Search Results (17583 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-1887 2 Apple, Mozilla 2 Iphone Os, Firefox 2025-04-16 9.8 Critical
The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.
CVE-2022-2137 1 Advantech 1 Iview 2025-04-16 4.9 Medium
The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information
CVE-2022-2135 1 Advantech 1 Iview 2025-04-16 7.5 High
The affected product is vulnerable to multiple SQL injections, which may allow an unauthorized attacker to disclose information.
CVE-2024-2152 1 Oretnom23 1 Online Mobile Store Management System 2025-04-16 4.7 Medium
A vulnerability, which was classified as critical, has been found in SourceCodester Online Mobile Management Store 1.0. Affected by this issue is some unknown functionality of the file /admin/product/manage_product.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-255584.
CVE-2024-33144 1 J2eefast 1 J2eefast 2025-04-16 8.8 High
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedTasksPage function in BpmTaskMapper.xml.
CVE-2024-33139 1 J2eefast 1 J2eefast 2025-04-16 7.5 High
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.
CVE-2024-35091 1 J2eefast 1 J2eefast 2025-04-16 9.8 Critical
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml.
CVE-2024-35090 1 J2eefast 1 J2eefast 2025-04-16 8.2 High
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysUreportFileMapper.xml.
CVE-2024-35086 1 J2eefast 1 J2eefast 2025-04-16 9.8 Critical
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.xml .
CVE-2024-35085 1 J2eefast 1 J2eefast 2025-04-16 5.4 Medium
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMapper.xml.
CVE-2024-35084 1 J2eefast 1 J2eefast 2025-04-16 9.8 Critical
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xml.
CVE-2024-35083 1 J2eefast 1 J2eefast 2025-04-16 8.8 High
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysLoginInfoMapper.xml.
CVE-2024-35082 1 J2eefast 1 J2eefast 2025-04-16 6.3 Medium
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysOperLogMapper.xml.
CVE-2021-40617 1 Os4ed 1 Opensis 2025-04-16 9.8 Critical
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
CVE-2020-5504 3 Debian, Phpmyadmin, Suse 3 Debian Linux, Phpmyadmin, Suse Linux Enterprise Server 2025-04-16 8.8 High
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.
CVE-2019-16693 1 Phpipam 1 Phpipam 2025-04-16 9.8 Critical
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
CVE-2024-40443 1 Oretnom23 1 Computer Laboratory Management System 2025-04-16 4.3 Medium
SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php
CVE-2025-1981 2025-04-16 N/A
Improper neutralization of input provided by a low-privileged user into a file search functionality in Ready_'s Invoices module allows for SQL Injection attacks.
CVE-2023-33362 1 Piwigo 1 Piwigo 2025-04-16 9.8 Critical
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
CVE-2025-39518 2025-04-16 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedefiningTheWeb BMA Lite allows SQL Injection. This issue affects BMA Lite: from n/a through 1.4.2.