Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-09-13 CVE-2022-38539 SQL Injection vulnerability in Archerydms Archery
Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/apply.
network
low complexity
archerydms CWE-89
critical
9.8
2022-09-13 CVE-2022-38540 SQL Injection vulnerability in Archerydms Archery
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface.
network
low complexity
archerydms CWE-89
critical
9.8
2022-09-13 CVE-2022-38541 SQL Injection vulnerability in Archerydms Archery 1.8.3/1.8.4/1.8.5
Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface.
network
low complexity
archerydms CWE-89
critical
9.8
2022-09-13 CVE-2022-38542 SQL Injection vulnerability in Archerydms Archery
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill_session interface.
network
low complexity
archerydms CWE-89
critical
9.8
2022-09-13 CVE-2022-38616 SQL Injection vulnerability in Bpcbt Smartvista Front-End 2.2.22
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.jsf.
network
low complexity
bpcbt CWE-89
8.8
2022-09-12 CVE-2022-38302 SQL Injection vulnerability in Online Leave Management System Project Online Leave Management System 1.0
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /maintenance/manage_department.php.
7.2
2022-09-12 CVE-2022-38303 SQL Injection vulnerability in Online Leave Management System Project Online Leave Management System 1.0
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /employees/manage_leave_type.php.
7.2
2022-09-12 CVE-2022-38304 SQL Injection vulnerability in Online Leave Management System Project Online Leave Management System 1.0
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /maintenance/manage_leave_type.php.
7.2
2022-09-12 CVE-2022-38605 SQL Injection vulnerability in Church Management System Project Church Management System 1.0
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_event.php.
network
low complexity
church-management-system-project CWE-89
7.2
2022-09-12 CVE-2022-38606 SQL Injection vulnerability in Garage Management System Project Garage Management System 1.0
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editcategory.php.
network
low complexity
garage-management-system-project CWE-89
7.2