Total
20788 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-38595 | 1 Church Management System Project | 1 Church Management System | 2026-06-17 | N/A | 7.2 HIGH |
| Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_user.php. | |||||
| CVE-2022-38594 | 1 Church Management System Project | 1 Church Management System | 2026-06-17 | N/A | 7.2 HIGH |
| Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_visitor.php. | |||||
| CVE-2022-38576 | 1 Janobe | 1 Interview Management System | 2026-06-17 | N/A | 7.2 HIGH |
| Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/delete.php?action=deletecand&id=. | |||||
| CVE-2022-38542 | 1 Archerydms | 1 Archery | 2026-06-17 | N/A | 9.8 CRITICAL |
| Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill_session interface. The project has released an update, please upgrade to v1.9.0 and above. | |||||
| CVE-2022-38541 | 1 Archerydms | 1 Archery | 2026-06-17 | N/A | 9.8 CRITICAL |
| Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface. | |||||
| CVE-2022-38540 | 1 Archerydms | 1 Archery | 2026-06-17 | N/A | 9.8 CRITICAL |
| Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface. | |||||
| CVE-2022-38539 | 1 Archerydms | 1 Archery | 2026-06-17 | N/A | 9.8 CRITICAL |
| Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/apply. | |||||
| CVE-2022-38538 | 1 Archerydms | 1 Archery | 2026-06-17 | N/A | 9.8 CRITICAL |
| Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the report module. | |||||
| CVE-2022-38537 | 1 Archerydms | 1 Archery | 2026-06-17 | N/A | 9.8 CRITICAL |
| Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, start_time, and stop_time parameters in the binlog2sql interface. | |||||
| CVE-2022-38509 | 1 Wedding Planner Project | 1 Wedding Planner | 2026-06-17 | N/A | 9.8 CRITICAL |
| Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php. | |||||
| CVE-2022-38492 | 1 Easyvista | 1 Service Manager | 2026-06-17 | N/A | 7.7 HIGH |
| An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes the vulnerability. | |||||
| CVE-2022-38490 | 1 Easyvista | 1 Service Manager | 2026-06-17 | N/A | 9.6 CRITICAL |
| An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue. | |||||
| CVE-2022-38488 | 1 Logrocket-oauth2-example Project | 1 Logrocket-oauth2-example | 2026-06-17 | N/A | 9.8 CRITICAL |
| logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter. | |||||
| CVE-2022-38304 | 1 Online Leave Management System Project | 1 Online Leave Management System | 2026-06-17 | N/A | 7.2 HIGH |
| Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /maintenance/manage_leave_type.php. | |||||
| CVE-2022-38303 | 1 Online Leave Management System Project | 1 Online Leave Management System | 2026-06-17 | N/A | 7.2 HIGH |
| Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /employees/manage_leave_type.php. | |||||
| CVE-2022-38302 | 1 Online Leave Management System Project | 1 Online Leave Management System | 2026-06-17 | N/A | 7.2 HIGH |
| Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /maintenance/manage_department.php. | |||||
| CVE-2022-38286 | 1 Jflyfox | 1 Jfinal Cms | 2026-06-17 | N/A | 7.2 HIGH |
| JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/role/list. | |||||
| CVE-2022-38285 | 1 Jflyfox | 1 Jfinal Cms | 2026-06-17 | N/A | 7.2 HIGH |
| JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/menu/list. | |||||
| CVE-2022-38284 | 1 Jflyfox | 1 Jfinal Cms | 2026-06-17 | N/A | 7.2 HIGH |
| JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/department/list. | |||||
| CVE-2022-38283 | 1 Jflyfox | 1 Jfinal Cms | 2026-06-17 | N/A | 7.2 HIGH |
| JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/video/list. | |||||
