Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-10-28 CVE-2021-38730 SQL Injection vulnerability in Sem-Cms Semcms 1.1
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
network
low complexity
sem-cms CWE-89
critical
9.8
2022-10-28 CVE-2021-38731 SQL Injection vulnerability in Sem-Cms Semcms 1.1
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
network
low complexity
sem-cms CWE-89
critical
9.8
2022-10-28 CVE-2021-38732 SQL Injection vulnerability in Sem-Cms Semcms 1.1
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
network
low complexity
sem-cms CWE-89
critical
9.8
2022-10-28 CVE-2021-38733 SQL Injection vulnerability in Sem-Cms Semcms 1.1
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
network
low complexity
sem-cms CWE-89
critical
9.8
2022-10-28 CVE-2021-35387 SQL Injection vulnerability in PHPgurukul Hospital Management System 4.0
Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.
network
low complexity
phpgurukul CWE-89
8.8
2022-10-28 CVE-2021-37782 SQL Injection vulnerability in PHPgurukul Employee Record Management System 1.2
Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.
network
low complexity
phpgurukul CWE-89
critical
9.8
2022-10-28 CVE-2021-38734 SQL Injection vulnerability in Sem-Cms Semcms 1.1
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.
network
low complexity
sem-cms CWE-89
critical
9.8
2022-10-28 CVE-2021-38736 SQL Injection vulnerability in Sem-Cms Semcms 1.1
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
network
low complexity
sem-cms CWE-89
critical
9.8
2022-10-28 CVE-2021-38737 SQL Injection vulnerability in Sem-Cms Semcms 1.1
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
network
low complexity
sem-cms CWE-89
critical
9.8
2022-10-28 CVE-2022-43276 SQL Injection vulnerability in Canteen Management System Project Canteen Management System 1.0
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /php_action/fetchSelectedfood.php.
network
low complexity
canteen-management-system-project CWE-89
7.2