Show filters
4,854 Total Results
Displaying 191-200 of 4,854
Sort by:
Attacker Value
Unknown

CVE-2023-33479

Disclosure Date: November 07, 2023 (last updated February 25, 2025)
RemoteClinic version 2.0 contains a SQL injection vulnerability in the /staff/edit.php file.
Attacker Value
Unknown

CVE-2023-33478

Disclosure Date: November 07, 2023 (last updated February 25, 2025)
RemoteClinic 2.0 has a SQL injection vulnerability in the ID parameter of /medicines/stocks.php.
Attacker Value
Unknown

CVE-2023-5709

Disclosure Date: November 07, 2023 (last updated February 25, 2025)
The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level and above permissions to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Attacker Value
Unknown

CVE-2023-42284

Disclosure Date: November 07, 2023 (last updated February 25, 2025)
Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.
Attacker Value
Unknown

CVE-2023-42283

Disclosure Date: November 07, 2023 (last updated February 25, 2025)
Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.
Attacker Value
Unknown

CVE-2023-5082

Disclosure Date: November 06, 2023 (last updated February 25, 2025)
The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it.
Attacker Value
Unknown

CVE-2023-46823

Disclosure Date: November 06, 2023 (last updated February 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum ImageLinks Interactive Image Builder for WordPress allows SQL Injection.This issue affects ImageLinks Interactive Image Builder for WordPress: from n/a through 1.5.4.
Attacker Value
Unknown

CVE-2023-46821

Disclosure Date: November 06, 2023 (last updated February 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Security Headers allows auth. (admin+) SQL Injection.This issue affects GD Security Headers: from n/a through 1.7.
Attacker Value
Unknown

CVE-2023-46084

Disclosure Date: November 06, 2023 (last updated February 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2.
Attacker Value
Unknown

CVE-2023-45830

Disclosure Date: November 06, 2023 (last updated February 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Online ADA Accessibility Suite by Online ADA allows SQL Injection.This issue affects Accessibility Suite by Online ADA: from n/a through 4.12.