Total
20793 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-34602 | 1 Jeecg | 1 Jeecgboot | 2026-06-17 | N/A | 7.5 HIGH |
| JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryTableDictItemsByCode at org.jeecg.modules.api.controller.SystemApiController. | |||||
| CVE-2023-34601 | 1 Jeesite | 1 Jeesite | 2026-06-17 | N/A | 9.8 CRITICAL |
| Jeesite before commit 10742d3 was discovered to contain a SQL injection vulnerability via the component ${businessTable} at /act/ActDao.xml. | |||||
| CVE-2023-34600 | 1 Adiscon | 1 Loganalyzer | 2026-06-17 | N/A | 9.8 CRITICAL |
| Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection. | |||||
| CVE-2023-34581 | 1 Oretnom23 | 1 Service Provider Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2 | |||||
| CVE-2023-34577 | 1 Planned Popup Project | 1 Planned Popup | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in Prestashop opartplannedpopup 1.4.11 and earlier allows remote attackers to run arbitrary SQL commands via OpartPlannedPopupModuleFrontController::prepareHook() method. | |||||
| CVE-2023-34576 | 1 Store-opart | 1 Op\'art Product Faq | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in updatepos.php in PrestaShop opartfaq through 1.0.3 allows remote attackers to run arbitrary SQL commands via unspedified vector. | |||||
| CVE-2023-34575 | 1 Store-opart | 1 Op\'art Save Cart | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL injection vulnerability in PrestaShop opartsavecart through 2.0.7 allows remote attackers to run arbitrary SQL commands via OpartSaveCartDefaultModuleFrontController::initContent() and OpartSaveCartDefaultModuleFrontController::displayAjaxSendCartByEmail() methods. | |||||
| CVE-2023-34548 | 1 Simple Customer Relationship Management Project | 1 Simple Customer Relationship Management | 2026-06-17 | N/A | 9.8 CRITICAL |
| Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter. | |||||
| CVE-2023-34545 | 1 Cskaza | 1 Cszcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| A SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers to run arbitrary SQL commands via p parameter or the search URL. | |||||
| CVE-2023-34487 | 1 Online Hotel Management System Project | 1 Online Hotel Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to SQL Injection. SQL injection points exist in the login password input box. This vulnerability can be exploited through time-based blind injection. | |||||
| CVE-2023-34477 | 1 Braincert | 1 Virtual Classroom | 2026-06-17 | N/A | 9.8 CRITICAL |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. | |||||
| CVE-2023-34476 | 1 Mooj | 1 Proforms | 2026-06-17 | N/A | 9.8 CRITICAL |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. | |||||
| CVE-2023-34418 | 1 Lenovo | 1 Xclarity Administrator | 2026-06-17 | N/A | 8.1 HIGH |
| A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API. | |||||
| CVE-2023-34383 | 1 Wedevs | 1 Wp Project Manager | 2026-06-17 | N/A | 8.5 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This issue affects WP Project Manager: from n/a through 2.6.0. | |||||
| CVE-2023-34362 | 1 Progress | 2 Moveit Cloud, Moveit Transfer | 2026-06-17 | N/A | 9.8 CRITICAL |
| In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in May and June 2023; exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions. | |||||
| CVE-2023-34249 | 1 Pybb Project | 1 Pybb | 2026-06-17 | N/A | 9.8 CRITICAL |
| benjjvi/PyBB is an open source bulletin board. Prior to commit dcaeccd37198ecd3e41ea766d1099354b60d69c2, benjjvi/PyBB is vulnerable to SQL Injection. This vulnerability has been fixed as of commit dcaeccd37198ecd3e41ea766d1099354b60d69c2. As a workaround, a user may be able to update the software manually to avoid this problem by sanitizing user queries to `BulletinDatabaseModule.py`. | |||||
| CVE-2023-34210 | 1 Easyuse | 1 Mailhunter Ultimate | 2026-06-17 | N/A | 7.7 HIGH |
| SQL Injection in create customer group function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to execute arbitrary SQL commands via the ctl00$ContentPlaceHolder1$txtCustSQL parameter. | |||||
| CVE-2023-34179 | 1 Groundhogg | 1 Groundhogg | 2026-06-17 | N/A | 7.6 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Inc. Groundhogg allows SQL Injection.This issue affects Groundhogg: from n/a through 2.7.11. | |||||
| CVE-2023-34168 | 1 Esiteq | 1 Wp Report Post | 2026-06-17 | N/A | 7.6 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Raven WP Report Post allows SQL Injection.This issue affects WP Report Post: from n/a through 2.1.2. | |||||
| CVE-2023-34133 | 1 Sonicwall | 2 Analytics, Global Management System | 2026-06-17 | N/A | 7.5 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. | |||||
