Total
20789 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-29236 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29235 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29234 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29233 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Emap.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29232 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Alert.Enum webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29230 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29227 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 5.4 MEDIUM |
| Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive information and conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29174 | 1 Dell | 1 Data Domain Operating System | 2026-06-17 | N/A | 4.4 MEDIUM |
| Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized access to application data. | |||||
| CVE-2024-29169 | 1 Dell | 1 Secure Connect Gateway | 2026-06-17 | N/A | 5.4 MEDIUM |
| Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal audit REST API. A remote authenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing potential unauthorized access and modification of application data. | |||||
| CVE-2024-29168 | 1 Dell | 1 Secure Connect Gateway | 2026-06-17 | N/A | 5.4 MEDIUM |
| Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal assets REST API. A remote authenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing potential unauthorized access and modification of application data. | |||||
| CVE-2024-29031 | 1 Layer5 | 1 Meshery | 2026-06-17 | N/A | 7.5 HIGH |
| Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery prior to version 0.7.17 allows a remote attacker to obtain sensitive information via the `order` parameter of `GetMeshSyncResources`. Version 0.7.17 contains a patch for this issue. | |||||
| CVE-2024-29001 | 1 Solarwinds | 1 Solarwinds Platform | 2026-06-17 | N/A | 7.5 HIGH |
| A SolarWinds Platform SWQL Injection Vulnerability was identified in the user interface. This vulnerability requires authentication and user interaction to be exploited. | |||||
| CVE-2024-28996 | 1 Solarwinds | 1 Solarwinds Platform | 2026-06-17 | N/A | 7.5 HIGH |
| The SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for this vulnerability. | |||||
| CVE-2024-28891 | 1 Deltaww | 1 Diaenergie | 2026-06-17 | N/A | 8.8 HIGH |
| SQL injection vulnerability exists in the script Handler_CFG.ashx. | |||||
| CVE-2024-28816 | 2026-06-17 | N/A | 7.1 HIGH | ||
| Student Information Chatbot a0196ab allows SQL injection via the username to the login function in index.php. | |||||
| CVE-2024-28613 | 1 Mayurik | 1 Php Task Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component. | |||||
| CVE-2024-28595 | 1 Walterjnr1 | 1 Employee Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter in update-admin.php. | |||||
| CVE-2024-28560 | 1 Niushop | 1 B2b2c Multi-business | 2026-06-17 | N/A | 5.4 MEDIUM |
| SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Address.php component. | |||||
| CVE-2024-28559 | 1 Niushop | 1 B2b2c Multi-business | 2026-06-17 | N/A | 8.8 HIGH |
| SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPrice() function of the Goodsbatchset.php component. | |||||
| CVE-2024-28558 | 1 Mayurik | 1 Petrol Pump Management | 2026-06-17 | N/A | 8.8 HIGH |
| SQL Injection vulnerability in sourcecodester Petrol pump management software v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin/app/web_crud.php. | |||||
