Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-05-11 CVE-2023-29863 SQL Injection vulnerability in Medisys Weblab 19.4.03
Medical Systems Co.
network
low complexity
medisys CWE-89
critical
9.8
2023-05-10 CVE-2023-30194 SQL Injection vulnerability in Prestashop Poststaticfooter
Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().
network
low complexity
prestashop CWE-89
critical
9.8
2023-05-10 CVE-2023-32569 SQL Injection vulnerability in Veritas Infoscale Operations Manager
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410.
network
low complexity
veritas CWE-89
critical
9.8
2023-05-08 CVE-2023-30092 SQL Injection vulnerability in Online Pizza Ordering System Project Online Pizza Ordering System 1.0
SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.
network
low complexity
online-pizza-ordering-system-project CWE-89
critical
9.8
2023-05-08 CVE-2020-23966 SQL Injection vulnerability in Victor CMS Project Victor CMS 1.0
SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request.
network
low complexity
victor-cms-project CWE-89
critical
9.8
2023-05-08 CVE-2021-28999 SQL Injection vulnerability in Cmsmadesimple CMS Made Simple
SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php.
network
low complexity
cmsmadesimple CWE-89
8.8
2023-05-08 CVE-2023-30018 SQL Injection vulnerability in Judging Management System Project Judging Management System 1.0
Judging Management System v1.0 is vulnerable to SQL Injection.
network
low complexity
judging-management-system-project CWE-89
critical
9.8
2023-05-05 CVE-2023-30243 SQL Injection vulnerability in Netentsec Application Security Gateway 6.3
Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access to sensitive information.
network
low complexity
netentsec CWE-89
7.5
2023-05-05 CVE-2023-30242 SQL Injection vulnerability in Netentsec Application Security Gateway 6.3
NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php.
network
low complexity
netentsec CWE-89
critical
9.8
2023-05-04 CVE-2023-30203 SQL Injection vulnerability in Judging Management System Project Judging Management System 1.0
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /php-jms/result_sheet.php.
network
low complexity
judging-management-system-project CWE-89
critical
9.8