Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-10-22 CVE-2024-9987 SQL Injection vulnerability in Pandorafms Pandora FMS 742/746
A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects Pandora FMS: from 700 through <777.3.
network
low complexity
pandorafms CWE-89
8.8
2024-10-21 CVE-2024-30157 SQL Injection vulnerability in Mitel Micollab
A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injection attack due to insufficient validation of user input.
network
low complexity
mitel CWE-89
7.2
2024-10-21 CVE-2024-30158 SQL Injection vulnerability in Mitel Micollab
A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injection attack due to insufficient validation of user input.
network
low complexity
mitel CWE-89
7.2
2024-10-21 CVE-2024-48509 SQL Injection vulnerability in Learning With Texts Project Learning With Texts 2.0.3
Learning with Texts (LWT) 2.0.3 is vulnerable to SQL Injection.
network
low complexity
learning-with-texts-project CWE-89
critical
9.8
2024-10-21 CVE-2024-47328 SQL Injection vulnerability in Funnelkit Automations
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Automation By Autonami allows SQL Injection.This issue affects Automation By Autonami: from n/a through 3.1.2.
network
low complexity
funnelkit CWE-89
7.2
2024-10-21 CVE-2024-8625 SQL Injection vulnerability in Total-Soft TS Poll
The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
network
low complexity
total-soft CWE-89
7.2
2024-10-21 CVE-2024-10196 SQL Injection vulnerability in Code-Projects Pharmacy Management System 1.0
A vulnerability was found in code-projects Pharmacy Management System 1.0 and classified as critical.
network
low complexity
code-projects CWE-89
critical
9.8
2024-10-20 CVE-2024-47325 SQL Injection vulnerability in Themeisle multiple Page Generator
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows SQL Injection.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.7.
network
low complexity
themeisle CWE-89
8.8
2024-10-20 CVE-2024-49609 SQL Injection vulnerability in Brandonwhite Author Discussion
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brandon White Author Discussion allows Blind SQL Injection.This issue affects Author Discussion: from n/a through 0.2.2.
network
low complexity
brandonwhite CWE-89
8.8
2024-10-20 CVE-2024-49612 SQL Injection vulnerability in Infotuts SW Contact Form
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infotuts SW Contact Form allows Blind SQL Injection.This issue affects SW Contact Form: from n/a through 1.0.
network
low complexity
infotuts CWE-89
8.8