Total
20788 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-34532 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allows a remote attacker to gain privileges via the query parameter to models/querydeluxe.py:QueryDeluxe::get_result_from_query. | |||||
| CVE-2024-34480 | 1 Oretnom23 | 1 Computer Laboratory Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection. | |||||
| CVE-2024-34479 | 1 Oretnom23 | 1 Computer Laboratory Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection. | |||||
| CVE-2024-34472 | 1 Hsclabs | 1 Mailinspector | 2026-06-17 | N/A | 5.5 MEDIUM |
| An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in a POST request to /mailinspector/mliRealtimeEmails.php does not properly sanitize input, allowing an authenticated attacker to execute arbitrary SQL commands, leading to the potential disclosure of the entire application database. | |||||
| CVE-2024-34458 | 1 Keyfactor | 1 Command | 2026-06-17 | N/A | 7.5 HIGH |
| Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure. | |||||
| CVE-2024-34412 | 2026-06-17 | N/A | 8.5 HIGH | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Parcel Panel ParcelPanel.This issue affects ParcelPanel: from n/a through 3.8.1. | |||||
| CVE-2024-34386 | 2026-06-17 | N/A | 7.6 HIGH | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Auto Affiliate Links.This issue affects Auto Affiliate Links: from n/a through 6.4.3.1. | |||||
| CVE-2024-34327 | 1 Sielox | 1 Anyware | 2026-06-17 | N/A | 6.5 MEDIUM |
| Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the password reset form. | |||||
| CVE-2024-34310 | 2026-06-17 | N/A | 8.8 HIGH | ||
| Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter. | |||||
| CVE-2024-34256 | 1 Ofcms Project | 1 Ofcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function. | |||||
| CVE-2024-34226 | 1 Oretnom23 | 1 Visitor Management System | 2026-06-17 | N/A | 9.4 CRITICAL |
| SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters. | |||||
| CVE-2024-34222 | 1 Oretnom23 | 1 Human Resource Management System | 2026-06-17 | N/A | 5.9 MEDIUM |
| Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter. | |||||
| CVE-2024-34220 | 1 Oretnom23 | 1 Human Resource Management System | 2026-06-17 | N/A | 7.5 HIGH |
| Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter. | |||||
| CVE-2024-34032 | 1 Deltaww | 1 Diaenergie | 2026-06-17 | N/A | 8.8 HIGH |
| Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed. | |||||
| CVE-2024-34031 | 1 Deltaww | 1 Diaenergie | 2026-06-17 | N/A | 8.8 HIGH |
| Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed. | |||||
| CVE-2024-33974 | 1 Janobe | 2 School Attendence Monitoring System, School Event Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Users in '/report/printlogs.php' parameter. | |||||
| CVE-2024-33973 | 1 Janobe | 5 Credit Card, Debit Card Payment, Paypal and 2 more | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Attendance' and 'YearLevel' in '/report/attendance_print.php' parameter. | |||||
| CVE-2024-33972 | 1 Janobe | 5 Credit Card, Debit Card Payment, Paypal and 2 more | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'events' in '/report/event_print.php' parameter. | |||||
| CVE-2024-33971 | 1 Janobe | 5 Credit Card, Debit Card Payment, Paypal and 2 more | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'username' in '/login.php' parameter. | |||||
| CVE-2024-33970 | 1 Janobe | 5 Credit Card, Debit Card Payment, Paypal and 2 more | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'studid' in '/candidate/controller.php' parameter. | |||||
