Total
20788 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-46531 | 1 Phpgurukul | 1 Vehicle Record System | 2026-06-17 | N/A | 6.3 MEDIUM |
| phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchinputdata parameter at /index.php. | |||||
| CVE-2024-46510 | 1 Esafenet | 1 Cdg | 2026-06-17 | N/A | 7.6 HIGH |
| ESAFENET CDG v5 was discovered to contain a SQL injection vulnerability via the id parameter in the NavigationAjax interface | |||||
| CVE-2024-46472 | 1 Codeastro | 1 Membership Management System | 2026-06-17 | N/A | 8.6 HIGH |
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page. | |||||
| CVE-2024-46382 | 1 Linlinjava | 1 Litemall | 2026-06-17 | N/A | 7.5 HIGH |
| A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via the goodsId, goodsSn, and name parameters in AdminOrderController.java. | |||||
| CVE-2024-46374 | 1 Mayurik | 1 Best House Rental Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the file rental/admin_class.php. | |||||
| CVE-2024-46257 | 1 Jc21 | 1 Nginx Proxy Manager | 2026-06-17 | N/A | 6.3 MEDIUM |
| A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5. | |||||
| CVE-2024-46078 | 1 Adonesevangelista | 1 Sports Management System | 2026-06-17 | N/A | 7.5 HIGH |
| itsourcecode Sports Management System Project 1.0 is vulnerable to SQL Injection in the function delete_category of the file sports_scheduling/player.php via the argument id. | |||||
| CVE-2024-45999 | 1 Magicbug | 1 Cloudlog | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php. The vulnerability is exploitable via the station_id parameter. | |||||
| CVE-2024-45918 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_gis_fence.php. | |||||
| CVE-2024-45876 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| The login form of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.283.4) at /Apps/TOPqw/Login.aspx is vulnerable to SQL injection. The vulnerability exists in the POST parameter txtUsername, which allows for manipulation of SQL queries. | |||||
| CVE-2024-45875 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| The create user function in baltic-it TOPqw Webportal 1.35.287.1 (fixed in version1.35.291), in /Apps/TOPqw/BenutzerManagement.aspx/SaveNewUser, is vulnerable to SQL injection. The JSON object username allows the manipulation of SQL queries. | |||||
| CVE-2024-45794 | 1 Devtron | 1 Devtron | 2026-06-17 | N/A | 8.3 HIGH |
| devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with minimum permission) could utilize and exploit SQL Injection to allow the execution of malicious SQL queries via CreateUser API (/orchestrator/user). This issue has been addressed in version 0.7.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability. | |||||
| CVE-2024-45771 | 1 Openrapid | 1 Rapidcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin.php. | |||||
| CVE-2024-45767 | 1 Dell | 1 Openmanage Enterprise | 2026-06-17 | N/A | 4.3 MEDIUM |
| Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |||||
| CVE-2024-45757 | 2026-06-17 | N/A | 7.2 HIGH | ||
| An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10. SQL injection can occur in the user-settings form. Exploitation is only accessible to authenticated users with high-privileged access. | |||||
| CVE-2024-45756 | 2026-06-17 | N/A | 7.2 HIGH | ||
| An issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0, 24.04.x before 24.04.2, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to create a ticket. Exploitation is only accessible to authenticated users with high-privileged access. | |||||
| CVE-2024-45755 | 2026-06-17 | N/A | 7.2 HIGH | ||
| An issue was discovered in Centreon centreon-dsm-server 24.10.x before 24.10.0, 24.04.x before 24.04.3, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to configure Centreon DSM slots. Exploitation is only accessible to authenticated users with high-privileged access. | |||||
| CVE-2024-45754 | 2026-06-17 | N/A | 7.2 HIGH | ||
| An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before 23.10.8, 23.04.x before 23.04.11, and 22.10.x before 22.10.11. SQL injection can occur in the listing of configured reporting jobs. Exploitation is only accessible to authenticated users with high-privileged access. | |||||
| CVE-2024-45622 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass. | |||||
| CVE-2024-45608 | 1 Glpi-project | 1 Glpi | 2026-06-17 | N/A | 6.5 MEDIUM |
| GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing its preferences. Upgrade to 10.0.17. | |||||
