Vulnerabilities (CVE)

Filtered by CWE-89
Total 15763 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-28297 2024-08-05 N/A 7.5 HIGH
SQL injection vulnerability in AzureSoft MyHorus 4.3.5 allows authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2023-6411 1 Aatifaneeq 1 Voovi 2024-02-05 N/A 7.5 HIGH
A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via home.php in the update parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the application.
CVE-2023-24787 1 Churchcrm 1 Churchcrm 2024-02-04 N/A N/A
RESERVED churchcrm v4.5.3 was discovered to contain a SQL injection vulnerability via the Event parameter at /churchcrm/EventAttendance.php.