Filtered by vendor
Subscriptions
Total
16424 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-34952 | 1 Phptpoint | 1 Pharmacy Management System | 2024-11-21 | 9.8 Critical |
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php. | ||||
CVE-2022-34951 | 1 Phptpoint | 1 Pharmacy Management System | 2024-11-21 | 9.8 Critical |
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php. | ||||
CVE-2022-34950 | 1 Pharmacy Management System Project | 1 Pharmacy Management System | 2024-11-21 | 9.8 Critical |
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editproduct.php. | ||||
CVE-2022-34949 | 1 Pharmacy Management System Project | 1 Pharmacy Management System | 2024-11-21 | 9.8 Critical |
Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or password parameter at login.php. | ||||
CVE-2022-34948 | 1 Pharmacy Management System Project | 1 Pharmacy Management System | 2024-11-21 | 9.8 Critical |
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editbrand.php. | ||||
CVE-2022-34947 | 1 Pharmacy Management System Project | 1 Pharmacy Management System | 2024-11-21 | 9.8 Critical |
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcategory.php. | ||||
CVE-2022-34946 | 1 Pharmacy Management System Project | 1 Pharmacy Management System | 2024-11-21 | 9.8 Critical |
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getexpproduct.php. | ||||
CVE-2022-34945 | 1 Pharmacy Management System Project | 1 Pharmacy Management System | 2024-11-21 | 9.8 Critical |
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php. | ||||
CVE-2022-34928 | 1 Jflyfox | 1 Jfinal Cms | 2024-11-21 | 8.8 High |
JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user. | ||||
CVE-2022-34878 | 1 Vicidial | 1 Vicidial | 2024-11-21 | 5.5 Medium |
SQL Injection vulnerability in User Stats interface (/vicidial/user_stats.php) of VICIdial via the file_download parameter allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make it otherwise unavailable, and become administrators of the database server. | ||||
CVE-2022-34877 | 1 Vicidial | 1 Vicidial | 2024-11-21 | 6.4 Medium |
SQL Injection vulnerability in AST Agent Time Sheet interface ((/vicidial/AST_agent_time_sheet.php) of VICIdial via the agent parameter allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make it otherwise unavailable, and become administrators of the database server. This issue affects: VICIdial 2.14b0.5 versions prior to 3555. | ||||
CVE-2022-34876 | 1 Vicidial | 1 Vicidial | 2024-11-21 | 5.5 Medium |
SQL Injection vulnerability in admin interface (/vicidial/admin.php) of VICIdial via modify_email_accounts, access_recordings, and agentcall_email parameters allows attacker to spoof identity, tamper with existing data, allow the complete disclosure of all data on the system, destroy the data or make it otherwise unavailable, and become administrators of the database server. This issue affects: VICIdial 2.14b0.5 versions prior to 3555. | ||||
CVE-2022-34872 | 1 Centreon | 1 Centreon | 2024-11-21 | 6.5 Medium |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of Virtual Metrics. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-16336. | ||||
CVE-2022-34871 | 1 Centreon | 1 Centreon | 2024-11-21 | 7.2 High |
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-16335. | ||||
CVE-2022-34590 | 1 Hospital Management System Project | 1 Hospital Management System | 2024-11-21 | 7.2 High |
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php. | ||||
CVE-2022-34588 | 1 Advanced School Management System Project | 1 Advanced School Management System | 2024-11-21 | 8.8 High |
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/timetable_insert_form.php. | ||||
CVE-2022-34586 | 1 Advanced School Management System Project | 1 Advanced School Management System | 2024-11-21 | 8.8 High |
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/student_grade_wise.php. | ||||
CVE-2022-34557 | 1 Barangay Management System Project | 1 Barangay Management System | 2024-11-21 | 8.8 High |
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/permit/permit.php. | ||||
CVE-2022-34132 | 1 Jorani | 1 Jorani | 2024-11-21 | 9.8 Critical |
Benjamin BALET Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php. | ||||
CVE-2022-34042 | 1 Barangay Management System Project | 1 Barangay Management System | 2024-11-21 | 7.2 High |
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/household/household.php. |