Total
20788 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-31241 | 2026-06-17 | N/A | 7.6 HIGH | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress LearnPress Export Import.This issue affects LearnPress Export Import: from n/a through 4.0.3. | |||||
| CVE-2024-31234 | 2026-06-17 | N/A | 8.5 HIGH | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sizam REHub Framework.This issue affects REHub Framework: from n/a before 19.6.2. | |||||
| CVE-2024-31233 | 2026-06-17 | N/A | 8.5 HIGH | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sizam Rehub.This issue affects Rehub: from n/a through 19.6.1. | |||||
| CVE-2024-31212 | 1 Instantcms | 1 Instantcms | 2026-06-17 | N/A | 6.7 MEDIUM |
| InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can cause the application to execute unauthorized SQL code. The vulnerability exists in index_chart_data action, which receives an input from user and passes it unsanitized to the core model `filterFunc` function that further embeds this data in an SQL statement. This allows attackers to inject unwanted SQL code into the statement. The `period` should be escaped before inserting it in the query. As of time of publication, a patched version is not available. | |||||
| CVE-2024-31116 | 1 10web | 1 Map Builder For Google Maps | 2026-06-17 | N/A | 7.6 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web 10Web Map Builder for Google Maps.This issue affects 10Web Map Builder for Google Maps: from n/a through 1.0.74. | |||||
| CVE-2024-31077 | 1 Incsub | 1 Forminator | 2026-06-17 | N/A | 7.2 HIGH |
| Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain and alter any information in the database and cause a denial-of-service (DoS) condition. | |||||
| CVE-2024-31025 | 2026-06-17 | N/A | 7.5 HIGH | ||
| SQL Injection vulnerability in ECshop 4.x allows an attacker to obtain sensitive information via the file/article.php component. | |||||
| CVE-2024-31010 | 1 Sem-cms | 1 Semcms | 2026-06-17 | N/A | 7.5 HIGH |
| SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php. | |||||
| CVE-2024-31009 | 1 Sem-cms | 1 Semcms | 2026-06-17 | N/A | 6.5 MEDIUM |
| SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter in Banner.php. | |||||
| CVE-2024-30998 | 1 Phpgurukul | 1 Men Salon Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via the email parameter in the index.php component. | |||||
| CVE-2024-30990 | 1 Phpgurukul | 1 Client Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "searchdata" parameter. | |||||
| CVE-2024-30985 | 1 Phpgurukul | 1 Client Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "todate" and "fromdate" parameters. | |||||
| CVE-2024-30983 | 1 Phpgurukul | 1 Cyber Cafe Management System | 2026-06-17 | N/A | 7.3 HIGH |
| SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the compname parameter in /edit-computer-detail.php file. | |||||
| CVE-2024-30982 | 1 Phpgurukul | 1 Cyber Cafe Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file. | |||||
| CVE-2024-30981 | 1 Phpgurukul | 1 Cyber Cafe Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in /edit-computer-detail.php in phpgurukul Cyber Cafe Management System Using PHP & MySQL v1.0 allows attackers to run arbitrary SQL commands via editid in the application URL. | |||||
| CVE-2024-30980 | 1 Phpgurukul | 1 Cyber Cafe Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the Computer Location parameter in manage-computer.php page. | |||||
| CVE-2024-30974 | 1 Tramyardg | 1 Autoexpress | 2026-06-17 | N/A | 7.3 HIGH |
| SQL Injection vulnerability in autoexpress v.1.3.0 allows attackers to run arbitrary SQL commands via the carId parameter. | |||||
| CVE-2024-30938 | 1 Sem-cms | 1 Semcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component. | |||||
| CVE-2024-30928 | 1 Derbynet | 1 Derbynet | 2026-06-17 | N/A | 8.1 HIGH |
| SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids' Parameter in ajax/query.slide.next.inc | |||||
| CVE-2024-30922 | 1 Derbynet | 1 Derbynet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in Award Document Rendering. | |||||
