Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-09-09 CVE-2024-8611 SQL Injection vulnerability in Angeljudesuarez Tailoring Management System 1.0
A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0.
network
low complexity
angeljudesuarez CWE-89
critical
9.8
2024-09-09 CVE-2024-6795 SQL Injection vulnerability in Baxter Connex Health Portal
In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database.  An attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and disclosure of database content and/or perform administrative operations including shutting down the database.
network
low complexity
baxter CWE-89
critical
9.8
2024-09-08 CVE-2024-8570 SQL Injection vulnerability in Angeljudesuarez Tailoring Management System 1.0
A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical.
network
low complexity
angeljudesuarez CWE-89
critical
9.8
2024-09-08 CVE-2024-6924 SQL Injection vulnerability in Themetechmount Truebooker
The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
network
low complexity
themetechmount CWE-89
critical
9.8
2024-09-08 CVE-2024-6928 SQL Injection vulnerability in Opti.Marketing Opti Marketing
The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
network
low complexity
opti-marketing CWE-89
critical
9.8
2024-09-08 CVE-2024-8569 SQL Injection vulnerability in Fabianros Hospital Management System 1.0
A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical.
network
low complexity
fabianros CWE-89
critical
9.8
2024-09-08 CVE-2024-8568 SQL Injection vulnerability in Project Team Tmall Demo
A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901.
network
low complexity
project-team CWE-89
critical
9.8
2024-09-08 CVE-2024-8567 SQL Injection vulnerability in Payroll Management System Project Payroll Management System 1.0
A vulnerability, which was classified as critical, has been found in itsourcecode Payroll Management System 1.0.
network
low complexity
payroll-management-system-project CWE-89
critical
9.8
2024-09-07 CVE-2024-8565 SQL Injection vulnerability in Oretnom23 Clinic'S Patient Management System 2.0
A vulnerability was found in SourceCodesters Clinics Patient Management System 2.0.
network
low complexity
oretnom23 CWE-89
critical
9.8
2024-09-07 CVE-2024-8564 SQL Injection vulnerability in Rems PHP Crud 1.0
A vulnerability was found in SourceCodester PHP CRUD 1.0.
network
low complexity
rems CWE-89
8.8