Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-09-26 CVE-2022-40403 SQL Injection vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit.php.
network
low complexity
wedding-planner-project CWE-89
7.2
2022-09-26 CVE-2022-40404 SQL Injection vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/select.php.
network
low complexity
wedding-planner-project CWE-89
8.8
2022-09-26 CVE-2022-40926 SQL Injection vulnerability in Online Leave Management System Project Online Leave Management System 1.0
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_leave_type.
7.2
2022-09-26 CVE-2022-40927 SQL Injection vulnerability in Online Leave Management System Project Online Leave Management System 1.0
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_designation.
7.2
2022-09-26 CVE-2022-40928 SQL Injection vulnerability in Online Leave Management System Project Online Leave Management System 1.0
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_application.
7.2
2022-09-23 CVE-2022-40113 SQL Injection vulnerability in Online Banking System Project Online Banking System 1.0
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds.php.
network
low complexity
online-banking-system-project CWE-89
critical
9.8
2022-09-23 CVE-2022-40114 SQL Injection vulnerability in Online Banking System Project Online Banking System 1.0
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer.php.
network
low complexity
online-banking-system-project CWE-89
critical
9.8
2022-09-23 CVE-2022-40115 SQL Injection vulnerability in Online Banking System Project Online Banking System 1.0
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_beneficiary.php.
network
low complexity
online-banking-system-project CWE-89
critical
9.8
2022-09-23 CVE-2022-40116 SQL Injection vulnerability in Online Banking System Project Online Banking System 1.0
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/beneficiary.php.
network
low complexity
online-banking-system-project CWE-89
critical
9.8
2022-09-23 CVE-2022-40117 SQL Injection vulnerability in Online Banking System Project Online Banking System 1.0
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_customer.php.
network
low complexity
online-banking-system-project CWE-89
critical
9.8