Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-11-12 CVE-2022-43672 SQL Injection vulnerability in Zohocorp products
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.
network
low complexity
zohocorp CWE-89
critical
9.8
2022-11-11 CVE-2022-3955 SQL Injection vulnerability in Crm42 Project Crm42
A vulnerability was found in tholum crm42.
network
low complexity
crm42-project CWE-89
critical
9.8
2022-11-11 CVE-2022-3956 SQL Injection vulnerability in Hhims Project Hhims 2.1
A vulnerability classified as critical has been found in tsruban HHIMS 2.1.
network
low complexity
hhims-project CWE-89
critical
9.8
2022-11-11 CVE-2022-3947 SQL Injection vulnerability in Eolink Goku Lite
A vulnerability classified as critical has been found in eolinker goku_lite.
network
low complexity
eolink CWE-89
critical
9.8
2022-11-11 CVE-2022-3948 SQL Injection vulnerability in Eolink Goku Lite
A vulnerability classified as critical was found in eolinker goku_lite.
network
low complexity
eolink CWE-89
critical
9.8
2022-11-11 CVE-2022-41892 SQL Injection vulnerability in Archesproject Arches
Arches is a web platform for creating, managing, & visualizing geospatial data.
network
low complexity
archesproject CWE-89
critical
9.8
2022-11-10 CVE-2022-44727 SQL Injection vulnerability in Lineagrafica EU Cookie LAW Gdpr
The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).
network
low complexity
lineagrafica CWE-89
critical
9.1
2022-11-09 CVE-2022-43058 SQL Injection vulnerability in Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System 1.0
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity.
9.8
2022-11-09 CVE-2022-43278 SQL Injection vulnerability in Canteen Management System Project Canteen Management System 1.0
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the categoriesId parameter at /php_action/fetchSelectedCategories.php.
network
low complexity
canteen-management-system-project CWE-89
7.2
2022-11-09 CVE-2022-43290 SQL Injection vulnerability in Canteen Management System Project Canteen Management System 1.0
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /youthappam/editcategory.php.
network
low complexity
canteen-management-system-project CWE-89
7.2