Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-06-29 CVE-2022-33061 SQL Injection vulnerability in Online Railway Reservation System Project Online Railway Reservation System 1.0
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_service.
7.2
2022-06-29 CVE-2022-33042 SQL Injection vulnerability in Online Railway Reservation System Project Online Railway Reservation System 1.0
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/inquiries/view_details.php.
7.2
2022-06-28 CVE-2021-41460 SQL Injection vulnerability in Shopex Ecshop 4.1.0
ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
network
low complexity
shopex CWE-89
7.5
2022-06-28 CVE-2017-20104 SQL Injection vulnerability in Simplessus 3.7.7
A vulnerability was found in Simplessus 3.7.7.
network
low complexity
simplessus CWE-89
7.5
2022-06-28 CVE-2022-34132 SQL Injection vulnerability in Jorani 1.0.0
Benjamin BALET Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php.
network
low complexity
jorani CWE-89
critical
9.8
2022-06-27 CVE-2017-20103 SQL Injection vulnerability in Wp-Kama Kama Click Counter
A vulnerability classified as critical has been found in Kama Click Counter Plugin up to 3.4.8.
network
low complexity
wp-kama CWE-89
8.8
2022-06-27 CVE-2022-31082 SQL Injection vulnerability in Glpi-Project Glpi Inventory 1.0.0/1.0.1
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.
network
low complexity
glpi-project CWE-89
critical
9.8
2022-06-25 CVE-2022-33128 SQL Injection vulnerability in Ruijienetworks Rg-Eg350 Firmware Egrgos11.1(6)
RG-EG series gateway EG350 EG_RGOS 11.1(6) was discovered to contain a SQL injection vulnerability via the function get_alarmAction at /alarm_pi/alarmService.php.
network
low complexity
ruijienetworks CWE-89
critical
9.1
2022-06-24 CVE-2022-22389 SQL Injection vulnerability in IBM DB2
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may terminate abnormally when executing specially crafted SQL statements by an authenticated user.
network
low complexity
ibm CWE-89
6.5
2022-06-24 CVE-2022-32391 SQL Injection vulnerability in Prison Management System Project Prison Management System 1.0
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/view_action.php:4
network
low complexity
prison-management-system-project CWE-89
8.8