Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-10-12 CVE-2023-41262 SQL Injection vulnerability in Plixer Scrutinizer
An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1.
network
low complexity
plixer CWE-89
critical
9.8
2023-10-11 CVE-2023-44961 SQL Injection vulnerability in Koha-Community Koha Library Software
SQL Injection vulnerability in Koha Library Software 23.0.5.04 and before allows a remote attacker to obtain sensitive information via the intranet/cgi bin/cataloging/ysearch.pl.
network
low complexity
koha-community CWE-89
7.5
2023-10-10 CVE-2023-4309 SQL Injection vulnerability in Electionservicesco Internet Election Service
Election Services Co.
network
low complexity
electionservicesco CWE-89
critical
9.8
2023-10-09 CVE-2023-43899 SQL Injection vulnerability in Hansuncms Project Hansuncms 1.0
hansun CMS v1.0 was discovered to contain a SQL injection vulnerability via the component /ajax/ajax_login.ashx.
network
low complexity
hansuncms-project CWE-89
critical
9.8
2023-10-05 CVE-2023-40920 SQL Injection vulnerability in Prixan Prixanconnect 1.61
Prixan prixanconnect up to v1.62 was discovered to contain a SQL injection vulnerability via the component CartsGuruCatalogModuleFrontController::importProducts().
network
low complexity
prixan CWE-89
critical
9.8
2023-10-05 CVE-2023-43983 SQL Injection vulnerability in Presto-Changeo Attribute Grid 2.0.3
Presto Changeo attributegrid up to 2.0.3 was discovered to contain a SQL injection vulnerability via the component disable_json.php.
network
low complexity
presto-changeo CWE-89
critical
9.8
2023-10-05 CVE-2023-44024 SQL Injection vulnerability in Knowband ONE Page Checkout, Social Login & Mailchimp 8.0.3
SQL injection vulnerability in KnowBand Module One Page Checkout, Social Login & Mailchimp (supercheckout) v.8.0.3 and before allows a remote attacker to execute arbitrary code via a crafted request to the updateCheckoutBehaviour function in the supercheckout.php component.
network
low complexity
knowband CWE-89
critical
9.8
2023-10-04 CVE-2022-36276 SQL Injection vulnerability in Tcman GIM 8.0.1
TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'.
network
low complexity
tcman CWE-89
critical
9.8
2023-10-04 CVE-2023-5373 SQL Injection vulnerability in Oretnom23 Online Computer and Laptop Store 1.0
A vulnerability classified as critical has been found in SourceCodester Online Computer and Laptop Store 1.0.
network
low complexity
oretnom23 CWE-89
critical
9.8
2023-10-04 CVE-2023-3038 SQL Injection vulnerability in Helpdezk 1.1.10
SQL injection vulnerability in HelpDezk Community affecting version 1.1.10.
network
low complexity
helpdezk CWE-89
7.5