Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-03-10 CVE-2023-24774 SQL Injection vulnerability in Funadmin 3.2.0
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.
network
low complexity
funadmin CWE-89
critical
9.8
2023-03-10 CVE-2023-1091 SQL Injection vulnerability in Alpatateknoloji Licensed Warehousing Automation System 2023.1.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Warehousing Automation System allows Command Line Execution through SQL Injection.This issue affects Licensed Warehousing Automation System: through 2023.1.01.
network
low complexity
alpatateknoloji CWE-89
critical
9.8
2023-03-09 CVE-2023-27202 SQL Injection vulnerability in Best POS Management System Project Best POS Management System 1.0
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.
network
low complexity
best-pos-management-system-project CWE-89
critical
9.8
2023-03-09 CVE-2023-27203 SQL Injection vulnerability in Best POS Management System Project Best POS Management System 1.0
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.
network
low complexity
best-pos-management-system-project CWE-89
critical
9.8
2023-03-09 CVE-2023-27204 SQL Injection vulnerability in Best POS Management System Project Best POS Management System 1.0
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.
network
low complexity
best-pos-management-system-project CWE-89
critical
9.8
2023-03-09 CVE-2023-27205 SQL Injection vulnerability in Best POS Management System Project Best POS Management System 1.0
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.
network
low complexity
best-pos-management-system-project CWE-89
critical
9.8
2023-03-09 CVE-2023-27207 SQL Injection vulnerability in Online Pizza Ordering System Project Online Pizza Ordering System 1.0
Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.
network
low complexity
online-pizza-ordering-system-project CWE-89
critical
9.8
2023-03-09 CVE-2023-27210 SQL Injection vulnerability in Online Pizza Ordering System Project Online Pizza Ordering System 1.0
Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php.
network
low complexity
online-pizza-ordering-system-project CWE-89
critical
9.8
2023-03-09 CVE-2023-27213 SQL Injection vulnerability in Online Student Management System Project Online Student Management System 1.0
Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /eduauth/student/search.php.
network
low complexity
online-student-management-system-project CWE-89
critical
9.8
2023-03-09 CVE-2023-27214 SQL Injection vulnerability in Online Student Management System Project Online Student Management System 1.0
Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate and todate parameters at /eduauth/student/between-date-reprtsdetails.php.
network
low complexity
online-student-management-system-project CWE-89
critical
9.8