Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-03-22 CVE-2023-28663 SQL Injection vulnerability in Formidablepro2Pdf Formidable Pro2Pdf
The Formidable PRO2PDF WordPress Plugin, version < 3.11, is affected by an authenticated SQL injection vulnerability in the ‘fieldmap’ parameter in the fpropdf_export_file action.
network
low complexity
formidablepro2pdf CWE-89
8.8
2023-03-22 CVE-2023-1578 SQL Injection vulnerability in Pimcore
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.
network
low complexity
pimcore CWE-89
8.8
2023-03-22 CVE-2023-27637 SQL Injection vulnerability in Tshirtecommerce Custom Product Designer 2.1.4
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop.
network
low complexity
tshirtecommerce CWE-89
critical
9.8
2023-03-22 CVE-2023-27638 SQL Injection vulnerability in Tshirtecommerce Custom Product Designer 2.1.4
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop.
network
low complexity
tshirtecommerce CWE-89
critical
9.8
2023-03-21 CVE-2023-27569 SQL Injection vulnerability in Prestashop EO Tags
The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.
network
low complexity
prestashop CWE-89
critical
9.8
2023-03-21 CVE-2023-27570 SQL Injection vulnerability in Prestashop EO Tags
The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie.
network
low complexity
prestashop CWE-89
critical
9.8
2023-03-21 CVE-2023-27871 SQL Injection vulnerability in IBM Aspera Faspex 4.4.1/4.4.2
IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query.
network
low complexity
ibm CWE-89
7.5
2023-03-21 CVE-2023-1153 SQL Injection vulnerability in Pacsrapor
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows SQL Injection, Command Line Execution through SQL Injection.This issue affects Pacsrapor: before 1.22.
network
low complexity
pacsrapor CWE-89
critical
9.8
2023-03-21 CVE-2023-1545 SQL Injection vulnerability in Teampass
SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.
network
low complexity
teampass CWE-89
7.5
2023-03-20 CVE-2022-4933 SQL Injection vulnerability in Atm-Consulting Dolibarr Module Quicksupplierprice
A vulnerability, which was classified as critical, has been found in ATM Consulting dolibarr_module_quicksupplierprice up to 1.1.6.
network
low complexity
atm-consulting CWE-89
critical
9.8