Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-10-27 CVE-2024-10411 SQL Injection vulnerability in Janobe Online Hotel Reservation System 1.0
A vulnerability was found in SourceCodester Online Hotel Reservation System 1.0.
network
low complexity
janobe CWE-89
7.2
2024-10-27 CVE-2024-10408 SQL Injection vulnerability in Fabianros Blood Bank Management System 1.0
A vulnerability has been found in code-projects Blood Bank Management up to 1.0 and classified as critical.
network
low complexity
fabianros CWE-89
8.8
2024-10-27 CVE-2024-10409 SQL Injection vulnerability in Fabianros Blood Bank Management System 1.0
A vulnerability was found in code-projects Blood Bank Management 1.0 and classified as critical.
network
low complexity
fabianros CWE-89
8.8
2024-10-27 CVE-2024-10407 SQL Injection vulnerability in Mayurik Petrol Pump Management 1.0
A vulnerability, which was classified as critical, was found in SourceCodester Petrol Pump Management Software 1.0.
network
low complexity
mayurik CWE-89
7.2
2024-10-26 CVE-2024-10406 SQL Injection vulnerability in Mayurik Petrol Pump Management 1.0
A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0.
network
low complexity
mayurik CWE-89
7.2
2024-10-26 CVE-2024-9475 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the order_by parameter in all versions up to, and including, 5.4.6 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
CWE-89
4.9
2024-10-25 CVE-2024-48218 SQL Injection vulnerability in Funadmin 5.0.2
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.
network
low complexity
funadmin CWE-89
7.2
2024-10-25 CVE-2024-48222 SQL Injection vulnerability in Funadmin 5.0.2
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.
network
low complexity
funadmin CWE-89
7.2
2024-10-25 CVE-2024-48223 SQL Injection vulnerability in Funadmin 5.0.2
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.
network
low complexity
funadmin CWE-89
7.2
2024-10-25 CVE-2024-48226 SQL Injection vulnerability in Funadmin 5.0.2
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.
network
low complexity
funadmin CWE-89
7.2