Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-02-08 | CVE-2024-24213 | SQL Injection vulnerability in Supabase Postgres 15.1 Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. | 9.8 |
2024-02-08 | CVE-2024-1207 | SQL Injection vulnerability in Wpbookingcalendar Booking Calendar The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 9.8 |
2024-02-08 | CVE-2024-24003 | SQL Injection vulnerability in Jishenghua Jsherp 3.3 jshERP v3.3 is vulnerable to SQL Injection. | 9.8 |
2024-02-08 | CVE-2024-24014 | SQL Injection vulnerability in Xxyopen Novel-Plus A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. | 9.8 |
2024-02-08 | CVE-2024-24017 | SQL Injection vulnerability in Xxyopen Novel-Plus A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. | 9.8 |
2024-02-08 | CVE-2024-24021 | SQL Injection vulnerability in Xxyopen Novel-Plus A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. | 9.8 |
2024-02-08 | CVE-2024-24018 | SQL Injection vulnerability in Xxyopen Novel-Plus A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. | 9.8 |
2024-02-08 | CVE-2024-24023 | SQL Injection vulnerability in Xxyopen Novel-Plus A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. | 9.8 |
2024-02-07 | CVE-2024-24133 | SQL Injection vulnerability in Atmail 6.3.0/6.6.0 Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page. | 9.8 |
2024-02-07 | CVE-2024-1118 | SQL Injection vulnerability in Podlove Subscribe Button The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute of the podlove-subscribe-button shortcode in all versions up to, and including, 1.3.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 8.8 |