Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-04-15 CVE-2023-2107 SQL Injection vulnerability in Ibos 4.5.5
A vulnerability, which was classified as critical, was found in IBOS 4.5.5.
network
low complexity
ibos CWE-89
critical
9.8
2023-04-15 CVE-2023-2094 SQL Injection vulnerability in Vehicle Service Management System Project Vehicle Service Management System 1.0
A vulnerability has been found in SourceCodester Vehicle Service Management System 1.0 and classified as critical.
6.3
2023-04-15 CVE-2023-2089 SQL Injection vulnerability in Complaint Management System Project Complaint Management System 1.0
A vulnerability was found in SourceCodester Complaint Management System 1.0.
8.8
2023-04-15 CVE-2022-45030 SQL Injection vulnerability in Rconfig 3.9.7
A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact with secure-file-priv).
network
low complexity
rconfig CWE-89
8.8
2023-04-14 CVE-2023-2054 SQL Injection vulnerability in Advanced Online Voting System Project Advanced Online Voting System 1.0
A vulnerability, which was classified as critical, was found in Campcodes Advanced Online Voting System 1.0.
7.5
2023-04-14 CVE-2023-27649 SQL Injection vulnerability in Bestools Trusted Tools Free Music
SQL injection vulnerability found in Trusted Tools Free Music v.2.1.0.47, v.2.0.0.46, v.1.9.1.45, v.1.8.2.43 allows a remote attacker to cause a denial of service via the search history table
network
low complexity
bestools CWE-89
7.5
2023-04-14 CVE-2023-29622 SQL Injection vulnerability in Purchase Order Management Project Purchase Order Management 1.0
Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /purchase_order/admin/login.php.
network
low complexity
purchase-order-management-project CWE-89
critical
9.8
2023-04-14 CVE-2023-29626 SQL Injection vulnerability in Yoga Class Registration System Project Yoga Class Registration System 1.0
Yoga Class Registration System 1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at /admin/login.php.
7.5
2023-04-13 CVE-2023-27667 SQL Injection vulnerability in Auto Dealer Management System Project Auto Dealer Management System 1.0
Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability.
network
low complexity
auto-dealer-management-system-project CWE-89
critical
9.8
2023-04-13 CVE-2023-27779 SQL Injection vulnerability in Amsystem AM Presencia 3.7.3
AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.
network
low complexity
amsystem CWE-89
critical
9.8