Total
20803 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-40989 | 1 Jeecg | 1 Jeecg Boot | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component. | |||||
| CVE-2023-40970 | 1 Slims | 1 Senayan Library Management System | 2026-06-17 | N/A | 8.8 HIGH |
| Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php. | |||||
| CVE-2023-40958 | 1 Didotech | 1 Engineering \& Lifecycle Management | 2026-06-17 | N/A | 8.8 HIGH |
| A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the query parameter in models/base_client.py component. | |||||
| CVE-2023-40957 | 1 Didotech | 1 Engineering \& Lifecycle Management | 2026-06-17 | N/A | 8.8 HIGH |
| A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the request parameter in models/base_client.py component. | |||||
| CVE-2023-40956 | 1 Cloudroits | 1 Wesite Job Search | 2026-06-17 | N/A | 8.8 HIGH |
| A SQL injection vulnerability in Cloudroits Website Job Search v.15.0 allows a remote authenticated attacker to execute arbitrary code via the name parameter in controllers/main.py component. | |||||
| CVE-2023-40955 | 1 Didotech | 1 Engineering \& Lifecycle Management | 2026-06-17 | N/A | 8.8 HIGH |
| A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the select parameter in models/base_client.py component. | |||||
| CVE-2023-40954 | 1 Gmarczynski | 1 Dynamic Progress Bar | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component. | |||||
| CVE-2023-40946 | 1 Schoolmate Project | 1 Schoolmate | 2026-06-17 | N/A | 9.8 CRITICAL |
| Schoolmate 1.3 is vulnerable to SQL Injection in the variable $username from SESSION in ValidateLogin.php. | |||||
| CVE-2023-40945 | 1 Doctor Appointment System Project | 1 Doctor Appointment System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php. | |||||
| CVE-2023-40944 | 1 Schoolmate Project | 1 Schoolmate | 2026-06-17 | N/A | 9.8 CRITICAL |
| Schoolmate 1.3 is vulnerable to SQL Injection in the variable $schoolname from Database at ~\header.php. | |||||
| CVE-2023-40923 | 1 Myprestamodules | 1 Orders \(csv\, Excel\) Export Pro | 2026-06-17 | N/A | 8.8 HIGH |
| MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and save_setting parameters. | |||||
| CVE-2023-40922 | 1 Kerawen | 1 Kerawen | 2026-06-17 | N/A | 9.8 CRITICAL |
| kerawen before v2.5.1 was discovered to contain a SQL injection vulnerability via the ocs_id_cart parameter at KerawenDeliveryModuleFrontController::initContent(). | |||||
| CVE-2023-40921 | 1 Common-services | 1 Soliberte | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters. | |||||
| CVE-2023-40920 | 1 Prixan | 1 Prixanconnect | 2026-06-17 | N/A | 9.8 CRITICAL |
| Prixan prixanconnect up to v1.62 was discovered to contain a SQL injection vulnerability via the component CartsGuruCatalogModuleFrontController::importProducts(). | |||||
| CVE-2023-40852 | 1 User Registration \& Login And User Management System With Admin Panel Project | 1 User Registration \& Login And User Management System With Admin Panel | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page. | |||||
| CVE-2023-40787 | 1 Bladex | 1 Springblade | 2026-06-17 | N/A | 9.8 CRITICAL |
| In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection. | |||||
| CVE-2023-40771 | 1 Dataease | 1 Dataease | 2026-06-17 | N/A | 7.5 HIGH |
| SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function. | |||||
| CVE-2023-40749 | 1 Phpjabbers | 1 Food Delivery Script | 2026-06-17 | N/A | 9.8 CRITICAL |
| PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php. | |||||
| CVE-2023-40748 | 1 Phpjabbers | 1 Food Delivery Script | 2026-06-17 | N/A | 9.8 CRITICAL |
| PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php. | |||||
| CVE-2023-40629 | 1 King-products | 1 Lms King Lite | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQLi vulnerability in LMS Lite component for Joomla. | |||||
