Total
20788 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-48465 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| The MRBS version 1.5.0 has an SQL injection vulnerability in the edit_entry_handler.php file, specifically in the rooms%5B%5D parameter | |||||
| CVE-2024-48427 | 1 Oretnom23 | 1 Packers And Movers Management System | 2026-06-17 | N/A | 8.8 HIGH |
| A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id | |||||
| CVE-2024-48411 | 1 Mayurik | 1 Online Tours \& Travels Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php. | |||||
| CVE-2024-48357 | 1 Lylme | 1 Lylme Spage | 2026-06-17 | N/A | 9.8 CRITICAL |
| LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php. | |||||
| CVE-2024-48356 | 1 Lylme | 1 Lylme Spage | 2026-06-17 | N/A | 9.8 CRITICAL |
| LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php. | |||||
| CVE-2024-48343 | 1 Esafenet | 1 Cdg | 2026-06-17 | N/A | 6.3 MEDIUM |
| A SQL Injection vulnerability in ESAFENET CDG 5 and earlier allows an attacker to execute arbitrary code via the id parameter of the dataSearch.jsp page. | |||||
| CVE-2024-48325 | 1 Portabilis | 1 I-educar | 2026-06-17 | N/A | 8.1 HIGH |
| Portabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the "getDocuments" function of the "InstituicaoDocumentacaoController" class. The "instituicao_id" parameter in "/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id" is not properly sanitized, allowing an unauthenticated remote attacker to inject malicious SQL commands. | |||||
| CVE-2024-48307 | 1 Jeecg | 1 Jeecg Boot | 2026-06-17 | N/A | 9.8 CRITICAL |
| JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData. | |||||
| CVE-2024-48283 | 1 Phpgurukul | 1 User Registration \& Login And User Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter. | |||||
| CVE-2024-48282 | 1 Phpgurukul | 1 User Registration \& Login And User Management System | 2026-06-17 | N/A | 7.6 HIGH |
| A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request. | |||||
| CVE-2024-48280 | 1 Phpgurukul | 1 User Registration \& Login And User Management System | 2026-06-17 | N/A | 7.6 HIGH |
| A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request. | |||||
| CVE-2024-48259 | 1 Magicbug | 1 Cloudlog | 2026-06-17 | N/A | 7.3 HIGH |
| Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign. | |||||
| CVE-2024-48257 | 1 Wavelog | 1 Wavelog | 2026-06-17 | N/A | 9.8 CRITICAL |
| Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin. | |||||
| CVE-2024-48255 | 1 Magicbug | 1 Cloudlog | 2026-06-17 | N/A | 9.8 CRITICAL |
| Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection. | |||||
| CVE-2024-48253 | 1 Magicbug | 1 Cloudlog | 2026-06-17 | N/A | 9.8 CRITICAL |
| Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection. | |||||
| CVE-2024-48251 | 1 Wavelog | 1 Wavelog | 2026-06-17 | N/A | 9.8 CRITICAL |
| Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode. | |||||
| CVE-2024-48249 | 1 Wavelog | 1 Wavelog | 2026-06-17 | N/A | 7.3 HIGH |
| Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode. | |||||
| CVE-2024-48238 | 1 Wtcms Project | 1 Wtcms | 2026-06-17 | N/A | 4.7 MEDIUM |
| WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter. | |||||
| CVE-2024-48231 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 7.2 HIGH |
| Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php. | |||||
| CVE-2024-48230 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 7.2 HIGH |
| funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php. | |||||
