CVE-2025-41403

CVSS v3 Score
8.3
High

Vulnerability Description

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.

CVSS:8.3(High)

There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerabil...

CWE-892019
CVSS:8.3(High)

dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

CWE-892022
CVSS:8.3(High)

pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

CWE-892022
CVSS:8.3(High)

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can se...

CWE-892022
CVSS:8.3(High)

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can se...

CWE-892022
CVSS:8.3(High)

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can se...

CWE-892022