Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-11-17 CVE-2022-44402 SQL Injection vulnerability in Automotive Shop Management System Project Automotive Shop Management System 1.0
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_transaction.
7.2
2022-11-17 CVE-2022-44403 SQL Injection vulnerability in Automotive Shop Management System Project Automotive Shop Management System 1.0
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=user/manage_user&id=.
7.2
2022-11-17 CVE-2022-4051 SQL Injection vulnerability in Hostel Searching Project Hostel Searching Project
A vulnerability has been found in Hostel Searching Project and classified as critical.
network
low complexity
hostel-searching-project CWE-89
critical
9.8
2022-11-17 CVE-2022-4052 SQL Injection vulnerability in Student Attendance Management System Project Student Attendance Management System
A vulnerability was found in Student Attendance Management System and classified as critical.
7.2
2022-11-17 CVE-2022-42245 SQL Injection vulnerability in Dreamer CMS Project Dreamer CMS 4.0.01
Dreamer CMS 4.0.01 is vulnerable to SQL Injection.
network
low complexity
dreamer-cms-project CWE-89
critical
9.8
2022-11-17 CVE-2021-38819 SQL Injection vulnerability in Simple Image Gallery web APP Project Simple Image Gallery web APP
A SQL injection vulnerability exits on the Simple Image Gallery System 1.0 application through "id" parameter on the album page.
8.8
2022-11-16 CVE-2022-44003 SQL Injection vulnerability in Backclick 5.9.63
An issue was discovered in BACKCLICK Professional 5.9.63.
network
low complexity
backclick CWE-89
critical
9.8
2022-11-16 CVE-2022-43135 SQL Injection vulnerability in Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System 1.0
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php.
9.8
2022-11-16 CVE-2022-43256 SQL Injection vulnerability in Seacms
SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.
network
low complexity
seacms CWE-89
critical
9.8
2022-11-16 CVE-2022-43262 SQL Injection vulnerability in Oretnom23 Human Resource Management System 1.0
Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /hrm/controller/login.php.
network
low complexity
oretnom23 CWE-89
critical
9.8