Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-11-20 CVE-2024-11487 SQL Injection vulnerability in Code4Berry Decoration Management System 1.0
A vulnerability has been found in Code4Berry Decoration Management System 1.0 and classified as critical.
network
low complexity
code4berry CWE-89
8.8
2024-11-20 CVE-2024-11179 SQL Injection vulnerability in Inspireui Mstore API
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via the 'status_type' parameter in all versions up to, and including, 4.15.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
inspireui CWE-89
6.5
2024-11-18 CVE-2024-52435 SQL Injection vulnerability in Wpdownloadmanager Premium Packages - Sell Digital products Securely
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in W3 Eden, Inc.
network
low complexity
wpdownloadmanager CWE-89
7.2
2024-11-18 CVE-2024-52436 SQL Injection vulnerability in Wpexperts Post Smtp
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Post SMTP allows Blind SQL Injection.This issue affects Post SMTP: from n/a through 2.9.9.
network
low complexity
wpexperts CWE-89
7.2
2024-11-18 CVE-2024-49574 SQL Injection vulnerability in Zohocorp Manageengine Adaudit Plus
Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.
network
low complexity
zohocorp CWE-89
8.8
2024-11-15 CVE-2024-11256 SQL Injection vulnerability in 1000Projects Portfolio Management System MCA 1.0
A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical.
network
low complexity
1000projects CWE-89
critical
9.8
2024-11-15 CVE-2024-11257 SQL Injection vulnerability in 1000Projects Beauty Parlour Management System 1.0
A vulnerability classified as critical has been found in 1000 Projects Beauty Parlour Management System 1.0.
network
low complexity
1000projects CWE-89
critical
9.8
2024-11-15 CVE-2024-11258 SQL Injection vulnerability in 1000Projects Beauty Parlour Management System 1.0
A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0.
network
low complexity
1000projects CWE-89
critical
9.8
2024-11-15 CVE-2024-41679 SQL Injection vulnerability in Glpi-Project Glpi
GLPI is a free asset and IT management software package.
network
low complexity
glpi-project CWE-89
8.8
2024-11-15 CVE-2024-45608 SQL Injection vulnerability in Glpi-Project Glpi
GLPI is a free asset and IT management software package.
network
low complexity
glpi-project CWE-89
8.8