Total
20792 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-29622 | 1 Purchase Order Management Project | 1 Purchase Order Management | 2026-06-17 | N/A | 9.8 CRITICAL |
| Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /purchase_order/admin/login.php. | |||||
| CVE-2023-29598 | 1 Lmxcms | 1 Lmxcms | 2026-06-17 | N/A | 9.8 CRITICAL |
| lmxcms v1.4.1 was discovered to contain a SQL injection vulnerability via the setbook parameter at index.php. | |||||
| CVE-2023-29597 | 1 Bloofox | 1 Bloofoxcms | 2026-06-17 | N/A | 8.8 HIGH |
| bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1. | |||||
| CVE-2023-29459 | 1 Redbull | 1 Fc Red Bull Salzburg | 2026-06-17 | N/A | 6.1 MEDIUM |
| The laola.redbull application through 5.1.9-R for Android exposes the exported activity at.redbullsalzburg.android.AppMode.Default.Splash.SplashActivity, which accepts a data: URI. The target of this URI is subsequently loaded into the application's webview, thus allowing the loading of arbitrary content into the context of the application. This can occur via the fcrbs schema or an explicit intent invocation. | |||||
| CVE-2023-29432 | 1 Favethemes | 1 Houzez | 2026-06-17 | N/A | 8.2 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Favethemes Houzez - Real Estate WordPress Theme.This issue affects Houzez - Real Estate WordPress Theme: from n/a before 2.8.3. | |||||
| CVE-2023-29245 | 1 Nozominetworks | 2 Cmc, Guardian | 2026-06-17 | N/A | 8.1 HIGH |
| A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, may allow an unauthenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application by sending specially crafted malicious network packets. Malicious users with extensive knowledge on the underlying system may be able to extract arbitrary information from the DBMS in an uncontrolled way, alter its structure and data, and/or affect its availability. | |||||
| CVE-2023-29154 | 1 Contec | 1 Conprosys Hmi System | 2026-06-17 | N/A | 7.2 HIGH |
| SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative privilege may execute an arbitrary SQL command via specially crafted input to the query setting page. | |||||
| CVE-2023-29119 | 1 Enelx | 2 Waybox Pro, Waybox Pro Firmware | 2026-06-17 | N/A | 9.6 CRITICAL |
| Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.php. | |||||
| CVE-2023-29118 | 1 Enelx | 2 Waybox Pro, Waybox Pro Firmware | 2026-06-17 | N/A | 9.6 CRITICAL |
| Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.php. | |||||
| CVE-2023-29096 | 1 Bestwebsoft | 1 Contact Form To Db | 2026-06-17 | N/A | 8.5 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress.This issue affects Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress: from n/a through 1.7.0. | |||||
| CVE-2023-29095 | 1 Carrcommunications | 1 Rsvpmaker | 2026-06-17 | N/A | 7.6 HIGH |
| Auth. (admin+) SQL Injection (SQLi) vulnerability in David F. Carr RSVPMaker plugin < 10.5.5 versions. | |||||
| CVE-2023-29047 | 1 Open-xchange | 1 Open-xchange Appsuite | 2026-06-17 | N/A | 5.3 MEDIUM |
| Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements. An attacker with access to the adjacent network and potentially API credentials, could read and modify database content which is accessible to the imageconverter SQL user account. None No publicly available exploits are known. | |||||
| CVE-2023-28883 | 1 Cerebrate-project | 1 Cerebrate | 2026-06-17 | N/A | 9.8 CRITICAL |
| In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint. | |||||
| CVE-2023-28849 | 1 Glpi-project | 1 Glpi | 2026-06-17 | N/A | 10.0 CRITICAL |
| GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.7, GLPI inventory endpoint can be used to drive a SQL injection attack. It can also be used to store malicious code that could be used to perform XSS attack. By default, GLPI inventory endpoint requires no authentication. Version 10.0.7 contains a patch for this issue. As a workaround, disable native inventory. | |||||
| CVE-2023-28843 | 1 202-ecommerce | 1 Paypal | 2026-06-17 | N/A | 9.8 CRITICAL |
| PrestaShop/paypal is an open source module for the PrestaShop web commerce ecosystem which provides paypal payment support. A SQL injection vulnerability found in the PrestaShop paypal module from release from 3.12.0 to and including 3.16.3 allow a remote attacker to gain privileges, modify data, and potentially affect system availability. The cause of this issue is that SQL queries were being constructed with user input which had not been properly filtered. Only deployments on PrestaShop 1.6 are affected. Users are advised to upgrade to module version 3.16.4. There are no known workarounds for this vulnerability. | |||||
| CVE-2023-28839 | 1 Shoppingfeed | 1 Shoppingfeed | 2026-06-17 | N/A | 9.4 CRITICAL |
| Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed for PrestaShop is vulnerable to SQL injection between version 1.4.0 and 1.8.2 due to a lack of input sanitization. This issue has been addressed in version 1.8.3. Users are advised to upgrade. There are no known workarounds for this issue. | |||||
| CVE-2023-28838 | 1 Glpi-project | 1 Glpi | 2026-06-17 | N/A | 9.6 CRITICAL |
| GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 9.5.13 and 10.0.7, a SQL Injection vulnerability allow users with access rights to statistics or reports to extract all data from database and, in some cases, write a webshell on the server. Versions 9.5.13 and 10.0.7 contain a patch for this issue. As a workaround, remove `Assistance > Statistics` and `Tools > Reports` read rights from every user. | |||||
| CVE-2023-28788 | 1 Pagevisitcounter | 1 Advanced Page Visit Counter | 2026-06-17 | N/A | 7.1 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 6.4.2. | |||||
| CVE-2023-28787 | 2026-06-17 | N/A | 9.3 CRITICAL | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4. | |||||
| CVE-2023-28777 | 1 Learndash | 1 Learndash | 2026-06-17 | N/A | 8.5 HIGH |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LearnDash LearnDash LMS allows SQL Injection.This issue affects LearnDash LMS: from n/a through 4.5.3. | |||||
