Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-10-07 CVE-2022-36635 SQL Injection vulnerability in Zkteco Zkbiosecurity V5000 4.1.3
ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.
network
low complexity
zkteco CWE-89
8.8
2022-10-07 CVE-2022-41377 SQL Injection vulnerability in Online PET Shop WE APP Project Online PET Shop WE APP 1.0
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/admin/?page=maintenance/manage_category.
network
low complexity
online-pet-shop-we-app-project CWE-89
7.2
2022-10-07 CVE-2022-41378 SQL Injection vulnerability in Online PET Shop WE APP Project Online PET Shop WE APP 1.0
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/admin/?page=inventory/manage_inventory.
network
low complexity
online-pet-shop-we-app-project CWE-89
7.2
2022-10-07 CVE-2022-42073 SQL Injection vulnerability in Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System 1.0
Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editclient.php?id=.
7.2
2022-10-07 CVE-2022-42074 SQL Injection vulnerability in Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System 1.0
Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editcategory.php?id=.
7.2
2022-10-07 CVE-2022-41513 SQL Injection vulnerability in Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System 1.0
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /diagnostic/edittest.php.
7.2
2022-10-07 CVE-2022-41514 SQL Injection vulnerability in Open Source Sacco Management System Project Open Source Sacco Management System 1.0
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_loan.
7.2
2022-10-07 CVE-2022-41515 SQL Injection vulnerability in Open Source Sacco Management System Project Open Source Sacco Management System 1.0
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_payment.
7.2
2022-10-07 CVE-2022-40824 SQL Injection vulnerability in Codeigniter
B.C.
network
low complexity
codeigniter CWE-89
critical
9.8
2022-10-07 CVE-2022-40825 SQL Injection vulnerability in Codeigniter
B.C.
network
low complexity
codeigniter CWE-89
critical
9.8