Total
20788 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-48229 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 7.2 HIGH |
| funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin. | |||||
| CVE-2024-48226 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 7.2 HIGH |
| Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield. | |||||
| CVE-2024-48223 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 7.2 HIGH |
| Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist. | |||||
| CVE-2024-48222 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 7.2 HIGH |
| Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit. | |||||
| CVE-2024-48218 | 1 Funadmin | 1 Funadmin | 2026-06-17 | N/A | 7.2 HIGH |
| Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list. | |||||
| CVE-2024-48177 | 1 Mrcms | 1 Mrcms | 2026-06-17 | N/A | 8.8 HIGH |
| MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do. | |||||
| CVE-2024-48072 | 1 Weaver | 1 E-cology | 2026-06-17 | N/A | 9.8 CRITICAL |
| Weaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?invoker=com.weaver.formmodel.mobile.mec.servlet.MECAction&action=getFieldTriggerValue&searchField=*&fromTable=HrmResourceManager&whereClause=1%3d1&triggerCondition=1&expression=%3d&fieldValue=1. | |||||
| CVE-2024-48043 | 2026-06-17 | N/A | 7.6 HIGH | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ShortPixel ShortPixel Image Optimizer shortpixel-image-optimiser allows Blind SQL Injection.This issue affects ShortPixel Image Optimizer: from n/a through <= 5.6.3. | |||||
| CVE-2024-48040 | 1 Tainacan | 1 Tainacan | 2026-06-17 | N/A | 8.5 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows SQL Injection.This issue affects Tainacan: from n/a through <= 0.21.8. | |||||
| CVE-2024-48020 | 2026-06-17 | N/A | 8.5 HIGH | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows SQL Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.21. | |||||
| CVE-2024-47977 | 1 Dell | 2 Avamar Data Store, Avamar Server | 2026-06-17 | N/A | 7.1 HIGH |
| Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |||||
| CVE-2024-47926 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | |||||
| CVE-2024-47911 | 1 Sonarsource | 1 Sonarqube | 2026-06-17 | N/A | 6.7 MEDIUM |
| In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allows SonarQube users with the administrator role to inject blind SQL commands. | |||||
| CVE-2024-47881 | 1 Openrefine | 1 Openrefine | 2026-06-17 | N/A | 8.1 HIGH |
| OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to load (local or remote) extension DLLs and so run arbitrary code on the server. The attacker needs to have network access to the OpenRefine instance. Version 3.8.3 fixes this issue. | |||||
| CVE-2024-47849 | 1 Mediawiki | 1 Cargo | 2026-06-17 | N/A | 9.8 CRITICAL |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows SQL Injection.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1. | |||||
| CVE-2024-47487 | 1 Hikvision | 1 Hikcentral Professional | 2026-06-17 | N/A | 8.8 HIGH |
| There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user to execute arbitrary SQL queries. | |||||
| CVE-2024-47484 | 1 Dell | 2 Avamar Data Store, Avamar Server | 2026-06-17 | N/A | 8.2 HIGH |
| Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |||||
| CVE-2024-47483 | 1 Dell | 1 Data Lakehouse | 2026-06-17 | N/A | 2.9 LOW |
| Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |||||
| CVE-2024-47350 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITHEMES YITH WooCommerce Ajax Search yith-woocommerce-ajax-search.This issue affects YITH WooCommerce Ajax Search: from n/a through <= 2.8.0. | |||||
| CVE-2024-47338 | 2026-06-17 | N/A | 8.5 HIGH | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal WPExperts Square For GiveWP wpexperts-square-for-give allows SQL Injection.This issue affects WPExperts Square For GiveWP: from n/a through <= 1.3. | |||||
