Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-06-16 CVE-2022-31384 SQL Injection vulnerability in PHPgurukul Directory Management System 1.0
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
network
low complexity
phpgurukul CWE-89
critical
9.8
2022-06-16 CVE-2022-31908 SQL Injection vulnerability in Student Registration and FEE Payment System Project Student Registration and FEE Payment System 1.0
Student Registration and Fee Payment System v1.0 is vulnerable to SQL Injection via /scms/student.php.
7.2
2022-06-16 CVE-2022-31911 SQL Injection vulnerability in Online Discussion Forum Site Project Online Discussion Forum Site 1.0
Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team.
7.2
2022-06-16 CVE-2022-31912 SQL Injection vulnerability in Online Tutor Portal Site Project Online Tutor Portal Site 1.0
Online Tutor Portal Site v1.0 is vulnerable to SQL Injection via /otps/classes/Master.php?f=delete_team.
network
low complexity
online-tutor-portal-site-project CWE-89
7.2
2022-06-16 CVE-2021-41654 SQL Injection vulnerability in Wuzhicms 4.1.0
SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php
network
low complexity
wuzhicms CWE-89
critical
9.8
2022-06-15 CVE-2022-32370 SQL Injection vulnerability in Advanced School Management System Project Advanced School Management System 1.0
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_classroom.php?id=.
7.2
2022-06-15 CVE-2022-32371 SQL Injection vulnerability in Advanced School Management System Project Advanced School Management System 1.0
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_teacher.php?id=.
7.2
2022-06-15 CVE-2022-32372 SQL Injection vulnerability in Advanced School Management System Project Advanced School Management System 1.0
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_subject.php?id=.
7.2
2022-06-15 CVE-2022-32368 SQL Injection vulnerability in Advanced School Management System Project Advanced School Management System 1.0
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_grade.php?id=.
7.2
2022-06-15 CVE-2022-32373 SQL Injection vulnerability in Advanced School Management System Project Advanced School Management System 1.0
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_exam.php?id=.
7.2