Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-4246 1 Lmeve Project 1 Lmeve 2022-12-22 N/A 9.8 CRITICAL
A vulnerability was found in roxlukas LMeve and classified as critical. Affected by this issue is some unknown functionality of the component Login Page. The manipulation of the argument X-Forwarded-For leads to sql injection. The attack may be launched remotely. The name of the patch is 29e1ead3bb1c1fad53b77dfc14534496421c5b5d. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216176.
CVE-2022-42535 1 Google 1 Android 2022-12-21 N/A 5.5 MEDIUM
In a query in MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770183
CVE-2021-31650 1 Online Grading System Project 1 Online Grading System 2022-12-21 N/A 9.8 CRITICAL
A SQL injection vulnerability in Sourcecodester Online Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via the uname parameter.
CVE-2021-24728 1 Cozmoslabs 1 Membership \& Content Restriction - Paid Member Subscriptions 2022-12-20 6.5 MEDIUM 8.8 HIGH
The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages.
CVE-2022-3481 1 Opmc 1 Woocommerce Dropshipping 2022-12-20 N/A 9.8 CRITICAL
The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection
CVE-2022-20518 1 Google 1 Android 2022-12-20 N/A 5.5 MEDIUM
In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224770203
CVE-2022-20517 1 Google 1 Android 2022-12-20 N/A 5.5 MEDIUM
In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224769956
CVE-2022-44588 1 Blocksera 1 Cryptocurrency Widgets Pack 2022-12-19 N/A 9.8 CRITICAL
Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.
CVE-2022-38488 1 Logrocket-oauth2-example Project 1 Logrocket-oauth2-example 2022-12-19 N/A 9.8 CRITICAL
logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter.
CVE-2022-4454 1 Bible-online Project 1 Bible-online 2022-12-19 N/A 9.8 CRITICAL
A vulnerability, which was classified as critical, has been found in m0ver bible-online. Affected by this issue is the function query of the file src/main/java/custom/application/search.java of the component Search Handler. The manipulation leads to sql injection. The name of the patch is 6ef0aabfb2d4ccd53fcaa9707781303af357410e. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-215444.
CVE-2022-46117 1 Helmet Store Showroom Site Project 1 Helmet Store Showroom Site 2022-12-16 N/A 7.2 HIGH
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=view_product&id=.
CVE-2022-46120 1 Helmet Store Showroom Site Project 1 Helmet Store Showroom Site 2022-12-16 N/A 7.2 HIGH
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=products/view_product&id=.
CVE-2022-46119 1 Helmet Store Showroom Site Project 1 Helmet Store Showroom Site 2022-12-16 N/A 7.2 HIGH
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=categories&c=.
CVE-2022-46118 1 Helmet Store Showroom Site Project 1 Helmet Store Showroom Site 2022-12-16 N/A 7.2 HIGH
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=product_per_brand&bid=.
CVE-2022-46125 1 Helmet Store Showroom Site Project 1 Helmet Store Showroom Site 2022-12-16 N/A 7.2 HIGH
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=client/manage_client&id=.
CVE-2022-46124 1 Helmet Store Showroom Site Project 1 Helmet Store Showroom Site 2022-12-16 N/A 7.2 HIGH
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=user/manage_user&id=.
CVE-2022-46122 1 Helmet Store Showroom Site Project 1 Helmet Store Showroom Site 2022-12-16 N/A 7.2 HIGH
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/view_category.php?id=.
CVE-2022-46126 1 Helmet Store Showroom Site Project 1 Helmet Store Showroom Site 2022-12-16 N/A 7.2 HIGH
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/brands/manage_brand.php?id=.
CVE-2022-46123 1 Helmet Store Showroom Site Project 1 Helmet Store Showroom Site 2022-12-16 N/A 7.2 HIGH
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/manage_category.php?id=.
CVE-2022-46127 1 Helmet Store Showroom Site Project 1 Helmet Store Showroom Site 2022-12-16 N/A 7.2 HIGH
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/classes/Master.php?f=delete_product.