Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-10-25 CVE-2024-48229 SQL Injection vulnerability in Funadmin 5.0.2
funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.
network
low complexity
funadmin CWE-89
7.2
2024-10-25 CVE-2024-48230 SQL Injection vulnerability in Funadmin 5.0.2
funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.
network
low complexity
funadmin CWE-89
7.2
2024-10-25 CVE-2024-10380 SQL Injection vulnerability in Mayurik Petrol Pump Management 1.0
A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0.
network
low complexity
mayurik CWE-89
7.5
2024-10-25 CVE-2024-10378 SQL Injection vulnerability in Esafenet CDG 5
A vulnerability classified as critical has been found in ESAFENET CDG 5.
network
low complexity
esafenet CWE-89
critical
9.8
2024-10-25 CVE-2024-10376 SQL Injection vulnerability in Esafenet CDG 5
A vulnerability was found in ESAFENET CDG 5.
network
low complexity
esafenet CWE-89
critical
9.8
2024-10-25 CVE-2024-10377 SQL Injection vulnerability in Esafenet CDG 5
A vulnerability was found in ESAFENET CDG 5.
network
low complexity
esafenet CWE-89
critical
9.8
2024-10-25 CVE-2024-47483 SQL Injection vulnerability in Dell Data Lakehouse 1.0.0.0/1.1.0.0
Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability.
local
low complexity
dell CWE-89
5.5
2024-10-25 CVE-2024-10341 SQL Injection vulnerability in Tezzeract League of Legends Shortcodes
The League of Legends Shortcodes plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
tezzeract CWE-89
6.5
2024-10-25 CVE-2024-10368 SQL Injection vulnerability in Codezips Sales Management System 1.0
A vulnerability was found in Codezips Sales Management System 1.0.
network
low complexity
codezips CWE-89
critical
9.8
2024-10-25 CVE-2024-10369 SQL Injection vulnerability in Codezips Sales Management System 1.0
A vulnerability was found in Codezips Sales Management System 1.0.
network
low complexity
codezips CWE-89
critical
9.8