Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-03-09 CVE-2023-1251 SQL Injection vulnerability in Akinsoft Wolvox
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akinsoft Wolvox. This issue affects Wolvox: before 8.02.03.
network
low complexity
akinsoft CWE-89
critical
9.8
2023-03-08 CVE-2023-24777 SQL Injection vulnerability in Funadmin 3.2.0
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.
network
low complexity
funadmin CWE-89
critical
9.8
2023-03-08 CVE-2023-24782 SQL Injection vulnerability in Funadmin 3.2.0
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit.
network
low complexity
funadmin CWE-89
critical
9.8
2023-03-08 CVE-2023-24773 SQL Injection vulnerability in Funadmin 3.2.0
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.
network
low complexity
funadmin CWE-89
critical
9.8
2023-03-08 CVE-2023-26922 SQL Injection vulnerability in Variscite Matrix-Gui 2.0
SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the shell_exect parameter to the \www\pages\matrix-gui-2.0 endpoint.
network
low complexity
variscite CWE-89
critical
9.8
2023-03-08 CVE-2023-1267 SQL Injection vulnerability in Pttemkart Pttem Kart
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ulkem Company PtteM Kart.This issue affects PtteM Kart: before 2.1.
network
low complexity
pttemkart CWE-89
critical
9.8
2023-03-08 CVE-2023-24780 SQL Injection vulnerability in Funadmin 3.2.0
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns.
network
low complexity
funadmin CWE-89
critical
9.8
2023-03-07 CVE-2023-24775 SQL Injection vulnerability in Funadmin 3.2.0
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.
network
low complexity
funadmin CWE-89
critical
9.8
2023-03-07 CVE-2023-25223 SQL Injection vulnerability in Crmeb Java 1.3.4
CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list.
network
low complexity
crmeb CWE-89
7.2
2023-03-07 CVE-2023-24781 SQL Injection vulnerability in Funadmin 3.2.0
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php.
network
low complexity
funadmin CWE-89
critical
9.8