Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-10-09 CVE-2024-9465 SQL Injection vulnerability in Paloaltonetworks Expedition
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys.
network
low complexity
paloaltonetworks CWE-89
critical
9.1
2024-10-08 CVE-2024-43468 Microsoft Configuration Manager Remote Code Execution Vulnerability
network
low complexity
CWE-89
critical
9.8
2024-10-08 CVE-2024-9379 SQL Injection vulnerability in Ivanti Endpoint Manager Cloud Services Appliance 4.5/4.6
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
network
low complexity
ivanti CWE-89
7.2
2024-10-08 CVE-2024-8911 The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, and including, 5.0.11.
network
low complexity
CWE-89
critical
9.8
2024-10-07 CVE-2024-9573 SQL Injection vulnerability in Soplanning
SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which could allow a remote user to send a specially crafted query and extract all the information stored on the server.
network
low complexity
soplanning CWE-89
6.5
2024-10-07 CVE-2024-9574 SQL Injection vulnerability in Soplanning
SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.
network
low complexity
soplanning CWE-89
6.5
2024-10-06 CVE-2024-9560 SQL Injection vulnerability in Esafenet CDG 5
A vulnerability was found in ESAFENET CDG V5.
network
low complexity
esafenet CWE-89
8.8
2024-10-05 CVE-2024-47849 SQL Injection vulnerability in Mediawiki Cargo 3.6.0
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows SQL Injection.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.
network
low complexity
mediawiki CWE-89
critical
9.8
2024-10-04 CVE-2024-7801 SQL Injection vulnerability in Microchip Timeprovider 4100 Firmware
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules) allows SQL Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.
low complexity
microchip CWE-89
6.5
2024-10-03 CVE-2024-42417 SQL Injection vulnerability in Deltaww Diaenergie
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx.
network
low complexity
deltaww CWE-89
8.8