Total
20789 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-48590 | 1 Sciencelogic | 1 Sl1 | 2026-06-17 | N/A | 8.8 HIGH |
| A SQL injection vulnerability exists in the “admin dynamic app mib errors” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |||||
| CVE-2022-48589 | 1 Sciencelogic | 1 Sl1 | 2026-06-17 | N/A | 8.8 HIGH |
| A SQL injection vulnerability exists in the “reporting job editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |||||
| CVE-2022-48588 | 1 Sciencelogic | 1 Sl1 | 2026-06-17 | N/A | 8.8 HIGH |
| A SQL injection vulnerability exists in the “schedule editor decoupled” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |||||
| CVE-2022-48587 | 1 Sciencelogic | 1 Sl1 | 2026-06-17 | N/A | 8.8 HIGH |
| A SQL injection vulnerability exists in the “schedule editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |||||
| CVE-2022-48586 | 1 Sciencelogic | 1 Sl1 | 2026-06-17 | N/A | 8.8 HIGH |
| A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |||||
| CVE-2022-48585 | 1 Sciencelogic | 1 Sl1 | 2026-06-17 | N/A | 8.8 HIGH |
| A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database. | |||||
| CVE-2022-48152 | 1 Remoteclinic | 1 Remote Clinic | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in RemoteClinic 2.0 allows attackers to execute arbitrary commands and gain sensitive information via the id parameter to /medicines/profile.php. | |||||
| CVE-2022-48149 | 1 Online Student Admission System Project | 1 Online Student Admission System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | |||||
| CVE-2022-48120 | 1 Hospital Management System Project | 1 Hospital Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php. | |||||
| CVE-2022-48114 | 1 Ruoyi | 1 Ruoyi | 2026-06-17 | N/A | 9.8 CRITICAL |
| RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable. | |||||
| CVE-2022-48090 | 1 Hotel Management System Project | 1 Hotel Management System | 2026-06-17 | N/A | 6.5 MEDIUM |
| Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to SQL Injection via /app/dao/CustomerDAO.php. | |||||
| CVE-2022-48082 | 1 Easyone | 1 Easyone Crm | 2026-06-17 | N/A | 9.8 CRITICAL |
| Easyone CRM v5.50.02 was discovered to contain a SQL Injection vulnerability via the text parameter at /Services/Misc.asmx/SearchTag. | |||||
| CVE-2022-48011 | 1 Opencats | 1 Opencats | 2026-06-17 | N/A | 9.8 CRITICAL |
| Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function. | |||||
| CVE-2022-47984 | 3 Ibm, Linux, Microsoft | 4 Aix, Infosphere Information Server, Linux Kernel and 1 more | 2026-06-17 | N/A | 6.3 MEDIUM |
| IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 243163. | |||||
| CVE-2022-47866 | 1 Lead Management System Project | 1 Lead Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php. | |||||
| CVE-2022-47865 | 1 Lead Management System Project | 1 Lead Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php. | |||||
| CVE-2022-47864 | 1 Lead Management System Project | 1 Lead Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php. | |||||
| CVE-2022-47862 | 1 Lead Management System Project | 1 Lead Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php. | |||||
| CVE-2022-47861 | 1 Lead Management System Project | 1 Lead Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php. | |||||
| CVE-2022-47860 | 1 Lead Management System Project | 1 Lead Management System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php. | |||||
