Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-01-11 CVE-2022-47866 SQL Injection vulnerability in Lead Management System Project Lead Management System 1.0
Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php.
network
low complexity
lead-management-system-project CWE-89
critical
9.8
2023-01-11 CVE-2023-22959 SQL Injection vulnerability in Webchess Project Webchess 0.9.0/1.0.0
WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName).
network
low complexity
webchess-project CWE-89
8.8
2023-01-10 CVE-2022-38490 SQL Injection vulnerability in Easyvista Service Manager 2020.2.125.3/2022.1.109.0.03
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03.
network
low complexity
easyvista CWE-89
8.8
2023-01-10 CVE-2022-38492 SQL Injection vulnerability in Easyvista Service Manager 2020.2.125.3/2022.1.109.0.03
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03.
network
low complexity
easyvista CWE-89
8.8
2023-01-10 CVE-2022-45165 SQL Injection vulnerability in Archibus web Central 2022.03.01.107
An issue was discovered in Archibus Web Central 2022.03.01.107.
network
low complexity
archibus CWE-89
8.8
2023-01-10 CVE-2022-46163 SQL Injection vulnerability in Opensuse Travel Support Program
Travel support program is a rails app to support the travel support program of openSUSE (TSP).
network
low complexity
opensuse CWE-89
7.5
2023-01-10 CVE-2023-0016 SQL Injection vulnerability in SAP Business Planning and Consolidation 800/810
SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries.
network
low complexity
sap CWE-89
8.8
2023-01-09 CVE-2022-47790 SQL Injection vulnerability in Dynamic Transaction Queuing System Project Dynamic Transaction Queuing System 1.0
Sourcecodester Dynamic Transaction Queuing System v1.0 is vulnerable to SQL Injection via /queuing/index.php?page=display&id=.
network
low complexity
dynamic-transaction-queuing-system-project CWE-89
critical
9.8
2023-01-08 CVE-2018-25072 SQL Injection vulnerability in Lojban Jbovlaste
A vulnerability classified as critical has been found in lojban jbovlaste.
network
low complexity
lojban CWE-89
critical
9.8
2023-01-08 CVE-2019-25100 SQL Injection vulnerability in Twmap Project Twmap
A vulnerability was found in happyman twmap.
network
low complexity
twmap-project CWE-89
critical
9.8