Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-10-14 CVE-2022-42064 SQL Injection vulnerability in Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System 1.0
Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.
9.8
2022-10-14 CVE-2022-3504 SQL Injection vulnerability in Sanitization Management System Project Sanitization Management System
A vulnerability was found in SourceCodester Sanitization Management System and classified as critical.
network
low complexity
sanitization-management-system-project CWE-89
critical
9.8
2022-10-14 CVE-2022-3495 SQL Injection vulnerability in Simple Online Public Access Catalog Project Simple Online Public Access Catalog 1.0
A vulnerability has been found in SourceCodester Simple Online Public Access Catalog 1.0 and classified as critical.
7.2
2022-10-14 CVE-2022-41535 SQL Injection vulnerability in Open Source Sacco Management System Project Open Source Sacco Management System 1.0
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_borrower.php.
7.2
2022-10-14 CVE-2022-41536 SQL Injection vulnerability in Open Source Sacco Management System Project Open Source Sacco Management System 1.0
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_user.php.
7.2
2022-10-13 CVE-2022-34022 SQL Injection vulnerability in Resiot IOT Platform and Lorawan Network Server
SQL injection vulnerability in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via a crafted POST request to /ResiotQueryDBActive.
network
low complexity
resiot CWE-89
7.2
2022-10-13 CVE-2022-41390 SQL Injection vulnerability in Ocomon Project Ocomon 4.0
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php.
network
low complexity
ocomon-project CWE-89
critical
9.8
2022-10-13 CVE-2022-41391 SQL Injection vulnerability in Ocomon Project Ocomon 4.0
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php.
network
low complexity
ocomon-project CWE-89
critical
9.8
2022-10-13 CVE-2022-37208 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal CMS 5.1.0 is vulnerable to SQL Injection.
network
low complexity
jflyfox CWE-89
8.8
2022-10-13 CVE-2022-3470 SQL Injection vulnerability in Oretnom23 Human Resource Management System
A vulnerability was found in SourceCodester Human Resource Management System.
network
low complexity
oretnom23 CWE-89
6.5