Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-08-30 CVE-2022-36712 SQL Injection vulnerability in Library Management System Project Library Management System 1.0
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/studentdetails.php.
network
low complexity
library-management-system-project CWE-89
critical
9.8
2022-08-30 CVE-2022-36713 SQL Injection vulnerability in Library Management System Project Library Management System 1.0
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /librarian/lab.php.
network
low complexity
library-management-system-project CWE-89
critical
9.8
2022-08-30 CVE-2022-36714 SQL Injection vulnerability in Library Management System Project Library Management System 1.0
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /staff/lab.php.
network
low complexity
library-management-system-project CWE-89
critical
9.8
2022-08-29 CVE-2022-36686 SQL Injection vulnerability in Ingredient Stock Management System Project Ingredient Stock Management System 1.0
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/stockin&month=.
8.8
2022-08-29 CVE-2022-36688 SQL Injection vulnerability in Ingredient Stock Management System Project Ingredient Stock Management System 1.0
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/stockout&month=.
8.8
2022-08-29 CVE-2022-36689 SQL Injection vulnerability in Ingredient Stock Management System Project Ingredient Stock Management System 1.0
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/waste&month=.
8.8
2022-08-29 CVE-2022-36690 SQL Injection vulnerability in Ingredient Stock Management System Project Ingredient Stock Management System 1.0
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user&id=.
8.8
2022-08-29 CVE-2022-22897 SQL Injection vulnerability in Apollotheme AP Pagebuilder 2.4.4/2.4.5
A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data.
network
low complexity
apollotheme CWE-89
critical
9.8
2022-08-28 CVE-2022-36704 SQL Injection vulnerability in Library Management System Project Library Management System 1.0
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /librarian/studentdetails.php.
network
low complexity
library-management-system-project CWE-89
8.8
2022-08-28 CVE-2022-36705 SQL Injection vulnerability in Ingredients Stock Management System Project Ingredients Stock Management System 1.0
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_waste.php.
network
low complexity
ingredients-stock-management-system-project CWE-89
critical
9.8