Total
20803 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-44163 | 1 Projectworlds | 1 Online Movie Ticket Booking System | 2026-06-17 | N/A | 9.8 CRITICAL |
| The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database. | |||||
| CVE-2023-44091 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 7.5 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. This ulnerability allowed SQL injections to be made even if authentication failed.This issue affects Pandora FMS: from 700 through <776. | |||||
| CVE-2023-44090 | 1 Artica | 1 Pandora Fms | 2026-06-17 | N/A | 6.8 MEDIUM |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows CVE-2008-5817. This vulnerability allowed SQL changes to be made to several files in the Grafana module. This issue affects Pandora FMS: from 700 through <776. | |||||
| CVE-2023-44088 | 1 Pandorafms | 1 Pandora Fms | 2026-06-17 | N/A | 5.9 MEDIUM |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700 through 774. | |||||
| CVE-2023-44047 | 1 Oretnom23 | 1 Toll Tax Management System | 2026-06-17 | N/A | 7.2 HIGH |
| Sourcecodester Toll Tax Management System v1 is vulnerable to SQL Injection. | |||||
| CVE-2023-44044 | 1 Superstorefinder | 1 Super Store Finder | 2026-06-17 | N/A | 7.2 HIGH |
| Super Store Finder v3.6 and below was discovered to contain a SQL injection vulnerability via the Search parameter at /admin/stores.php. | |||||
| CVE-2023-44025 | 1 Addify | 1 Free Gifts | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in addify Addifyfreegifts v.1.0.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the getrulebyid function in the AddifyfreegiftsModel.php component. | |||||
| CVE-2023-44024 | 1 Knowband | 1 One Page Checkout\, Social Login \& Mailchimp | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in KnowBand Module One Page Checkout, Social Login & Mailchimp (supercheckout) v.8.0.3 and before allows a remote attacker to execute arbitrary code via a crafted request to the updateCheckoutBehaviour function in the supercheckout.php component. | |||||
| CVE-2023-43986 | 1 Dmconcept | 1 Configurator | 2026-06-17 | N/A | 9.8 CRITICAL |
| DM Concept configurator before v4.9.4 was discovered to contain a SQL injection vulnerability via the component ConfiguratorAttachment::getAttachmentByToken. | |||||
| CVE-2023-43985 | 1 Sunnytoo | 1 Stblogsearch | 2026-06-17 | N/A | 9.8 CRITICAL |
| SunnyToo stblogsearch up to v1.0.0 was discovered to contain a SQL injection vulnerability via the StBlogSearchClass::prepareSearch component. | |||||
| CVE-2023-43983 | 1 Presto-changeo | 1 Attribute Grid | 2026-06-17 | N/A | 9.8 CRITICAL |
| Presto Changeo attributegrid up to 2.0.3 was discovered to contain a SQL injection vulnerability via the component disable_json.php. | |||||
| CVE-2023-43980 | 1 Presto-changeo | 1 Testsitecreator | 2026-06-17 | N/A | 9.8 CRITICAL |
| Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php. | |||||
| CVE-2023-43979 | 1 Prestahero | 1 Ybc Blog | 2026-06-17 | N/A | 9.8 CRITICAL |
| ETS Soft ybc_blog before v4.4.0 was discovered to contain a SQL injection vulnerability via the component Ybc_blogBlogModuleFrontController::getPosts(). | |||||
| CVE-2023-43909 | 1 Hospital Management System Project | 1 Hospital Management System | 2026-06-17 | N/A | 9.1 CRITICAL |
| Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php. | |||||
| CVE-2023-43899 | 1 Hansuncms Project | 1 Hansuncms | 2026-06-17 | N/A | 9.8 CRITICAL |
| hansun CMS v1.0 was discovered to contain a SQL injection vulnerability via the component /ajax/ajax_login.ashx. | |||||
| CVE-2023-43836 | 1 Jizhicms | 1 Jizhicms | 2026-06-17 | N/A | 6.5 MEDIUM |
| There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information | |||||
| CVE-2023-43813 | 1 Glpi-project | 1 Glpi | 2026-06-17 | N/A | 6.5 MEDIUM |
| GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, the saved search feature can be used to perform a SQL injection. Version 10.0.11 contains a patch for the issue. | |||||
| CVE-2023-43794 | 1 Nocodb | 1 Nocodb | 2026-06-17 | N/A | 6.5 MEDIUM |
| Nocodb is an open source Airtable alternative. Affected versions of nocodb contain a SQL injection vulnerability, that allows an authenticated attacker with creator access to query the underlying database. By supplying a specially crafted payload to the given an attacker can inject arbitrary SQL queries to be executed. Since this is a blind SQL injection, an attacker may need to use time-based payloads which would include a function to delay execution for a given number of seconds. The response time indicates, whether the result of the query execution was true or false. Depending on the result, the HTTP response will be returned after a given number of seconds, indicating TRUE, or immediately, indicating FALSE. In that way, an attacker can reveal the data present in the database. This vulnerability has been addressed in version 0.111.0. Users are advised to upgrade. There are no known workarounds for this vulnerability. This issue is also tracked as `GHSL-2023-141`. | |||||
| CVE-2023-43743 | 1 Zultys | 12 Mx-e, Mx-e Firmware, Mx-se and 9 more | 2026-06-17 | N/A | 8.8 HIGH |
| A SQL injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an authenticated attacker to execute arbitrary SQL queries on the backend database via the filter parameter in requests to the /newapi/ endpoint in the Zultys MX web interface. | |||||
| CVE-2023-43739 | 1 Online Book Store Project Project | 1 Online Book Store Project | 2026-06-17 | N/A | 9.8 CRITICAL |
| The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database. | |||||
