Export limit exceeded: 347821 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 347821 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (18887 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-26032 | 1 Zoneminder | 1 Zoneminder | 2025-03-10 | 8.9 High |
| ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain SQL Injection via malicious jason web token. The Username field of the JWT token was trusted when performing an SQL query to load the user. If an attacker could determine the HASH key used by ZoneMinder, they could generate a malicious JWT token and use it to execute arbitrary SQL. This issue is fixed in versions 1.36.33 and 1.37.33. | ||||
| CVE-2023-26034 | 1 Zoneminder | 1 Zoneminder | 2025-03-10 | 9.6 Critical |
| ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are affected by a SQL Injection vulnerability. The (blind) SQL Injection vulnerability is present within the `filter[Query][terms][0][attr]` query string parameter of the `/zm/index.php` endpoint. A user with the View or Edit permissions of Events may execute arbitrary SQL. The resulting impact can include unauthorized data access (and modification), authentication and/or authorization bypass, and remote code execution. | ||||
| CVE-2023-26037 | 1 Zoneminder | 1 Zoneminder | 2025-03-10 | 8.9 High |
| ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an SQL Injection. The minTime and maxTime request parameters are not properly validated and could be used execute arbitrary SQL. This issue is fixed in versions 1.36.33 and 1.37.33. | ||||
| CVE-2023-0487 | 1 Premio | 1 My Sticky Elements | 2025-03-10 | 7.2 High |
| The My Sticky Elements WordPress plugin before 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement when deleting messages, leading to a SQL injection exploitable by high privilege users such as admin | ||||
| CVE-2023-1064 | 1 Uzaybaskul | 1 Weighbridge Automation Software | 2025-03-07 | 9.8 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighbridge Automation Software allows SQL Injection.This issue affects Weighbridge Automation Software: before 1.1. | ||||
| CVE-2023-23315 | 1 Stripe | 1 Stripe Payment Pro | 2025-03-07 | 9.8 Critical |
| The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection. | ||||
| CVE-2022-46501 | 1 Accruent | 1 Maintenance Connection | 2025-03-07 | 9.8 Critical |
| Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function. | ||||
| CVE-2023-26780 | 1 Yf-exam Project | 1 Yf-exam | 2025-03-07 | 9.8 Critical |
| CleverStupidDog yf-exam v 1.8.0 is vulnerable to SQL Injection. | ||||
| CVE-2023-24763 | 1 Prestashop | 1 Xen Forum | 2025-03-07 | 8.8 High |
| In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0. | ||||
| CVE-2023-24642 | 1 Judging Management System Project | 1 Judging Management System | 2025-03-07 | 9.8 Critical |
| Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateTxtview.php. | ||||
| CVE-2023-24641 | 1 Judging Management System Project | 1 Judging Management System | 2025-03-07 | 9.8 Critical |
| Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateview.php. | ||||
| CVE-2023-0784 | 1 Mayurik | 1 Best Online News Portal | 2025-03-07 | 7.3 High |
| A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. Affected is an unknown function of the component Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220644. | ||||
| CVE-2023-1962 | 1 Mayurik | 1 Best Online News Portal | 2025-03-07 | 7.3 High |
| A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225361 was assigned to this vulnerability. | ||||
| CVE-2024-9008 | 2 Mayurik, Sourcecodester | 2 Best Online News Portal, Best Online News Portal | 2025-03-07 | 6.3 Medium |
| A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. This vulnerability affects unknown code of the file /news-details.php of the component Comment Section. The manipulation of the argument name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2024-5985 | 1 Mayurik | 1 Best Online News Portal | 2025-03-07 | 6.3 Medium |
| A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. This affects an unknown part of the file /admin/index.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-268461 was assigned to this vulnerability. | ||||
| CVE-2025-1870 | 1 Mayurik | 1 Best Online News Portal | 2025-03-07 | 9.8 Critical |
| SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in admin/aboutus.php. | ||||
| CVE-2025-1869 | 1 Mayurik | 1 Best Online News Portal | 2025-03-07 | 9.8 Critical |
| SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/check_avalability.php. | ||||
| CVE-2025-1871 | 1 Mayurik | 1 Best Online News Portal | 2025-03-07 | 9.8 Critical |
| SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" parameters in admin/add-subcategory.php. | ||||
| CVE-2025-1875 | 1 Mayurik | 1 Best Online News Portal | 2025-03-07 | 9.8 Critical |
| SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in search.php. | ||||
| CVE-2025-1874 | 1 Mayurik | 1 Best Online News Portal | 2025-03-07 | 9.8 Critical |
| SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admin/add-category.php. | ||||