Total
20789 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-28557 | 1 Mayurik | 1 Php Task Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to update-admin.php. | |||||
| CVE-2024-28556 | 1 Mayurik | 1 Php Task Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin-manage-user.php. | |||||
| CVE-2024-28521 | 1 Netentsec | 2 Application Security Gateway Firmware, Ns-asg | 2026-06-17 | N/A | 7.8 HIGH |
| SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted script to the loginid parameter of the /singlelogin.php component. | |||||
| CVE-2024-28421 | 1 Cobub | 1 Razor | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updateapk method of the channelmodle.php | |||||
| CVE-2024-28395 | 1 Best-kit | 1 Bestkit Popup | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component. | |||||
| CVE-2024-28393 | 1 Scalapay | 1 Scalapay | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in scalapay v.1.2.41 and before allows a remote attacker to escalate privileges via the ScalapayReturnModuleFrontController::postProcess() method. | |||||
| CVE-2024-28392 | 1 Prestashop | 1 Abandoned Cart Reminder Pro | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method. | |||||
| CVE-2024-28389 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail() method. | |||||
| CVE-2024-28388 | 1 Sunnytoo | 1 Product Comments | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method. | |||||
| CVE-2024-28323 | 1 Phpgurukul | 1 User Registration \& Login And User Management System | 2026-06-17 | N/A | 6.5 MEDIUM |
| The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The script retrieves user-provided date inputs without proper validation, making it susceptible to SQL injection attacks. | |||||
| CVE-2024-28322 | 1 Puneethreddyhc | 1 Event Management | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST request. | |||||
| CVE-2024-28303 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php. | |||||
| CVE-2024-28298 | 1 E-bmsoft | 1 Bmplanning | 2026-06-17 | N/A | 8.8 HIGH |
| SQL injection vulnerability in BM SOFT BMPlanning 1.0.0.1 allows authenticated users to execute arbitrary SQL commands via the SEC_IDF, LIE_IDF, PLANF_IDF, CLI_IDF, DOS_IDF, and possibly other parameters to /BMServerR.dll/BMRest. | |||||
| CVE-2024-28297 | 2026-06-17 | N/A | 7.5 HIGH | ||
| SQL injection vulnerability in AzureSoft MyHorus 4.3.5 allows authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
| CVE-2024-28294 | 1 Limbas | 1 Limbas | 2026-06-17 | N/A | 6.5 MEDIUM |
| Limbas up to v5.2.14 was discovered to contain a SQL injection vulnerability via the ftid parameter. | |||||
| CVE-2024-28279 | 1 Carmelo | 1 Computer Book Store | 2026-06-17 | N/A | 7.3 HIGH |
| Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=. | |||||
| CVE-2024-28145 | 2026-06-17 | N/A | 5.9 MEDIUM | ||
| An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword. | |||||
| CVE-2024-28107 | 1 Phpmyfaq | 1 Phpmyfaq | 2026-06-17 | N/A | 8.8 HIGH |
| phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection vulnerability has been discovered in the `insertentry` & `saveentry` when modifying records due to improper escaping of the email address. This allows any authenticated user with the rights to add/edit FAQ news to exploit this vulnerability to exfiltrate data, take over accounts and in some cases, even achieve RCE. This vulnerability is fixed in 3.2.6. | |||||
| CVE-2024-28094 | 1 Schoolbox | 1 Schoolbox | 2026-06-17 | N/A | 8.8 HIGH |
| Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the authenticated attackers to read, modify, and delete database records. | |||||
| CVE-2024-28040 | 1 Deltaww | 1 Diaenergie | 2026-06-17 | N/A | 8.8 HIGH |
| SQL injection vulnerability exists in GetDIAE_astListParameters. | |||||
