexWater Corpo…

9.8 CVSS
0.1% EPSS
CVE-2024-36058 🟠 Łataj w tym tygodniu

The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library user…

9.8 CVSS
0.1% EPSS
sql-injection 2026-04-07
CVE-2026-5963 🟠 Łataj w tym tygodniu

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

9.8 CVSS
0.1% EPSS
CVE-2026-5964 🟠 Łataj w tym tygodniu

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

9.8 CVSS
0.1% EPSS
CVE-2026-6887 🟠 Łataj w tym tygodniu

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete datab…

9.8 CVSS
0.1% EPSS
sql-injection 2026-04-23
CVE-2023-6677 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Financial Technology Online Collection allows SQL Injection. This issue affects Online Collection: before v.1.0…

9.8 CVSS
0.1% EPSS
oduyosql-injection 2024-02-09
CVE-2023-5155 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies SoliPay Mobile App allows SQL Injection. This issue affects SoliPay Mobile App: befor…

9.8 CVSS
0.1% EPSS
utaritsql-injection 2024-02-15
CVE-2023-4675 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GM Information Technologies MDO allows SQL Injection. This issue affects MDO: through 20231229.  NOTE: The vendor wa…

9.8 CVSS
0.1% EPSS
CVE-2023-4530 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Turna Advertising Administration Panel allows SQL Injection. This issue affects Advertising Administration Panel: bef…

9.8 CVSS
0.1% EPSS
CVE-2023-2963 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oliva Expertise Oliva Expertise EKS allows SQL Injection.This issue affects Oliva Expertise EKS: before 1.2.

9.8 CVSS
0.1% EPSS
CVE-2023-3376 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digital Strategy Zekiweb allows SQL Injection.This issue affects Zekiweb: before 2.

9.8 CVSS
0.1% EPSS
CVE-2024-13147 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2B Login Panel allows SQL Injection. This issue affects B2B Login Panel: before 15.01.2025.

9.8 CVSS
0.1% EPSS
sql-injection 2025-03-05
CVE-2024-12097 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Boceksoft Informatics E-Travel allows SQL Injection. This issue affects E-Travel: before 15.12.2024.

9.8 CVSS
0.1% EPSS
sql-injection 2025-03-05
CVE-2023-4034 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection. This issue affects Smartrise…

9.8 CVSS
0.1% EPSS
CVE-2023-1547 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Elra Parkmatik allows SQL Injection through SOAP Parameter Tampering, Command Line Execution through SQL Injection. T…

9.8 CVSS
0.1% EPSS
elrasql-injection 2023-07-13
CVE-2024-12016 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection. This issue affects CM News: through 6.0. NOTE: The vendor was con…

9.8 CVSS
0.1% EPSS
sql-injection 2025-03-20
CVE-2025-4822 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allows SQL Injection. This issue affects ScadaWatt Otopilot: before 27.05…

9.8 CVSS
0.1% EPSS
sql-injection 2025-07-24
CVE-2023-5045 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Kayisi allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Kayis…

9.8 CVSS
0.1% EPSS
biltaysql-injection 2023-10-12
CVE-2023-5046 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Procost allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Proc…

9.8 CVSS
0.1% EPSS
biltaysql-injection 2023-10-12
CVE-2023-4671 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software ECOP allows Command Line Execution through SQL Injection. This issue affects ECOP: before 32255.

9.8 CVSS
0.1% EPSS
CVE-2023-35064 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Satos Satos Mobile allows SQL Injection through SOAP Parameter Tampering.This issue affects Satos Mobile: before 20230…

9.8 CVSS
0.1% EPSS
satossql-injection 2023-06-13
CVE-2023-3377 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veribilim Software Computer Veribase allows SQL Injection.This issue affects Veribase: through 20231123.  NOTE: The v…

9.8 CVSS
0.1% EPSS
CVE-2023-2852 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Softmed SelfPatron allows SQL Injection.This issue affects SelfPatron : before 2.0.

9.8 CVSS
0.1% EPSS
CVE-2026-10880 🟠 Łataj w tym tygodniu

OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowing an unauthenticated remote attacker to…

9.8 CVSS
0.1% EPSS
CVE-2026-28430 🟠 Łataj w tym tygodniu

Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnerability which allows remote attackers to execute arbitrary SQL commands via the custom_dates paramete…

9.8 CVSS
0.1% EPSS
CVE-2023-38382 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category allows SQL Injection.This issue affects Subscribe to Ca…

9.8 CVSS
0.1% EPSS
CVE-2023-4531 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestav Software E-commerce Software allows SQL Injection. This issue affects E-commerce Software: before 20230901 .

9.8 CVSS
0.1% EPSS
mestavsql-injection 2023-09-05
CVE-2023-3045 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tise Technology Parking Web Report allows SQL Injection.This issue affects Parking Web Report: before 2.1.

9.8 CVSS
0.1% EPSS
tisesql-injection 2023-07-10
CVE-2023-35070 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VegaGroup Web Collection allows SQL Injection.This issue affects Web Collection: before 31197.

9.8 CVSS
0.1% EPSS
CVE-2023-3046 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Scienta allows SQL Injection.This issue affects Scienta: before 20230630.1953.

9.8 CVSS
0.1% EPSS
biltaysql-injection 2023-07-25
CVE-2023-35066 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software E-Invoice Approval System allows SQL Injection.This issue affects E-Invoice Approval System: before …

9.8 CVSS
0.1% EPSS
CVE-2023-3386 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 Camera Trap Tracking System allows SQL Injection.This issue affects Camera Trap Tracking System: before 3.1905.

9.8 CVSS
0.1% EPSS
CVE-2023-3522 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in a2 License Portal System allows SQL Injection.This issue affects License Portal System: before 1.48.

9.8 CVSS
0.1% EPSS
CVE-2023-35072 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proagent allows SQL Injection.This issue affects Proagent: before 20230904 .

9.8 CVSS
0.1% EPSS
CVE-2023-2750 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cityboss E-municipality allows SQL Injection.This issue affects E-municipality: before 6.05.

9.8 CVSS
0.1% EPSS
CVE-2023-2045 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software Auto Damage Tracking Software allows SQL Injection.This issue affects Auto Damage Tracking Software:…

9.8 CVSS
0.1% EPSS
CVE-2023-2064 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Minova Technology eTrace allows SQL Injection.This issue affects eTrace: before 23.05.20.

9.8 CVSS
0.1% EPSS
CVE-2023-2907 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marksoft allows SQL Injection.This issue affects Marksoft: through Mobile:v.7.1.7 ; Login:1.4 ; API:20230605.

9.8 CVSS
0.1% EPSS
CVE-2023-2046 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yontem Informatics Vehicle Tracking System allows SQL Injection.This issue affects Vehicle Tracking System: before 8. …

9.8 CVSS
0.1% EPSS
CVE-2023-2957 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisa Software Florist Site allows SQL Injection.This issue affects Florist Site: before 3.0.

9.8 CVSS
0.1% EPSS