Total
20784 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-40682 | 1 Oretnom23 | 1 Human Resource Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, create, update and delete databases via the “city” and “state” parameters in the /controller/ccity.php endpoint. | |||||
| CVE-2025-40677 | 2026-06-17 | N/A | N/A | ||
| SQL injection vulnerability in Summar Software´s Portal del Empleado. This vulnerability allows an attacker to retrieve, create, update, and delete the database by sending a POST request using the parameter “ctl00$ContentPlaceHolder1$filtroNombre” in “/MemberPages/quienesquien.aspx”. | |||||
| CVE-2025-40666 | 1 Tcman | 1 Gim | 2026-06-17 | N/A | 9.8 CRITICAL |
| Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete databases through ArbolID parameter in/GIMWeb/PC/frmPreventivosList.aspx. | |||||
| CVE-2025-40665 | 1 Tcman | 1 Gim | 2026-06-17 | N/A | 9.8 CRITICAL |
| Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update and delete databases through ArbolID parameter in /GIMWeb/PC/frmCorrectivosList.aspx. | |||||
| CVE-2025-40657 | 1 Acc | 1 Dm Corporative Cms | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the codform parameter in /modules/forms/collectform.asp. | |||||
| CVE-2025-40656 | 1 Acc | 1 Dm Corporative Cms | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the cod parameter in /administer/node-selection/data.asp. | |||||
| CVE-2025-40655 | 1 Acc | 1 Dm Corporative Cms | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the name parameter in /antcatalogue.asp. | |||||
| CVE-2025-40654 | 1 Acc | 1 Dm Corporative Cms | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the name and cod parameters in /antbuspre.asp. | |||||
| CVE-2025-40639 | 1 Sbitsoft | 1 Eventobot | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/php/calculate_discount.php'. | |||||
| CVE-2025-40636 | 2026-06-17 | N/A | N/A | ||
| SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retrieve database content via the ‘cip_vvisitcounter’ cookie at all endpoints where the plugin counts visits. | |||||
| CVE-2025-40635 | 2026-06-17 | N/A | N/A | ||
| SQL injection vulnerability in Comerzzia Backoffice: Sales Orchestrator 3.0.15. This vulnerability allows an attacker to retrieve, create, update and delete databases via the ‘uidActivity’, ‘codCompany’ and ‘uidInstance’ parameters of the ‘/comerzzia/login’ endpoint. | |||||
| CVE-2025-40628 | 2026-06-17 | N/A | N/A | ||
| SQL injection vulnerability in DomainsPRO 1.2. This vulnerability could allow an attacker to retrieve, create, update and delete databases via the “d” parameter in the “/article.php” endpoint. | |||||
| CVE-2025-40624 | 1 Tcman | 1 Gim | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘User’ and “email” parameters of the ‘updatePassword’ endpoint. | |||||
| CVE-2025-40623 | 1 Tcman | 1 Gim | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘Sender’ and “email” parameters of the ‘createNotificationAndroid’ endpoint. | |||||
| CVE-2025-40622 | 1 Tcman | 1 Gim | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘username’ parameter of the ‘GetLastDatePasswordChange’ endpoint. | |||||
| CVE-2025-40621 | 1 Tcman | 1 Gim | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘User’ parameter of the ‘ValidateUserAndGetData’ endpoint. | |||||
| CVE-2025-40620 | 1 Tcman | 1 Gim | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in the database. This vulnerability was found in each of the following parameters according to the vulnerability identifier ‘User’ parameter of the ‘ValidateUserAndWS’ endpoint. | |||||
| CVE-2025-40618 | 1 Bookgy | 1 Bookgy | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDRESERVA" parameter in /bkg_imprimir_comprobante.php | |||||
| CVE-2025-40617 | 1 Bookgy | 1 Bookgy | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDTIPO", "IDPISTA" and "IDSOCIO" parameters in /bkg_seleccionar_hora_ajax.php. | |||||
| CVE-2025-3998 | 1 Codeastro | 1 Membership Management System | 2026-06-17 | 7.5 HIGH | 7.3 HIGH |
| A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |||||
