Filtered by vendor
Subscriptions
Total
18413 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-4103 | 1 Qsige | 1 Qsige | 2024-11-21 | 8.8 High |
| QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application. | ||||
| CVE-2023-4102 | 1 Qsige | 1 Qsige | 2024-11-21 | 8.8 High |
| QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application. | ||||
| CVE-2023-4098 | 1 Qsige | 1 Qsige | 2024-11-21 | 8.8 High |
| It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application. | ||||
| CVE-2023-4092 | 1 Fujitsu | 1 Arconte Aurea | 2024-11-21 | 8.8 High |
| SQL injection vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to read sensitive data from the database, modify data (insert/update/delete), perform database administration operations and, in some cases, execute commands on the operating system. | ||||
| CVE-2023-4037 | 1 Setelsa-security | 1 Conacwin | 2024-11-21 | 9.9 Critical |
| Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter. | ||||
| CVE-2023-4034 | 1 Digitatek | 1 Smartrise Document Management System | 2024-11-21 | 9.8 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection.This issue affects Smartrise Document Management System: before Hvl-2.0. | ||||
| CVE-2023-49825 | 1 Pencidesign | 1 Soledad | 2024-11-21 | 8.5 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1. | ||||
| CVE-2023-49776 | 1 Dmry | 1 Sayfa Sayac | 2024-11-21 | 9.3 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a through 2.6. | ||||
| CVE-2023-49764 | 1 Sigmaplugin | 1 Advanced Database Cleaner | 2024-11-21 | 7.6 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Younes JFR. Advanced Database Cleaner.This issue affects Advanced Database Cleaner: from n/a through 3.1.2. | ||||
| CVE-2023-49752 | 1 Spoonthemes | 1 Adifier | 2024-11-21 | 9.3 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoon themes Adifier - Classified Ads WordPress Theme.This issue affects Adifier - Classified Ads WordPress Theme: from n/a before 3.1.4. | ||||
| CVE-2023-49750 | 1 Spoonthemes | 1 Couponis | 2024-11-21 | 9.3 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoonthemes Couponis - Affiliate & Submitting Coupons WordPress Theme.This issue affects Couponis - Affiliate & Submitting Coupons WordPress Theme: from n/a before 2.2. | ||||
| CVE-2023-49708 | 1 Joomstar | 1 Starshop | 2024-11-21 | 9.8 Critical |
| SQLi vulnerability in Starshop component for Joomla. | ||||
| CVE-2023-49707 | 1 Joomlart | 1 S5 Register | 2024-11-21 | 9.8 Critical |
| SQLi vulnerability in S5 Register module for Joomla. | ||||
| CVE-2023-49689 | 1 Kashipara | 1 Job Portal | 2024-11-21 | 9.8 Critical |
| Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'JobId' parameter of the Employer/DeleteJob.php resource does not validate the characters received and they are sent unfiltered to the database. | ||||
| CVE-2023-49688 | 1 Kashipara | 1 Job Portal | 2024-11-21 | 9.8 Critical |
| Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtUser' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database. | ||||
| CVE-2023-49681 | 1 Kashipara | 1 Job Portal | 2024-11-21 | 9.8 Critical |
| Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cmbQual' parameter of the Employer/InsertWalkin.php resource does not validate the characters received and they are sent unfiltered to the database. | ||||
| CVE-2023-49677 | 1 Kashipara | 1 Job Portal | 2024-11-21 | 9.8 Critical |
| Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cmbQual' parameter of the Employer/InsertJob.php resource does not validate the characters received and they are sent unfiltered to the database. | ||||
| CVE-2023-49581 | 1 Sap | 1 Netweaver Application Server Abap | 2024-11-21 | 4.1 Medium |
| SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker to write data to a database table. By doing so the attacker could increase response times of the AS ABAP, leading to mild impact on availability. | ||||
| CVE-2023-49429 | 1 Tenda | 2 Ax9, Ax9 Firmware | 2024-11-21 | 9.8 Critical |
| Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules. | ||||
| CVE-2023-49371 | 1 Ruoyi | 1 Ruoyi | 2024-11-21 | 9.8 Critical |
| RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit. | ||||
ReportizFlow