Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-06-14 CVE-2022-32348 SQL Injection vulnerability in Hospital'S Patient Records Management System Project Hospital'S Patient Records Management System 1.0
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_doctor.
7.2
2022-06-14 CVE-2022-32349 SQL Injection vulnerability in Hospital'S Patient Records Management System Project Hospital'S Patient Records Management System 1.0
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_history.
7.2
2022-06-14 CVE-2022-32350 SQL Injection vulnerability in Hospital'S Patient Records Management System Project Hospital'S Patient Records Management System 1.0
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_room_type.
7.2
2022-06-14 CVE-2022-32351 SQL Injection vulnerability in Hospital'S Patient Records Management System Project Hospital'S Patient Records Management System 1.0
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_message.
7.2
2022-06-14 CVE-2022-32352 SQL Injection vulnerability in Hospital'S Patient Records Management System Project Hospital'S Patient Records Management System 1.0
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_admission.
9.8
2022-06-14 CVE-2022-32336 SQL Injection vulnerability in Fast Food Ordering System Project Fast Food Ordering System 1.0
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=.
network
low complexity
fast-food-ordering-system-project CWE-89
critical
9.8
2022-06-14 CVE-2022-31415 SQL Injection vulnerability in Online Fire Reporting System Project Online Fire Reporting System 1.0
Online Fire Reporting System v1.0 was discovered to contain a SQL injection vulnerability via the GET parameter in /report/list.php.
6.5
2022-06-13 CVE-2021-41661 SQL Injection vulnerability in Church Management System Project Church Management System 1.0
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory.
network
low complexity
church-management-system-project CWE-89
critical
9.8
2022-06-13 CVE-2021-41662 SQL Injection vulnerability in South Gate INN Online Reservation System Project South Gate INN Online Reservation System 1.0
The South Gate Inn Online Reservation System v1.0 contains an SQL injection vulnerability that can be chained with a malicious PHP file upload, which is caused by improper file handling in the editImg function.
9.8
2022-06-13 CVE-2022-23168 SQL Injection vulnerability in Amodat Mobile Application Gateway
The attacker could get access to the database.
network
low complexity
amodat CWE-89
critical
9.8