Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-10-30 CVE-2024-10502 SQL Injection vulnerability in Esafenet CDG 5
A vulnerability has been found in ESAFENET CDG 5 and classified as critical.
network
low complexity
esafenet CWE-89
8.8
2024-10-29 CVE-2024-8924 SQL Injection vulnerability in Servicenow Vancouver/Xanadu
ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform.
network
low complexity
servicenow CWE-89
7.5
2024-10-29 CVE-2024-7042 SQL Injection vulnerability in Langchain
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection.
network
low complexity
langchain CWE-89
critical
9.8
2024-10-28 CVE-2024-10449 SQL Injection vulnerability in Codezips Hospital Appointment System 1.0
A vulnerability, which was classified as critical, was found in Codezips Hospital Appointment System 1.0.
network
low complexity
codezips CWE-89
critical
9.8
2024-10-28 CVE-2024-10447 SQL Injection vulnerability in Projectworlds Online Time Table Generator 1.0
A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0.
network
low complexity
projectworlds CWE-89
8.8
2024-10-28 CVE-2024-50465 SQL Injection vulnerability in Squirrly Premium SEO Pack
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP SEO – Calin Vingan Premium SEO Pack allows SQL Injection.This issue affects Premium SEO Pack: from n/a through 1.6.001.
network
low complexity
squirrly CWE-89
6.5
2024-10-28 CVE-2024-50479 SQL Injection vulnerability in Mansurahamed Woocommerce Quote Calculator
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocommerce Quote Calculator: from n/a through 1.1.
network
low complexity
mansurahamed CWE-89
critical
9.8
2024-10-28 CVE-2024-50491 SQL Injection vulnerability in Micahblu Rsvp ME
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Micah Blu RSVP ME allows SQL Injection.This issue affects RSVP ME: from n/a through 1.9.9.
network
low complexity
micahblu CWE-89
critical
9.8
2024-10-28 CVE-2024-10446 SQL Injection vulnerability in Projectworlds Online Time Table Generator 1.0
A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0.
network
low complexity
projectworlds CWE-89
7.2
2024-10-28 CVE-2024-10440 SQL Injection vulnerability in Sun.Net Ehdr Ctms
The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modify, and delete database contents.
network
low complexity
sun-net CWE-89
critical
9.8