Total
20789 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-29731 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/checkBlindFields/ , parameters idChallenge and idEmpresa. | |||||
| CVE-2024-29730 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/consejoRandom/ , parameter idCat;. | |||||
| CVE-2024-29729 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/generateShortURL/, parameter url. | |||||
| CVE-2024-29728 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/inscribeUsuario/ , parameter idDesafio. | |||||
| CVE-2024-29727 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sendParticipationRemember/ , parameter send. | |||||
| CVE-2024-29726 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/setAsRead/, parameter id. | |||||
| CVE-2024-29725 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sort_bloques/, parameter list. | |||||
| CVE-2024-29724 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/ax/registerSp/, parameter idDesafio. | |||||
| CVE-2024-29723 | 1 Sportsnet | 1 Sportsnet | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/conexiones/ax/openTracExt/, parameter categoria;. | |||||
| CVE-2024-29432 | 1 Alldata | 1 Alldata | 2026-06-17 | N/A | 9.8 CRITICAL |
| Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/datas. | |||||
| CVE-2024-29390 | 1 Anujk305 | 1 Daily Expenses Management System | 2026-06-17 | N/A | 7.3 HIGH |
| Daily Expenses Management System version 1.0, developed by PHP Gurukul, contains a time-based blind SQL injection vulnerability in the 'add-expense.php' page. An attacker can exploit the 'item' parameter in a POST request to execute arbitrary SQL commands in the backend database. This can be done by injecting specially crafted SQL queries that make the database perform time-consuming operations, thereby confirming the presence of the SQL injection vulnerability based on the delay in the server's response. | |||||
| CVE-2024-29386 | 1 Projeqtor | 1 Projeqtor | 2026-06-17 | N/A | 5.4 MEDIUM |
| projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceExport.php. | |||||
| CVE-2024-29320 | 1 Wallosapp | 1 Wallos | 2026-06-17 | N/A | 8.1 HIGH |
| Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php. | |||||
| CVE-2024-29303 | 1 Mayurik | 1 Php Task Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection | |||||
| CVE-2024-29302 | 1 Mayurik | 1 Php Task Management System | 2026-06-17 | N/A | 7.5 HIGH |
| SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php. | |||||
| CVE-2024-29301 | 1 Mayurik | 1 Php Task Management System | 2026-06-17 | N/A | 7.5 HIGH |
| SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id= | |||||
| CVE-2024-29275 | 1 Seacms | 1 Seacms | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php. | |||||
| CVE-2024-29239 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29238 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29237 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
