Filtered by vendor
Subscriptions
Total
16424 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-40831 | 1 Codeigniter | 1 Codeigniter | 2024-11-21 | 9.8 Critical |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php like() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | ||||
CVE-2022-40830 | 1 Codeigniter | 1 Codeigniter | 2024-11-21 | 9.8 Critical |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | ||||
CVE-2022-40829 | 1 Codeigniter | 1 Codeigniter | 2024-11-21 | 9.8 Critical |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_like() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | ||||
CVE-2022-40826 | 1 Codeigniter | 1 Codeigniter | 2024-11-21 | 9.8 Critical |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_having() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | ||||
CVE-2022-40825 | 1 Codeigniter | 1 Codeigniter | 2024-11-21 | 9.8 Critical |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | ||||
CVE-2022-40824 | 1 Codeigniter | 1 Codeigniter | 2024-11-21 | 9.8 Critical |
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where() function. Note: Multiple third parties have disputed this as not a valid vulnerability. | ||||
CVE-2022-40766 | 1 Moderncampus | 1 Omni Cms | 2024-11-21 | 9.8 Critical |
Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' substring. | ||||
CVE-2022-3801 | 1 Ibax | 1 Go-ibax | 2024-11-21 | 6.3 Medium |
A vulnerability, which was classified as critical, was found in IBAX go-ibax. This affects an unknown part of the file /api/v2/open/rowsInfo. The manipulation of the argument order leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212637 was assigned to this vulnerability. | ||||
CVE-2022-3729 | 1 Ehoney Project | 1 Ehoney | 2024-11-21 | 6.3 Medium |
A vulnerability, which was classified as critical, has been found in seccome Ehoney. This issue affects some unknown processing of the file /api/v1/attack. The manipulation of the argument AttackIP leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-212411. | ||||
CVE-2022-3714 | 1 Oretnom23 | 1 Online Medicine Ordering System | 2024-11-21 | 5 Medium |
A vulnerability classified as critical has been found in SourceCodester Online Medicine Ordering System 1.0. Affected is an unknown function of the file admin/?page=orders/view_order. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. VDB-212346 is the identifier assigned to this vulnerability. | ||||
CVE-2022-3671 | 1 Elearning System Project | 1 Elearning System | 2024-11-21 | 6.3 Medium |
A vulnerability classified as critical was found in SourceCodester eLearning System 1.0. This vulnerability affects unknown code of the file /admin/students/manage.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-212014 is the identifier assigned to this vulnerability. | ||||
CVE-2022-3579 | 1 Oretnom23 | 1 Cashier Queuing System | 2024-11-21 | 6.3 Medium |
A vulnerability classified as critical was found in SourceCodester Cashier Queuing System 1.0. This vulnerability affects unknown code of the file /queuing/login.php of the component Login Page. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-211186 is the identifier assigned to this vulnerability. | ||||
CVE-2022-3473 | 1 Oretnom23 | 1 Human Resource Management System | 2024-11-21 | 6.3 Medium |
A vulnerability classified as critical has been found in SourceCodester Human Resource Management System. This affects an unknown part of the file getstatecity.php. The manipulation of the argument ci leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-210717 was assigned to this vulnerability. | ||||
CVE-2022-3471 | 1 Oretnom23 | 1 Human Resource Management System | 2024-11-21 | 6.3 Medium |
A vulnerability was found in SourceCodester Human Resource Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file city.php. The manipulation of the argument searccity leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-210715. | ||||
CVE-2022-3470 | 1 Oretnom23 | 1 Human Resource Management System | 2024-11-21 | 6.3 Medium |
A vulnerability was found in SourceCodester Human Resource Management System. It has been classified as critical. Affected is an unknown function of the file getstatecity.php. The manipulation of the argument sc leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-210714 is the identifier assigned to this vulnerability. | ||||
CVE-2022-3142 | 1 Basixonline | 1 Nex-forms | 2024-11-21 | 8.8 High |
The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however can be configured otherwise via the plugin settings. | ||||
CVE-2022-3141 | 1 Cozmoslabs | 1 Translatepress | 2024-11-21 | 8.8 High |
The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in the SQL query can be surpassed and a time-based blind payload can be injected. | ||||
CVE-2022-39822 | 1 Nokia | 1 Network Functions Manager For Transport | 2024-11-21 | 8.8 High |
In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET parameter. An authenticated attacker is required for exploitation. | ||||
CVE-2022-39817 | 1 Nokia | 1 1350 Optical Management System | 2024-11-21 | 8.8 High |
In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify query syntax and perform unauthorized (and unexpected) operations against the remote database. | ||||
CVE-2022-38812 | 1 Aerocms Project | 1 Aerocms | 2024-11-21 | 6.5 Medium |
AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter. |