Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-09-02 CVE-2022-36754 SQL Injection vulnerability in Oretnom23 Expense Management System 1.0
Expense Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Home/debit_credit_p.
network
low complexity
oretnom23 CWE-89
7.2
2022-09-02 CVE-2020-22669 SQL Injection vulnerability in multiple products
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability.
network
low complexity
owasp debian CWE-89
critical
9.8
2022-09-02 CVE-2022-36609 SQL Injection vulnerability in Oretnom23 Clinic'S Patient Management System 1.0
Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php.
network
low complexity
oretnom23 CWE-89
critical
9.8
2022-09-02 CVE-2022-36636 SQL Injection vulnerability in Garage Management System Project Garage Management System 1.0
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php.
network
low complexity
garage-management-system-project CWE-89
8.8
2022-09-02 CVE-2022-36594 SQL Injection vulnerability in Mybatis Mapper
Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds function.
network
low complexity
mybatis CWE-89
critical
9.8
2022-09-02 CVE-2022-36759 SQL Injection vulnerability in Online Food Ordering System Project Online Food Ordering System 1.0
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=.
network
low complexity
online-food-ordering-system-project CWE-89
critical
9.8
2022-09-01 CVE-2022-36674 SQL Injection vulnerability in Simple Task Scheduling System Project Simple Task Scheduling System 1.0
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /schedules/view_schedule.php.
7.2
2022-09-01 CVE-2022-36675 SQL Injection vulnerability in Simple Task Scheduling System Project Simple Task Scheduling System 1.0
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /schedules/manage_schedule.php.
7.2
2022-09-01 CVE-2022-36676 SQL Injection vulnerability in Simple Task Scheduling System Project Simple Task Scheduling System 1.0
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/view_category.php.
7.2
2022-08-31 CVE-2022-36201 SQL Injection vulnerability in Doctor'S Appointment System Project Doctor'S Appointment System 1.0
Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php.
network
low complexity
doctor-s-appointment-system-project CWE-89
critical
9.8