Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-10-03 CVE-2024-43699 SQL Injection vulnerability in Deltaww Diaenergie
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx.
network
low complexity
deltaww CWE-89
critical
9.8
2024-10-03 CVE-2024-9460 SQL Injection vulnerability in Codezips Online Shopping Portal 1.0
A vulnerability was found in Codezips Online Shopping Portal 1.0.
network
low complexity
codezips CWE-89
critical
9.8
2024-10-02 CVE-2024-9429 SQL Injection vulnerability in Code-Projects Restaurant Reservation System 1.0
A vulnerability has been found in code-projects Restaurant Reservation System 1.0 and classified as critical.
network
low complexity
code-projects CWE-89
critical
9.8
2024-10-01 CVE-2024-45999 SQL Injection vulnerability in Magicbug Cloudlog
A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php.
network
low complexity
magicbug CWE-89
critical
9.8
2024-10-01 CVE-2024-9018 SQL Injection vulnerability in Plugingarden WP Easy Gallery
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
plugingarden CWE-89
8.8
2024-10-01 CVE-2024-9360 SQL Injection vulnerability in Code-Projects Restaurant Reservation System 1.0
A vulnerability was found in code-projects Restaurant Reservation System 1.0.
network
low complexity
code-projects CWE-89
critical
9.8
2024-10-01 CVE-2024-9359 SQL Injection vulnerability in Code-Projects Restaurant Reservation System 1.0
A vulnerability was found in code-projects Restaurant Reservation System 1.0 and classified as critical.
network
low complexity
code-projects CWE-89
critical
9.8
2024-09-30 CVE-2024-8379 SQL Injection vulnerability in Stylemixthemes Cost Calculator Builder
The Cost Calculator Builder WordPress plugin before 3.2.29 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.
network
low complexity
stylemixthemes CWE-89
7.2
2024-09-29 CVE-2024-9328 SQL Injection vulnerability in Mayurik Advocate Office Management System 1.0
A vulnerability was found in SourceCodester Advocate Office Management System 1.0.
network
low complexity
mayurik CWE-89
critical
9.8
2024-09-29 CVE-2024-9327 SQL Injection vulnerability in Code-Projects Blood Bank System 1.0
A vulnerability was found in code-projects Blood Bank System 1.0.
network
low complexity
code-projects CWE-89
critical
9.8