Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-08-10 CVE-2022-36750 SQL Injection vulnerability in Oretnom23 Clinic'S Patient Management System 1.0
Clinic's Patient Management System v1.0 is vulnerable to SQL injection via /pms/update_user.php?id=.
network
low complexity
oretnom23 CWE-89
critical
9.8
2022-08-10 CVE-2022-38130 SQL Injection vulnerability in Keysight Sensor Management Server 2.4.0
The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS.
network
low complexity
keysight CWE-89
critical
9.8
2022-08-08 CVE-2022-2698 SQL Injection vulnerability in Simple E-Learning System Project Simple E-Learning System
A vulnerability was found in SourceCodester Simple E-Learning System.
network
low complexity
simple-e-learning-system-project CWE-89
critical
9.8
2022-08-08 CVE-2022-2706 SQL Injection vulnerability in Fabian Online Class and Exam Scheduling System 1.0
A vulnerability classified as critical has been found in SourceCodester Online Class and Exam Scheduling System 1.0.
network
low complexity
fabian CWE-89
critical
9.8
2022-08-08 CVE-2022-2707 SQL Injection vulnerability in Fabian Online Class and Exam Scheduling System 1.0
A vulnerability classified as critical was found in SourceCodester Online Class and Exam Scheduling System 1.0.
network
low complexity
fabian CWE-89
critical
9.8
2022-08-05 CVE-2022-2677 SQL Injection vulnerability in Apartment Visitors Management System Project Apartment Visitors Management System 1.0
A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0.
network
low complexity
apartment-visitors-management-system-project CWE-89
critical
9.8
2022-08-05 CVE-2022-31659 SQL Injection vulnerability in VMWare products
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability.
network
low complexity
vmware CWE-89
7.2
2022-08-05 CVE-2022-36839 SQL Injection vulnerability in Samsung Checkout
SQL injection vulnerability via IAPService in Samsung Checkout prior to version 5.0.53.1 allows attackers to access IAP information.
local
low complexity
samsung CWE-89
5.5
2022-08-03 CVE-2022-34968 SQL Injection vulnerability in Percona Server 8.0.2819
An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query.
network
low complexity
percona CWE-89
7.5
2022-08-03 CVE-2022-34928 SQL Injection vulnerability in Jflyfox Jfinal CMS 5.1.0
JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.
network
low complexity
jflyfox CWE-89
8.8