Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-07-26 CVE-2022-34989 SQL Injection vulnerability in Fruits Bazar Project Fruits Bazar 1.0
Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_password_recover.php.
network
low complexity
fruits-bazar-project CWE-89
critical
9.8
2022-07-26 CVE-2022-36161 SQL Injection vulnerability in Garage Management System Project Garage Management System 1.0
Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
network
low complexity
garage-management-system-project CWE-89
critical
9.8
2022-07-25 CVE-2022-29709 SQL Injection vulnerability in Communilink Clink Office 2.0
CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.
network
low complexity
communilink CWE-89
7.5
2022-07-22 CVE-2022-34114 SQL Injection vulnerability in Dataease Project Dataease 1.11.1
Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.
network
low complexity
dataease-project CWE-89
8.8
2022-07-20 CVE-2022-34586 SQL Injection vulnerability in Advanced School Management System Project Advanced School Management System 1.0
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/student_grade_wise.php.
8.8
2022-07-20 CVE-2022-34588 SQL Injection vulnerability in Advanced School Management System Project Advanced School Management System 1.0
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/timetable_insert_form.php.
8.8
2022-07-20 CVE-2022-34590 SQL Injection vulnerability in Hospital Management System Project Hospital Management System 1.0
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php.
7.2
2022-07-20 CVE-2022-34042 SQL Injection vulnerability in Barangay Management System Project Barangay Management System 1.0
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/household/household.php.
7.2
2022-07-20 CVE-2022-2489 SQL Injection vulnerability in Simple E-Learning System Project Simple E-Learning System 1.0
A vulnerability was found in SourceCodester Simple E-Learning System 1.0.
network
low complexity
simple-e-learning-system-project CWE-89
8.8
2022-07-20 CVE-2022-2490 SQL Injection vulnerability in Simple E-Learning System Project Simple E-Learning System 1.0
A vulnerability classified as critical has been found in SourceCodester Simple E-Learning System 1.0.
network
low complexity
simple-e-learning-system-project CWE-89
8.8