Filtered by vendor
Subscriptions
Total
16485 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-41507 | 1 Superstorefinder | 1 Super Store Finder | 2024-11-21 | 9.8 Critical |
Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters. | ||||
CVE-2023-41443 | 1 Xxyopen | 1 Novel-plus | 2024-11-21 | 7.2 High |
SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list. | ||||
CVE-2023-41387 | 2 Apple, Patreon | 2 Iphone Os, Flutter Downloader | 2024-11-21 | 9.1 Critical |
A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses UIFileSharingEnabled and LSSupportsOpeningDocumentsInPlace properties. As a result, local users can obtain the same attack primitives as remote attackers by tampering with the internal database of the framework on the device. | ||||
CVE-2023-41364 | 1 Metaways | 1 Tine | 2024-11-21 | 9.8 Critical |
In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection. | ||||
CVE-2023-41328 | 1 Frappe | 1 Frappe | 2024-11-21 | 4.2 Medium |
Frappe is a low code web framework written in Python and Javascript. A SQL Injection vulnerability has been identified in the Frappe Framework which could allow a malicious actor to access sensitive information. This issue has been addressed in versions 13.46.1 and 14.20.0. Users are advised to upgrade. There's no workaround to fix this without upgrading. | ||||
CVE-2023-41320 | 1 Glpi-project | 1 Glpi | 2024-11-21 | 8.1 High |
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. UI layout preferences management can be hijacked to lead to SQL injection. This injection can be use to takeover an administrator account. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability. | ||||
CVE-2023-41285 | 1 Qnap | 1 Qumagie | 2024-11-21 | 7.4 High |
A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: QuMagie 2.1.4 and later | ||||
CVE-2023-41284 | 1 Qnap | 1 Qumagie | 2024-11-21 | 7.4 High |
A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: QuMagie 2.1.4 and later | ||||
CVE-2023-41262 | 1 Plixer | 1 Scrutinizer | 2024-11-21 | 9.8 Critical |
An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV is vulnerable to SQL injection through the sorting parameter, allowing an unauthenticated user to execute arbitrary SQL statements in the context of the application's backend database server. | ||||
CVE-2023-40989 | 1 Jeecg | 1 Jeecg Boot | 2024-11-21 | 9.8 Critical |
SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component. | ||||
CVE-2023-40970 | 1 Slims | 1 Senayan Library Management System | 2024-11-21 | 8.8 High |
Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php. | ||||
CVE-2023-40958 | 1 Didotech | 1 Engineering \& Lifecycle Management | 2024-11-21 | 8.8 High |
A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the query parameter in models/base_client.py component. | ||||
CVE-2023-40957 | 1 Didotech | 1 Engineering \& Lifecycle Management | 2024-11-21 | 8.8 High |
A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the request parameter in models/base_client.py component. | ||||
CVE-2023-40956 | 1 Cloudroits | 1 Wesite Job Search | 2024-11-21 | 8.8 High |
A SQL injection vulnerability in Cloudroits Website Job Search v.15.0 allows a remote authenticated attacker to execute arbitrary code via the name parameter in controllers/main.py component. | ||||
CVE-2023-40955 | 1 Didotech | 1 Engineering \& Lifecycle Management | 2024-11-21 | 8.8 High |
A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the select parameter in models/base_client.py component. | ||||
CVE-2023-40954 | 1 Gmarczynski | 1 Dynamic Progress Bar | 2024-11-21 | 9.8 Critical |
A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component. | ||||
CVE-2023-40946 | 1 Schoolmate Project | 1 Schoolmate | 2024-11-21 | 9.8 Critical |
Schoolmate 1.3 is vulnerable to SQL Injection in the variable $username from SESSION in ValidateLogin.php. | ||||
CVE-2023-40945 | 1 Doctor Appointment System Project | 1 Doctor Appointment System | 2024-11-21 | 9.8 Critical |
Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php. | ||||
CVE-2023-40944 | 1 Schoolmate Project | 1 Schoolmate | 2024-11-21 | 9.8 Critical |
Schoolmate 1.3 is vulnerable to SQL Injection in the variable $schoolname from Database at ~\header.php. | ||||
CVE-2023-40934 | 1 Nagios | 1 Nagios Xi | 2024-11-21 | 7.2 High |
A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings. |