Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-11-04 CVE-2023-32741 SQL Injection vulnerability in Itpathsolutions Contact Form to ANY API
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IT Path Solutions PVT LTD Contact Form to Any API allows SQL Injection.This issue affects Contact Form to Any API: from n/a through 1.1.2.
network
low complexity
itpathsolutions CWE-89
7.2
2023-11-03 CVE-2023-25800 SQL Injection vulnerability in Themeum Tutor LMS
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.2.0.
network
low complexity
themeum CWE-89
8.8
2023-11-03 CVE-2023-34383 SQL Injection vulnerability in Wedevs WP Project Manager
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This issue affects WP Project Manager: from n/a through 2.6.0.
network
low complexity
wedevs CWE-89
critical
9.8
2023-11-03 CVE-2023-46954 SQL Injection vulnerability in Relativity Relativityone 12.4.537.3
SQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacker to execute arbitrary code via the name parameter.
network
low complexity
relativity CWE-89
critical
9.8
2023-11-02 CVE-2023-26452 SQL Injection vulnerability in Open-Xchange Appsuite
Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed unchecked.
low complexity
open-xchange CWE-89
8.8
2023-11-02 CVE-2023-26453 SQL Injection vulnerability in Open-Xchange Appsuite
Requests to cache an image could be abused to include SQL queries that would be executed unchecked.
low complexity
open-xchange CWE-89
8.8
2023-11-02 CVE-2023-26454 SQL Injection vulnerability in Open-Xchange Appsuite
Requests to fetch image metadata could be abused to include SQL queries that would be executed unchecked.
low complexity
open-xchange CWE-89
8.8
2023-11-02 CVE-2023-29047 SQL Injection vulnerability in Open-Xchange Appsuite
Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements.
low complexity
open-xchange CWE-89
7.3
2023-11-01 CVE-2023-44025 SQL Injection vulnerability in Addify Free Gifts 1.0.2
SQL injection vulnerability in addify Addifyfreegifts v.1.0.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the getrulebyid function in the AddifyfreegiftsModel.php component.
network
low complexity
addify CWE-89
critical
9.8
2023-11-01 CVE-2023-46482 SQL Injection vulnerability in Wuzhicms 4.1.0
SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.
network
low complexity
wuzhicms CWE-89
critical
9.8