Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-07-19 CVE-2024-6901 SQL Injection vulnerability in Jkev Record Management System 1.0
A vulnerability classified as critical has been found in SourceCodester Record Management System 1.0.
network
low complexity
jkev CWE-89
8.8
2024-07-19 CVE-2024-6205 SQL Injection vulnerability in Payplus Payment Gateway
The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a WooCommerce API route available to unauthenticated users, leading to an SQL injection vulnerability.
network
low complexity
payplus CWE-89
critical
9.8
2024-07-19 CVE-2024-6899 SQL Injection vulnerability in Jkev Record Management System 1.0
A vulnerability was found in SourceCodester Record Management System 1.0.
network
low complexity
jkev CWE-89
critical
9.8
2024-07-18 CVE-2024-0857 SQL Injection vulnerability in Uni-Yaz Flexwater Corporate Water Management
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software Inc.
network
low complexity
uni-yaz CWE-89
critical
9.8
2024-07-17 CVE-2024-6808 SQL Injection vulnerability in Code-Projects Simple Task List 1.0
A vulnerability was found in itsourcecode Simple Task List 1.0.
network
low complexity
code-projects CWE-89
critical
9.8
2024-07-17 CVE-2024-6803 SQL Injection vulnerability in Document Management System Project Document Management System 1.0
A vulnerability has been found in itsourcecode Document Management System 1.0 and classified as critical.
network
low complexity
document-management-system-project CWE-89
critical
9.8
2024-07-17 CVE-2024-6802 SQL Injection vulnerability in Computer Laboratory Management System Project Computer Laboratory Management System 1.0
A vulnerability, which was classified as critical, was found in SourceCodester Computer Laboratory Management System 1.0.
network
low complexity
computer-laboratory-management-system-project CWE-89
critical
9.8
2024-07-16 CVE-2024-40637 SQL Injection vulnerability in Getdbt DBT Core
dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications.
local
low complexity
getdbt CWE-89
7.8
2024-07-16 CVE-2024-40393 SQL Injection vulnerability in Angeljudesuarez Online Clinic Management System 1.0
Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user parameter at login.php.
network
low complexity
angeljudesuarez CWE-89
critical
9.8
2024-07-16 CVE-2024-40322 SQL Injection vulnerability in Jfinalcms Project Jfinalcms 5.0.0
An issue was discovered in JFinalCMS v.5.0.0.
network
low complexity
jfinalcms-project CWE-89
8.8