Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-43510 1 Simple Client Management System Project 1 Simple Client Management System 2022-02-04 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.
CVE-2021-24946 1 Webnus 1 Modern Events Calendar Lite 2022-02-04 7.5 HIGH 9.8 CRITICAL
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue
CVE-2021-24862 1 Metagauss 1 Registrationmagic 2022-02-04 6.5 MEDIUM 7.2 HIGH
The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue
CVE-2021-46385 1 Mingsoft 1 Mcms 2022-02-04 5.0 MEDIUM 7.5 HIGH
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive information from the database.
CVE-2021-44593 1 Simple College Website Project 1 Simple College Website 2022-02-03 6.8 MEDIUM 8.1 HIGH
Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL injection in the username parameter on /admin/login.php.
CVE-2022-24266 1 Cuppacms 1 Cuppacms 2022-02-03 7.8 HIGH 7.5 HIGH
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.
CVE-2022-24265 1 Cuppacms 1 Cuppacms 2022-02-03 7.8 HIGH 7.5 HIGH
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.
CVE-2022-24264 1 Cuppacms 1 Cuppacms 2022-02-03 7.8 HIGH 7.5 HIGH
Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.
CVE-2021-46444 1 Hhg-multistore 1 Multistore 2022-02-02 7.5 HIGH 9.8 CRITICAL
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_group_edit&agID.
CVE-2021-46445 1 Hhg-multistore 1 Multistore 2022-02-02 7.5 HIGH 9.8 CRITICAL
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/categories.php?box_group_id.
CVE-2021-46446 1 Hhg-multistore 1 Multistore 2022-02-02 7.5 HIGH 9.8 CRITICAL
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_access_group_edit&aagID.
CVE-2021-46448 1 Hhg-multistore 1 Multistore 2022-02-02 7.5 HIGH 9.8 CRITICAL
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=1&cID.
CVE-2021-41609 1 Classapps 1 Selectsurvey.net 2022-02-02 7.5 HIGH 9.8 CRITICAL
SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection.
CVE-2021-46383 1 Mingsoft 1 Mcms 2022-02-02 5.0 MEDIUM 7.5 HIGH
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive information from the database.
CVE-2022-24222 1 Elitecms 1 Elite Cms 2022-02-02 7.5 HIGH 9.8 CRITICAL
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.
CVE-2022-24220 1 Elitecms 1 Elite Cms 2022-02-02 7.5 HIGH 9.8 CRITICAL
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php.
CVE-2022-24219 1 Elitecms 1 Elite Cms 2022-02-02 7.5 HIGH 9.8 CRITICAL
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.
CVE-2022-24221 1 Elitecms 1 Elite Cms 2022-02-02 7.5 HIGH 9.8 CRITICAL
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.
CVE-2022-22294 1 Zfaka Project 1 Zfaka 2022-02-02 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in ZFAKA<=1.43 which an attacker can use to complete SQL injection in the foreground and add a background administrator account.
CVE-2021-45435 1 Simple Cold Storage Management System Project 1 Simple Cold Storage Management System 2022-02-02 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the username field in login.php.