Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-10-26 CVE-2022-37202 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list
network
low complexity
jflyfox CWE-89
8.8
2022-10-26 CVE-2022-43774 SQL Injection vulnerability in Deltaww Diaenergie 1.9.0
The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.
network
low complexity
deltaww CWE-89
critical
9.8
2022-10-26 CVE-2022-43775 SQL Injection vulnerability in Deltaww Diaenergie 1.9.0
The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.
network
low complexity
deltaww CWE-89
critical
9.8
2022-10-26 CVE-2022-3671 SQL Injection vulnerability in Elearning System Project Elearning System 1.0
A vulnerability classified as critical was found in SourceCodester eLearning System 1.0.
network
low complexity
elearning-system-project CWE-89
critical
9.8
2022-10-26 CVE-2022-29822 SQL Injection vulnerability in Feathersjs Feathers-Sequelize
Due to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection
network
low complexity
feathersjs CWE-89
critical
9.8
2022-10-26 CVE-2022-2422 SQL Injection vulnerability in Feathersjs Feathers-Sequelize
Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the back-end database, in case the feathers-sequelize package is used.
network
low complexity
feathersjs CWE-89
critical
9.8
2022-10-20 CVE-2022-42021 SQL Injection vulnerability in Best Student Result Management System Project Best Student Result Management System 1.0
Best Student Result Management System v1.0 is vulnerable to SQL Injection via /upresult/upresult/notice-details.php?nid=.
network
low complexity
best-student-result-management-system-project CWE-89
critical
9.8
2022-10-19 CVE-2022-43020 SQL Injection vulnerability in Opencats 0.9.6
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.
network
low complexity
opencats CWE-89
6.5
2022-10-19 CVE-2022-43021 SQL Injection vulnerability in Opencats 0.9.6
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.
network
low complexity
opencats CWE-89
6.5
2022-10-19 CVE-2022-43022 SQL Injection vulnerability in Opencats 0.9.6
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.
network
low complexity
opencats CWE-89
6.5