Total
20788 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-43772 | 1 Easytest | 1 Easytest Online Test Platform | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter. | |||||
| CVE-2024-43699 | 1 Deltaww | 1 Diaenergie | 2026-06-17 | N/A | 9.8 CRITICAL |
| Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain records contained in the targeted product. | |||||
| CVE-2024-43468 | 1 Microsoft | 3 Configuration Manager 2403, Configuration Manager 2409, Configuration Manager 2503 | 2026-06-17 | N/A | 9.8 CRITICAL |
| Microsoft Configuration Manager Remote Code Execution Vulnerability | |||||
| CVE-2024-43436 | 1 Moodle | 1 Moodle | 2026-06-17 | N/A | 7.2 HIGH |
| A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators. | |||||
| CVE-2024-43415 | 2026-06-17 | N/A | 9.0 CRITICAL | ||
| An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write files or execute commands. | |||||
| CVE-2024-43406 | 1 Lfedge | 1 Ekuiper | 2026-06-17 | N/A | 8.8 HIGH |
| LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2. | |||||
| CVE-2024-43360 | 1 Zoneminder | 1 Zoneminder | 2026-06-17 | N/A | 9.8 CRITICAL |
| ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61. | |||||
| CVE-2024-43286 | 1 Squirrly | 1 Seo Plugin By Squirrly Seo | 2026-06-17 | N/A | 8.5 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Squirrly SEO Plugin by Squirrly SEO.This issue affects SEO Plugin by Squirrly SEO: from n/a through 12.3.19. | |||||
| CVE-2024-43282 | 1 Themeum | 1 Tutor Lms | 2026-06-17 | N/A | 7.6 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2. | |||||
| CVE-2024-43207 | 2026-06-17 | N/A | 8.5 HIGH | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Valiano Unite Gallery Lite.This issue affects Unite Gallery Lite: from n/a through 1.7.62. | |||||
| CVE-2024-43145 | 1 Ayecode | 1 Geodirectory | 2026-06-17 | N/A | 8.5 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode Ltd GeoDirectory.This issue affects GeoDirectory: from n/a through 2.3.61. | |||||
| CVE-2024-43144 | 1 Stylemixthemes | 1 Cost Calculator Builder | 2026-06-17 | N/A | 9.3 CRITICAL |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15. | |||||
| CVE-2024-43132 | 1 Wpwebelite | 1 Docket | 2026-06-17 | N/A | 9.3 CRITICAL |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPWeb Elite Docket (WooCommerce Collections / Wishlist / Watchlist) allows SQL Injection.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a before 1.7.0. | |||||
| CVE-2024-43040 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| Renwoxing Enterprise Intelligent Management System before v3.0 was discovered to contain a SQL injection vulnerability via the parid parameter at /fx/baseinfo/SearchInfo. | |||||
| CVE-2024-43018 | 1 Piwigo | 1 Piwigo | 2026-06-17 | N/A | 6.4 MEDIUM |
| Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters are used in ws_user_gerList function from file include\ws_functions\pwg.users.php and this same function is called by ws.php file at some point can be used for searching users in advanced way in /admin.php?page=user_list. | |||||
| CVE-2024-42994 | 1 Vtiger | 1 Vtiger Crm | 2026-06-17 | N/A | 7.2 HIGH |
| VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module. | |||||
| CVE-2024-42913 | 1 Ruoyi | 1 Ruoyi | 2026-06-17 | N/A | 9.8 CRITICAL |
| RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1. | |||||
| CVE-2024-42885 | 1 Esafenet | 1 Cdg | 2026-06-17 | N/A | 9.1 CRITICAL |
| SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page. | |||||
| CVE-2024-42844 | 2026-06-17 | N/A | 8.1 HIGH | ||
| A SQL Injection vulnerability has been identified in EPICOR Prophet 21 (P21) up to 23.2.5232. This vulnerability allows authenticated remote attackers to execute arbitrary SQL commands through unsanitized user input fields to obtain unauthorized information | |||||
| CVE-2024-42843 | 1 Projectworlds | 1 Online Examination System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Projectworlds Online Examination System v1.0 is vulnerable to SQL Injection via the subject parameter in feed.php. | |||||
