Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-09-19 CVE-2024-46382 SQL Injection vulnerability in Linlinjava Litemall 1.8.0
A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via the goodsId, goodsSn, and name parameters in AdminGoodscontroller.java.
network
low complexity
linlinjava CWE-89
7.5
2024-09-18 CVE-2022-25775 SQL Injection vulnerability in Acquia Mautic
Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems.
network
low complexity
acquia CWE-89
7.2
2024-09-18 CVE-2024-5958 SQL Injection vulnerability in Elizsoftware Panel
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eliz Software Panel allows Command Line Execution through SQL Injection.This issue affects Panel: before v2.3.24.
network
low complexity
elizsoftware CWE-89
8.8
2024-09-17 CVE-2024-43976 SQL Injection vulnerability in Superstorefinder Super Store Finder
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection.This issue affects Super Store Finder: from n/a through 6.9.7.
network
low complexity
superstorefinder CWE-89
critical
9.8
2024-09-17 CVE-2024-43978 SQL Injection vulnerability in Superstorefinder Super Store Finder
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injection.This issue affects Super Store Finder: from n/a before 6.9.8.
network
low complexity
superstorefinder CWE-89
critical
9.8
2024-09-17 CVE-2024-44004 SQL Injection vulnerability in Wptaskforce Track & Trace
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTaskForce WPCargo Track & Trace allows SQL Injection.This issue affects WPCargo Track & Trace: from n/a through 7.0.6.
network
low complexity
wptaskforce CWE-89
critical
9.8
2024-09-17 CVE-2024-8944 SQL Injection vulnerability in Fabianros Hospital Management System 1.0
A vulnerability, which was classified as critical, was found in code-projects Hospital Management System 1.0.
network
low complexity
fabianros CWE-89
critical
9.8
2024-09-17 CVE-2024-8945 SQL Injection vulnerability in Fairsketch Rise Ultimate Project Manager 3.7.0
A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical.
network
low complexity
fairsketch CWE-89
8.8
2024-09-16 CVE-2024-6401 SQL Injection vulnerability in SFS Insuree GL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting InsureE GL allows SQL Injection.This issue affects InsureE GL: before 4.6.2.
network
low complexity
sfs CWE-89
critical
9.8
2024-09-15 CVE-2024-8868 SQL Injection vulnerability in Code-Projects Crud Operation System 1.0
A vulnerability was found in code-projects Crud Operation System 1.0.
network
low complexity
code-projects CWE-89
critical
9.8