Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-44249 1 Online Motorcycle \(bike\) Rental System Project 1 Online Motorcycle \(bike\) Rental System 2022-02-02 7.5 HIGH 9.8 CRITICAL
Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login portal. This can lead attackers to remotely dump MySQL database credentials.
CVE-2022-21720 1 Glpi-project 1 Glpi 2022-02-02 4.0 MEDIUM 4.9 MEDIUM
GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving normally inaccessible data via SQL injection. Version 9.5.7 contains a patch for this issue. As a workaround, disabling the `Entities` update right prevents exploitation of this vulnerability.
CVE-2021-46377 1 Cskaza 1 Cszcms 2022-02-02 7.5 HIGH 9.8 CRITICAL
There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser
CVE-2021-46427 1 Simple Chatbot Application Project 1 Simple Chatbot Application 2022-02-02 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.
CVE-2022-0362 1 Showdoc 1 Showdoc 2022-02-02 7.5 HIGH 9.8 CRITICAL
SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.
CVE-2022-0332 1 Moodle 1 Moodle 2022-02-01 7.5 HIGH 9.8 CRITICAL
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.
CVE-2020-7500 1 Schneider-electric 12 Mtn6260-0310, Mtn6260-0310 Firmware, Mtn6260-0315 and 9 more 2022-01-31 7.5 HIGH 9.8 CRITICAL
A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause arbitrary code to be executed when a malicious command is entered.
CVE-2021-43863 1 Nextcloud 1 Nextcloud 2022-01-31 5.0 MEDIUM 7.5 HIGH
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. The Nextcloud Android app uses content providers to manage its data. Prior to version 3.18.1, the providers `FileContentProvider` and `DiskLruImageCacheFileProvider` have security issues (an SQL injection, and an insufficient permission control, respectively) that allow malicious apps in the same device to access Nextcloud's data bypassing the permission control system. Users should upgrade to version 3.18.1 to receive a patch. There are no known workarounds aside from upgrading.
CVE-2021-41659 1 Banking System Project 1 Banking System 2022-01-31 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field.
CVE-2021-41660 1 Patient Appointment Scheduler System Project 1 Patient Appointment Scheduler System 2022-01-31 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php.
CVE-2021-41928 1 Try My Recipe Project 1 Try My Recipe 2022-01-31 7.5 HIGH 9.8 CRITICAL
SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code via the rid parameter to the view_recipe page.
CVE-2021-46200 1 Simple Music Cloud Community System Project 1 Simple Music Cloud Community System 2022-01-31 10.0 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.
CVE-2021-4088 1 Mcafee 1 Data Loss Prevention 2022-01-31 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.101, and 11.6.401 allows a remote authenticated attacker to inject unfiltered SQL into the DLP part of the ePO database. This could lead to remote code execution on the ePO server with privilege escalation.
CVE-2021-46061 1 Computer And Mobile Repair Shop Management System Project 1 Computer And Mobile Repair Shop Management System 2022-01-28 10.0 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management system (RSMS) 1.0 via the code parameter in /rsms/ node app.
CVE-2021-45334 1 Online Thesis Archiving System Project 1 Online Thesis Archiving System 2022-01-28 7.5 HIGH 9.8 CRITICAL
Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentication and gain access to admin panel using SQL Injection
CVE-2021-46089 1 Jeecg 1 Jeecg Boot 2022-01-28 10.0 HIGH 9.8 CRITICAL
In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.
CVE-2021-46451 1 Online Project Time Management System Project 1 Online Project Time Management System 2022-01-28 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerabilty exists in Sourcecodester Online Project Time Management System 1.0 via the pid parameter in the load_file function.
CVE-2021-45802 1 Iresturant Project 1 Iresturant 2022-01-28 7.5 HIGH 9.8 CRITICAL
MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration.
CVE-2021-45803 1 Iresturant Project 1 Iresturant 2022-01-28 6.5 MEDIUM 8.8 HIGH
MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation.
CVE-2021-40908 1 Purchase Order Management System Project 1 Purchase Order Management System 2022-01-28 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.