Vulnerabilities (CVE)

Filtered by CWE-89
Total 17786 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-3694 1 Modified 1 Ecommerce Shopsoftware 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-module is not installed, allow remote attackers to execute arbitrary SQL commands via the (1) orders_status or (2) customers_status parameter to api/easybill/easybillcsv.php.
CVE-2016-8929 1 Ibm 1 Kenexa Lms 2025-04-20 5.5 MEDIUM 5.4 MEDIUM
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2016-9728 1 Ibm 1 Qradar Security Information And Event Manager 2025-04-20 5.0 MEDIUM 7.5 HIGH
IBM Qradar 7.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM Reference #: 1999543.
CVE-2017-16510 1 Wordpress 1 Wordpress 2025-04-20 7.5 HIGH 9.8 CRITICAL
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
CVE-2017-17601 1 Cab Booking Script Project 1 Cab Booking Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter.
CVE-2017-14844 1 Dasinfomedia 1 Wpgym Gym Management System 2025-04-20 6.5 MEDIUM 8.8 HIGH
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
CVE-2024-31507 1 Tamparongj03 1 Online Graduate Tracer System 2025-04-18 N/A 8.6 HIGH
Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "request" parameter in admin/fetch_gendercs.php.
CVE-2023-45503 1 Macs Cms Project 1 Macs Cms 2025-04-18 N/A 5.3 MEDIUM
SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via crafted payload to resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUser, deleteRole, deleteComment, deleteUser, allowComment, saveRole, forgotPasswordProcess, resetPassword, saveUser, addComment, saveRole, and saveUser endpoints.
CVE-2024-50717 1 Smarts-srl 1 Smart Agent 2025-04-18 N/A 9.8 CRITICAL
SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the client parameter in the /recuperaLog.php component.
CVE-2024-34220 1 Oretnom23 1 Human Resource Management System 2025-04-18 N/A 7.5 HIGH
Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.
CVE-2024-34222 1 Oretnom23 1 Human Resource Management System 2025-04-18 N/A 5.9 MEDIUM
Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.
CVE-2022-20518 1 Google 1 Android 2025-04-18 N/A 5.5 MEDIUM
In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770203
CVE-2022-20517 1 Google 1 Android 2025-04-18 N/A 5.5 MEDIUM
In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224769956
CVE-2024-57095 1 Go-admin 1 Go-cms 2025-04-18 N/A 6.8 MEDIUM
SQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload.
CVE-2025-0950 1 Angeljudesuarez 1 Tailoring Management System 2025-04-18 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects some unknown processing of the file staffview.php. The manipulation of the argument staffid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-25991 1 Hoosk 1 Hoosk 2025-04-18 N/A 5.1 MEDIUM
SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.
CVE-2024-48177 1 Mrcms 1 Mrcms 2025-04-18 N/A 8.8 HIGH
MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.
CVE-2024-2592 1 Amss\+\+ Project 1 Amss\+\+ 2025-04-17 N/A 8.2 HIGH
Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/person/pic_show.php, in the 'person_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.
CVE-2024-2591 1 Amss\+\+ Project 1 Amss\+\+ 2025-04-17 N/A 8.2 HIGH
Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/book/main/bookdetail_group.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.
CVE-2024-2590 1 Amss\+\+ Project 1 Amss\+\+ 2025-04-17 N/A 8.2 HIGH
Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/mail/main/select_send.php, in the 'sd_index' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.