Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-09-27 CVE-2022-41570 SQL Injection vulnerability in Eyesofnetwork
An issue was discovered in EyesOfNetwork (EON) through 5.3.11.
network
low complexity
eyesofnetwork CWE-89
critical
9.8
2022-09-26 CVE-2022-40097 SQL Injection vulnerability in Online Tours and Travels Management System Project Online Tours and Travels Management System 1.0
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_currency.php.
7.2
2022-09-26 CVE-2022-40098 SQL Injection vulnerability in Online Tours & Travels Management System Project Online Tours & Travels Management System 1.0
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense.php.
7.2
2022-09-26 CVE-2022-40099 SQL Injection vulnerability in Online Tours & Travels Management System Project Online Tours & Travels Management System 1.0
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense_category.php.
7.2
2022-09-26 CVE-2022-30004 SQL Injection vulnerability in Online Market Place Site Project Online Market Place Site 1.0
Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..
network
low complexity
online-market-place-site-project CWE-89
critical
9.8
2022-09-26 CVE-2022-40043 SQL Injection vulnerability in Centreon 20.10.18
Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations.
network
low complexity
centreon CWE-89
8.8
2022-09-26 CVE-2022-40483 SQL Injection vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /wedding_details.php.
network
low complexity
wedding-planner-project CWE-89
critical
9.8
2022-09-26 CVE-2022-40484 SQL Injection vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php.
network
low complexity
wedding-planner-project CWE-89
critical
9.8
2022-09-26 CVE-2022-40485 SQL Injection vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php.
network
low complexity
wedding-planner-project CWE-89
critical
9.8
2022-09-26 CVE-2022-40402 SQL Injection vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_assign.php.
network
low complexity
wedding-planner-project CWE-89
8.8