Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-08-24 CVE-2022-37178 SQL Injection vulnerability in 72Crm Wukong CRM 9.0
An issue was discovered in 72crm 9.0.
network
low complexity
72crm CWE-89
8.8
2022-08-24 CVE-2022-37333 SQL Injection vulnerability in Exceedone Exment
SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows remote authenticated attackers to execute arbitrary SQL commands.
network
low complexity
exceedone CWE-89
8.8
2022-08-23 CVE-2022-35115 SQL Injection vulnerability in Icewarp Webclient DC2 13.0.2.9
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.
network
low complexity
icewarp CWE-89
critical
9.8
2022-08-23 CVE-2022-37111 SQL Injection vulnerability in Bluecms Project Bluecms 1.6
BlueCMS 1.6 has SQL injection in line 132 of admin/article.php
network
low complexity
bluecms-project CWE-89
critical
9.8
2022-08-23 CVE-2022-37112 SQL Injection vulnerability in Bluecms Project Bluecms 1.6
BlueCMS 1.6 has SQL injection in line 55 of admin/model.php
network
low complexity
bluecms-project CWE-89
critical
9.8
2022-08-23 CVE-2022-37113 SQL Injection vulnerability in Bluecms Project Bluecms 1.6
Bluecms 1.6 has SQL injection in line 132 of admin/area.php
network
low complexity
bluecms-project CWE-89
critical
9.8
2022-08-23 CVE-2022-37223 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.
network
low complexity
jflyfox CWE-89
critical
9.8
2022-08-23 CVE-2022-37199 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.
network
low complexity
jflyfox CWE-89
critical
9.8
2022-08-22 CVE-2022-36198 SQL Injection vulnerability in PHPgurukul BUS Pass Management System 1.0
Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category-detail.php, and buspassms/admin/edit-pass-detail.php
network
low complexity
phpgurukul CWE-89
critical
9.8
2022-08-19 CVE-2022-36578 SQL Injection vulnerability in Jizhicms 2.3.1
jizhicms v2.3.1 has SQL injection in the background.
network
low complexity
jizhicms CWE-89
critical
9.8