Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-10-31 CVE-2022-3059 SQL Injection vulnerability in Schoolbox 21.0.2
The application was vulnerable to multiple instances of SQL injection (authenticated and unauthenticated) through a vulnerable parameter.
network
low complexity
schoolbox CWE-89
7.5
2022-10-31 CVE-2022-41680 SQL Injection vulnerability in Formalms
Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability.
network
low complexity
formalms CWE-89
6.5
2022-10-31 CVE-2022-42923 SQL Injection vulnerability in Formalms
Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability.
network
low complexity
formalms CWE-89
8.8
2022-10-31 CVE-2022-42924 SQL Injection vulnerability in Formalms
Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability.
network
low complexity
formalms CWE-89
6.5
2022-10-28 CVE-2021-36898 SQL Injection vulnerability in Expresstech Quiz and Survey Master
Auth.
network
low complexity
expresstech CWE-89
7.2
2022-10-28 CVE-2022-43228 SQL Injection vulnerability in Barangay Management System Project Barangay Management System 1.0
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /clearance/clearance.php.
7.2
2022-10-28 CVE-2022-43229 SQL Injection vulnerability in Simple Cold Storage Management System Project Simple Cold Storage Managment System 1.0
Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /bookings/update_status.php.
7.2
2022-10-28 CVE-2022-43230 SQL Injection vulnerability in Simple Cold Storage Management System Project Simple Cold Storage Managment System 1.0
Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=bookings/view_details.
7.2
2022-10-28 CVE-2022-43232 SQL Injection vulnerability in Canteen Management System Project Canteen Management System 1.0
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchOrderData.php.
network
low complexity
canteen-management-system-project CWE-89
7.2
2022-10-28 CVE-2022-43233 SQL Injection vulnerability in Canteen Management System Project Canteen Management System 1.0
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchSelectedUser.php.
network
low complexity
canteen-management-system-project CWE-89
7.2