Total
20789 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-27956 | 1 Valvepress | 1 Automatic | 2026-06-17 | N/A | 9.9 CRITICAL |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0. | |||||
| CVE-2024-27941 | 1 Siemens | 1 Ruggedcom Crossbow | 2026-06-17 | N/A | 8.8 HIGH |
| A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected client systems do not properly sanitize input data before sending it to the SQL server. An attacker could use this vulnerability to compromise the whole database. | |||||
| CVE-2024-27940 | 1 Siemens | 1 Ruggedcom Crossbow | 2026-06-17 | N/A | 8.8 HIGH |
| A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow any authenticated user to send arbitrary SQL commands to the SQL server. An attacker could use this vulnerability to compromise the whole database. | |||||
| CVE-2024-27889 | 1 Arista | 1 Ng Firewall | 2026-06-17 | N/A | 8.8 HIGH |
| Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges. | |||||
| CVE-2024-27746 | 1 Mayurik | 1 Petrol Pump Management | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component. | |||||
| CVE-2024-27718 | 2026-06-17 | N/A | 7.8 HIGH | ||
| SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component. | |||||
| CVE-2024-27709 | 2026-06-17 | N/A | 9.8 CRITICAL | ||
| SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the searchby parameter of the allstudents.php component and the id parameter of the requestmanager.php component. | |||||
| CVE-2024-27685 | 1 Phpgurukul | 1 Student Record System | 2026-06-17 | N/A | 7.1 HIGH |
| SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensitive information via a crafted payload to the $cshortname, $cfullname, and $cdate variables. | |||||
| CVE-2024-27574 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| SQL Injection vulnerability in Trainme Academy version Ichin v.1.3.2 allows a remote attacker to obtain sensitive information via the informacion, idcurso, and tit parameters. | |||||
| CVE-2024-27515 | 1 Mindstellar | 1 Osclass | 2026-06-17 | N/A | 7.2 HIGH |
| Osclass 5.1.2 is vulnerable to SQL Injection. | |||||
| CVE-2024-27304 | 1 Jackc | 2 Pgproto3, Pgx | 2026-06-17 | N/A | 9.8 CRITICAL |
| pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size. | |||||
| CVE-2024-27299 | 1 Phpmyfaq | 1 Phpmyfaq | 2026-06-17 | N/A | 8.8 HIGH |
| phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection vulnerability has been discovered in the the "Add News" functionality due to improper escaping of the email address. This allows any authenticated user with the rights to add/edit FAQ news to exploit this vulnerability to exfiltrate data, take over accounts and in some cases, even achieve RCE. The vulnerable field lies in the `authorEmail` field which uses PHP's `FILTER_VALIDATE_EMAIL` filter. This filter is insufficient in protecting against SQL injection attacks and should still be properly escaped. However, in this version of phpMyFAQ (3.2.5), this field is not escaped properly can be used together with other fields to fully exploit the SQL injection vulnerability. This vulnerability is fixed in 3.2.6. | |||||
| CVE-2024-27298 | 1 Parseplatform | 1 Parse-server | 2026-06-17 | N/A | 10.0 CRITICAL |
| parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database. The vulnerability has been fixed in 6.5.0 and 7.0.0-alpha.20. | |||||
| CVE-2024-27289 | 1 Jackc | 1 Pgx | 2026-06-17 | N/A | 8.1 HIGH |
| pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: the non-default simple protocol is used; a placeholder for a numeric value must be immediately preceded by a minus; there must be a second placeholder for a string value after the first placeholder; both must be on the same line; and both parameter values must be user-controlled. The problem is resolved in v4.18.2. As a workaround, do not use the simple protocol or do not place a minus directly before a placeholder. | |||||
| CVE-2024-27112 | 1 Soplanning | 1 Soplanning | 2026-06-17 | N/A | 9.8 CRITICAL |
| A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database. The vulnerability has been remediated in version 1.52.02. | |||||
| CVE-2024-27096 | 1 Glpi-project | 1 Glpi | 2026-06-17 | N/A | 7.7 HIGH |
| GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can exploit a SQL injection vulnerability in the search engine to extract data from the database. This issue has been patched in version 10.0.13. | |||||
| CVE-2024-26264 | 1 Ebmtech | 1 Risweb | 2026-06-17 | N/A | 9.8 CRITICAL |
| EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers to inject SQL commands without authentication, enabling them to read, modify, and delete database records. | |||||
| CVE-2024-26262 | 1 Ebmtech | 1 Uniweb\/solipacs Webserver | 2026-06-17 | N/A | 8.8 HIGH |
| EBM Technologies Uniweb/SoliPACS WebServer's query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL commands for reading, modifying, and deleting database records, as well as executing system commands. Attackers may even leverage the dbo privilege in the database for privilege escalation, elevating their privileges to administrator . | |||||
| CVE-2024-26026 | 1 F5 | 1 Big-ip Next Central Manager | 2026-06-17 | N/A | 7.5 HIGH |
| An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |||||
| CVE-2024-25937 | 1 Deltaww | 1 Diaenergie | 2026-06-17 | N/A | 8.8 HIGH |
| SQL injection vulnerability exists in the script DIAE_tagHandler.ashx. | |||||
