Total
14524 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-41440 | 1 Billing System Project Project | 1 Billing System Project | 2024-11-21 | N/A | 7.2 HIGH |
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editcategory.php. | |||||
CVE-2022-41439 | 1 Billing System Project Project | 1 Billing System Project | 2024-11-21 | N/A | 7.2 HIGH |
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php. | |||||
CVE-2022-41416 | 1 Online Tours \& Travels Management System Project | 1 Online Tours \& Travels Management System | 2024-11-21 | N/A | 7.2 HIGH |
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /user/update_booking.php. | |||||
CVE-2022-41408 | 1 Online Pet Shop We App Project | 1 Online Pet Shop We App | 2024-11-21 | N/A | 9.8 CRITICAL |
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order. | |||||
CVE-2022-41407 | 1 Online Pet Shop We App Project | 1 Online Pet Shop We App | 2024-11-21 | N/A | 7.2 HIGH |
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order. | |||||
CVE-2022-41403 | 1 Newsletter Subscribe \(popup \+ Regular Module\) Project | 1 Newsletter Subscribe \(popup \+ Regular Module\) | 2024-11-21 | N/A | 9.8 CRITICAL |
OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at index.php?route=extension/module/so_newletter_custom_popup/newsletter. | |||||
CVE-2022-41391 | 1 Ocomon Project | 1 Ocomon | 2024-11-21 | N/A | 9.8 CRITICAL |
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php. | |||||
CVE-2022-41390 | 1 Ocomon Project | 1 Ocomon | 2024-11-21 | N/A | 9.8 CRITICAL |
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php. | |||||
CVE-2022-41378 | 1 Online Pet Shop We App Project | 1 Online Pet Shop We App | 2024-11-21 | N/A | 7.2 HIGH |
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/admin/?page=inventory/manage_inventory. | |||||
CVE-2022-41377 | 1 Online Pet Shop We App Project | 1 Online Pet Shop We App | 2024-11-21 | N/A | 7.2 HIGH |
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/admin/?page=maintenance/manage_category. | |||||
CVE-2022-41355 | 1 Online Leave Management System Project | 1 Online Leave Management System | 2024-11-21 | N/A | 7.2 HIGH |
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /leave_system/classes/Master.php?f=delete_department. | |||||
CVE-2022-41272 | 1 Sap | 1 Netweaver Process Integration | 2024-11-21 | N/A | 9.9 CRITICAL |
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data across the entire system. This allows the attacker to have full read access to user data, make limited modifications to user data, and degrade the performance of the system, leading to a high impact on confidentiality and a limited impact on the availability and integrity of the application. | |||||
CVE-2022-41271 | 1 Sap | 1 Netweaver Process Integration | 2024-11-21 | N/A | 9.4 CRITICAL |
An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to access services that could perform unauthorized operations. The vulnerability affects local users and data, leading to a considerable impact on confidentiality as well as availability and a limited impact on the integrity of the application. These operations can be used to: * Read any information * Modify sensitive information * Denial of Service attacks (DoS) * SQL Injection | |||||
CVE-2022-41259 | 1 Sap | 1 Sql Anywhere | 2024-11-21 | N/A | 6.5 MEDIUM |
SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries that use an ARRAY constructor. | |||||
CVE-2022-41142 | 1 Centreon | 1 Centreon | 2024-11-21 | N/A | 8.8 HIGH |
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to configure poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18304. | |||||
CVE-2022-41133 | 1 Deltaww | 1 Diaenergie | 2024-11-21 | N/A | 8.8 HIGH |
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListParameters. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries. | |||||
CVE-2022-40967 | 1 Deltaww | 1 Diaenergie | 2024-11-21 | N/A | 8.8 HIGH |
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoTHubNameExisted. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries. | |||||
CVE-2022-40944 | 1 Phpgurukul | 1 Dairy Farm Shop Management System | 2024-11-21 | N/A | 9.8 CRITICAL |
Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file. | |||||
CVE-2022-40943 | 1 Phpgurukul | 1 Dairy Farm Shop Management System | 2024-11-21 | N/A | 9.8 CRITICAL |
Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file. | |||||
CVE-2022-40935 | 1 Online Pet Shop Web Application Project | 1 Online Pet Shop Web Application | 2024-11-21 | N/A | 7.2 HIGH |
Online Pet Shop We App v1.0 is vulnerable to SQL Injection via /pet_shop/classes/Master.php?f=delete_category,id. |