Total
20803 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-41525 | 1 Kishan0725 | 1 Hospital Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php. | |||||
| CVE-2023-41524 | 1 Student Attendance Management System Project | 1 Student Attendance Management System | 2026-06-17 | N/A | 8.8 HIGH |
| Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index.php. | |||||
| CVE-2023-41523 | 1 Student Attendance Management System Project | 1 Student Attendance Management System | 2026-06-17 | N/A | 8.8 HIGH |
| Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher.php. | |||||
| CVE-2023-41522 | 1 Student Attendance Management System Project | 1 Student Attendance Management System | 2026-06-17 | N/A | 8.8 HIGH |
| Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents.php via the Id, firstname, and admissionNumber parameters. | |||||
| CVE-2023-41521 | 1 Student Attendance Management System Project | 1 Student Attendance Management System | 2026-06-17 | N/A | 8.8 HIGH |
| Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessionTerm.php via the id, termId, and sessionName parameters. | |||||
| CVE-2023-41520 | 1 Student Attendance Management System Project | 1 Student Attendance Management System | 2026-06-17 | N/A | 8.8 HIGH |
| Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassArms.php via the classId and classArmName parameters. | |||||
| CVE-2023-41507 | 1 Superstorefinder | 1 Super Store Finder | 2026-06-17 | N/A | 9.8 CRITICAL |
| Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters. | |||||
| CVE-2023-41504 | 1 Code-projects | 1 Student Enrollment | 2026-06-17 | N/A | 8.8 HIGH |
| SQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Search function. | |||||
| CVE-2023-41443 | 1 Xxyopen | 1 Novel-plus | 2026-06-17 | N/A | 7.2 HIGH |
| SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list. | |||||
| CVE-2023-41387 | 2 Apple, Patreon | 2 Iphone Os, Flutter Downloader | 2026-06-17 | N/A | 9.1 CRITICAL |
| A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses UIFileSharingEnabled and LSSupportsOpeningDocumentsInPlace properties. As a result, local users can obtain the same attack primitives as remote attackers by tampering with the internal database of the framework on the device. | |||||
| CVE-2023-41364 | 1 Metaways | 1 Tine | 2026-06-17 | N/A | 9.8 CRITICAL |
| In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection. | |||||
| CVE-2023-41328 | 1 Frappe | 1 Frappe | 2026-06-17 | N/A | 4.2 MEDIUM |
| Frappe is a low code web framework written in Python and Javascript. A SQL Injection vulnerability has been identified in the Frappe Framework which could allow a malicious actor to access sensitive information. This issue has been addressed in versions 13.46.1 and 14.20.0. Users are advised to upgrade. There's no workaround to fix this without upgrading. | |||||
| CVE-2023-41320 | 1 Glpi-project | 1 Glpi | 2026-06-17 | N/A | 8.1 HIGH |
| GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. UI layout preferences management can be hijacked to lead to SQL injection. This injection can be use to takeover an administrator account. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability. | |||||
| CVE-2023-41287 | 1 Qnap | 1 Video Station | 2026-06-17 | N/A | 4.3 MEDIUM |
| A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.2 ( 2023/11/23 ) and later | |||||
| CVE-2023-41285 | 1 Qnap | 1 Qumagie | 2026-06-17 | N/A | 7.4 HIGH |
| A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: QuMagie 2.1.4 and later | |||||
| CVE-2023-41284 | 1 Qnap | 1 Qumagie | 2026-06-17 | N/A | 7.4 HIGH |
| A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: QuMagie 2.1.4 and later | |||||
| CVE-2023-41262 | 1 Plixer | 1 Scrutinizer | 2026-06-17 | N/A | 9.8 CRITICAL |
| An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV is vulnerable to SQL injection through the sorting parameter, allowing an unauthenticated user to execute arbitrary SQL statements in the context of the application's backend database server. | |||||
| CVE-2023-41015 | 1 Code-projects | 1 Online Job Portal | 2026-06-17 | N/A | 5.5 MEDIUM |
| code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via /Employer/DeleteJob.php?JobId=1. | |||||
| CVE-2023-41014 | 1 Code-projects | 1 Online Job Portal | 2026-06-17 | N/A | 9.8 CRITICAL |
| code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer." | |||||
| CVE-2023-40992 | 1 Kishan0725 | 1 Hospital Management System | 2026-06-17 | N/A | 6.5 MEDIUM |
| Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 parameter. | |||||
