Total
20788 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-53792 | 1 Kibokolabs | 1 Watu Quiz | 2026-06-17 | N/A | 8.5 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Watu Quiz watu allows SQL Injection.This issue affects Watu Quiz: from n/a through <= 3.4.1.2. | |||||
| CVE-2024-53783 | 2026-06-17 | N/A | 7.6 HIGH | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Anzar Ahmed Ni WooCommerce Cost Of Goods ni-woocommerce-cost-of-goods.This issue affects Ni WooCommerce Cost Of Goods: from n/a through <= 3.2.8. | |||||
| CVE-2024-53678 | 1 Apache | 1 Vcl | 2026-06-17 | N/A | 8.8 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitted when requesting a new Block Allocation such that a SELECT SQL statement is modified. The data returned by the SELECT statement is not viewable by the attacker. This issue affects all versions of Apache VCL from 2.2 through 2.5.1. Users are recommended to upgrade to version 2.5.2, which fixes the issue. | |||||
| CVE-2024-53603 | 1 Phpgurukul | 1 Covid19 Testing Management System | 2026-06-17 | N/A | 7.3 HIGH |
| A SQL Injection vulnerability was found in /covid-tms/password-recovery.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the contactno POST request parameter. | |||||
| CVE-2024-53544 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint. | |||||
| CVE-2024-53543 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the addProject method in the smarttimeplus/MySQLConnection endpoint. | |||||
| CVE-2024-53507 | 1 B3log | 1 Siyuan | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems. | |||||
| CVE-2024-53506 | 1 B3log | 1 Siyuan | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs. | |||||
| CVE-2024-53505 | 1 B3log | 1 Siyuan | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent. | |||||
| CVE-2024-53504 | 1 B3log | 1 Siyuan | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory. | |||||
| CVE-2024-53502 | 1 Sem-cms | 1 Semcms | 2026-06-17 | N/A | 3.8 LOW |
| Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page. | |||||
| CVE-2024-53499 | 1 Jeewms | 1 Jeewms | 2026-06-17 | N/A | 9.8 CRITICAL |
| Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API. | |||||
| CVE-2024-53438 | 1 Churchcrm | 1 Churchcrm | 2026-06-17 | N/A | 9.8 CRITICAL |
| EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands. | |||||
| CVE-2024-53354 | 1 Easyvirt | 2 Co2scope, Dcscope | 2026-06-17 | N/A | 6.5 MEDIUM |
| Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) user parameter to /api/management/findfilterlist; the (2) user or (3) filter parameter to /api/audit/findmetawatcher; the (4) user parameter to /api/audit/findmetaalert; the (5) user parameter to /api/management/ds; the (6) user or (7) filter parameter to /api/audit/findmetarunalert; the (7) user parameter to /api/management/findtimeview; the (8) user, (9) filter or (10) target parameter to /api/management/getihmsettings; the (11) user or (12) filter parameter to /api/management/elementstype; the (14) login, (15) user, (16) is_local, (17) is_ldap, or (18) is_openid parameter to /api/user/addalias; the (19) role parameter to /api/user/addrole; the (20) user or (21) filter parameter to /api/management/addtimeview; the (22) TIMEAGO, (23) IDENTIFIER, (24) USER, (25) NAME, or (26) COST parameter to /api/management/addtagcosts; the (27) USER, or (28) VM_COST parameter to /api/management/updategenericcpucost; the (29) VM, (30) HOST, or (31) STORAGE parameter to /api/management/updatecostinfo; the (32) user, (33) filter, or (34) timeago parameter to /api/management/addfilter; the (35) user parameter to /api/report/getreporthistory. | |||||
| CVE-2024-52969 | 1 Fortinet | 1 Fortisiem | 2026-06-17 | N/A | 4.1 MEDIUM |
| An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiSIEM ersion 7.1.7 and below, version 7.1.0, version 7.0.3 and below, version 6.7.9 and below, 6.7.8, version 6.6.5 and below, version 6.5.3 and below, version 6.4.4 and below Update/Create Case feature may allow an authenticated attacker to extract database information via crafted requests. | |||||
| CVE-2024-52874 | 1 Infoblox | 1 Netmri | 2026-06-17 | N/A | 8.8 HIGH |
| In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks. | |||||
| CVE-2024-52724 | 1 Zzcms | 1 Zzcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| ZZCMS 2023 was discovered to contain a SQL injection vulnerability in /q/show.php. | |||||
| CVE-2024-52675 | 1 Oretnom23 | 1 Sentiment Based Movie Rating System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SourceCodester Sentiment Based Movie Rating System 1.0 is vulnerable to SQL Injection in /msrps/movies.php. | |||||
| CVE-2024-52538 | 1 Dell | 2 Avamar Data Store, Avamar Server | 2026-06-17 | N/A | 7.6 HIGH |
| Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. | |||||
| CVE-2024-52495 | 2026-06-17 | N/A | 8.5 HIGH | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calculator allows SQL Injection.This issue affects Distance Based Shipping Calculator: from n/a through <= 2.0.23. | |||||
