Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-09-23 CVE-2022-40119 SQL Injection vulnerability in Online Banking System Project Online Banking System 1.0
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/transactions.php.
network
low complexity
online-banking-system-project CWE-89
critical
9.8
2022-09-23 CVE-2022-40120 SQL Injection vulnerability in Online Banking System Project Online Banking System 1.0
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/customer_transactions.php.
network
low complexity
online-banking-system-project CWE-89
critical
9.8
2022-09-23 CVE-2022-40121 SQL Injection vulnerability in Online Banking System Project Online Banking System 1.0
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/manage_customers.php.
network
low complexity
online-banking-system-project CWE-89
critical
9.8
2022-09-23 CVE-2022-40122 SQL Injection vulnerability in Online Banking System Project Online Banking System 1.0
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer_action.php.
network
low complexity
online-banking-system-project CWE-89
critical
9.8
2022-09-23 CVE-2022-32211 SQL Injection vulnerability in Rocket.Chat
A SQL injection vulnerability exists in Rocket.Chat <v3.18.6, <v4.4.4 and <v4.7.3 which can allow an attacker to retrieve a reset password token through or a 2fa secret.
network
low complexity
rocket-chat CWE-89
8.8
2022-09-23 CVE-2022-40091 SQL Injection vulnerability in Online Tours and Travels Management System Project Online Tours and Travels Management System 1.0
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_packages.php.
7.2
2022-09-23 CVE-2022-40092 SQL Injection vulnerability in Online Tours and Travels Management System Project Online Tours and Travels Management System 1.0
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_payment.php.
7.2
2022-09-23 CVE-2022-40093 SQL Injection vulnerability in Online Tours and Travels Management System Project Online Tours and Travels Management System 1.0
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_tax.php.
7.2
2022-09-22 CVE-2022-40933 SQL Injection vulnerability in Online PET Shop web Application Project Online PET Shop web Application 1.0
Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,id.
7.2
2022-09-22 CVE-2022-40934 SQL Injection vulnerability in Online PET Shop web Application Project Online PET Shop web Application 1.0
Online Pet Shop We App v1.0 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_sub_category,id
7.2