Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-12-12 CVE-2024-12497 SQL Injection vulnerability in 1000Projects Attendance Tracking Management System 1.0
A vulnerability classified as critical has been found in 1000 Projects Attendance Tracking Management System 1.0.
network
low complexity
1000projects CWE-89
critical
9.8
2024-12-12 CVE-2024-12479 SQL Injection vulnerability in Cjbi Wetech-Cms 1.0/1.1/1.2
A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2 and classified as critical.
network
low complexity
cjbi CWE-89
8.8
2024-12-12 CVE-2024-12480 SQL Injection vulnerability in Cjbi Wetech-Cms 1.0/1.1/1.2
A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2.
network
low complexity
cjbi CWE-89
8.8
2024-12-12 CVE-2024-12481 SQL Injection vulnerability in Cjbi Wetech-Cms 1.0/1.1/1.2
A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2.
network
low complexity
cjbi CWE-89
8.8
2024-12-09 CVE-2024-54922 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.
network
low complexity
lopalopa CWE-89
7.2
2024-12-09 CVE-2024-54930 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.
network
low complexity
lopalopa CWE-89
7.2
2024-12-09 CVE-2024-54933 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.
network
low complexity
lopalopa CWE-89
7.2
2024-12-09 CVE-2024-54926 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the school_year parameter.
network
low complexity
lopalopa CWE-89
8.8
2024-12-09 CVE-2024-54920 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters.
network
low complexity
lopalopa CWE-89
critical
9.8
2024-12-09 CVE-2024-54929 SQL Injection vulnerability in Lopalopa E-Learning Management System 1.0
KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.
network
low complexity
lopalopa CWE-89
7.2