Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25491 1 Hospital Management System Project 1 Hospital Management System 2022-05-12 7.5 HIGH 7.5 HIGH
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php.
CVE-2022-25004 1 Hospital\'s Patient Records Management System Project 1 Hospital\'s Patient Records Management System 2022-05-12 7.5 HIGH 9.8 CRITICAL
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php.
CVE-2022-25492 1 Hospital Management System Project 1 Hospital Management System 2022-05-12 7.5 HIGH 9.8 CRITICAL
HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.
CVE-2022-28079 1 College Management System Project 1 College Management System 2022-05-12 6.5 MEDIUM 8.8 HIGH
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.
CVE-2022-28080 1 Event Management System Project 1 Event Management System 2022-05-12 6.5 MEDIUM 8.8 HIGH
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.
CVE-2020-6145 1 Frappe 1 Erpnext 2022-05-12 6.5 MEDIUM 8.8 HIGH
An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
CVE-2020-6114 1 Icehrm 1 Icehrm 2022-05-12 6.5 MEDIUM 7.2 HIGH
An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
CVE-2022-27413 1 Hospital Management System Project 1 Hospital Management System 2022-05-12 7.5 HIGH 9.8 CRITICAL
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php.
CVE-2021-42185 1 Wdja 1 Wdja 2022-05-12 7.5 HIGH 9.8 CRITICAL
wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function.
CVE-2022-28552 1 Chshcms 1 Cscms 2022-05-12 6.5 MEDIUM 8.8 HIGH
Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.
CVE-2022-28512 1 Fantastic Blog Project 1 Fantastic Blog 2022-05-12 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters.
CVE-2022-0657 1 5 Stars Rating Funnel Project 1 5 Stars Rating Funnel 2022-05-12 7.5 HIGH 9.8 CRITICAL
The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an attempt to sanitise the input, using sanitize_text_field(), however such function is not intended to prevent SQL injections.
CVE-2022-28099 1 Poultry Farm Management System Project 1 Poultry Farm Management System 2022-05-12 6.5 MEDIUM 8.8 HIGH
Poultry Farm Management System v1.0 was discovered to contain a SQL injection vulnerability via the Item parameter at /farm/store.php.
CVE-2022-28530 1 Covid-19 Directory On Vaccination System Project 1 Covid-19 Directory On Vaccination System 2022-05-11 7.5 HIGH 9.8 CRITICAL
Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory.
CVE-2022-28533 1 Medical Hub Directory Site Project 1 Medical Hub Directory Site 2022-05-11 7.5 HIGH 9.8 CRITICAL
Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php.
CVE-2022-27431 1 Wuzhicms 1 Wuzhi Cms 2022-05-11 7.5 HIGH 9.8 CRITICAL
Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php.
CVE-2022-27420 1 Hospital Management System Project 1 Hospital Management System 2022-05-11 7.5 HIGH 9.8 CRITICAL
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.
CVE-2021-41942 1 Msvod 1 Msvod Cms 2022-05-11 5.0 MEDIUM 7.5 HIGH
The Magic CMS MSVOD v10 video system has a SQL injection vulnerability. Attackers can use vulnerabilities to obtain sensitive information in the database.
CVE-2022-1378 1 Deltaww 1 Diaenergie 2022-05-11 10.0 HIGH 9.8 CRITICAL
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
CVE-2022-1377 1 Deltaww 1 Diaenergie 2022-05-11 10.0 HIGH 9.8 CRITICAL
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.