Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-43213 1 Billing System Project Project 1 Billing System Project 2022-11-28 N/A 9.8 CRITICAL
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.
CVE-2022-45206 1 Jeecg 1 Jeecg Boot 2022-11-28 N/A 9.8 CRITICAL
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
CVE-2022-45207 1 Jeecg 1 Jeecg Boot 2022-11-28 N/A 9.8 CRITICAL
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
CVE-2022-45205 1 Jeecg 1 Jeecg Boot 2022-11-28 N/A 5.3 MEDIUM
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
CVE-2022-45208 1 Jeecg 1 Jeecg Boot 2022-11-28 N/A 4.3 MEDIUM
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.
CVE-2022-45210 1 Jeecg 1 Jeecg Boot 2022-11-28 N/A 4.3 MEDIUM
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.
CVE-2022-44140 1 Jizhicms 1 Jizhicms 2022-11-28 N/A 8.8 HIGH
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component.
CVE-2022-44120 1 Dedebiz 1 Dedecmsv6 2022-11-28 N/A 9.8 CRITICAL
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.
CVE-2022-45278 1 Jizhicms 1 Jizhicms 2022-11-28 N/A 8.8 HIGH
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component.
CVE-2022-44117 1 Boa 1 Boa 2022-11-28 N/A 9.8 CRITICAL
Boa 0.94.14rc21 is vulnerable to SQL Injection via username.
CVE-2022-36193 1 School Management System Project 1 School Management System 2022-11-28 N/A 9.8 CRITICAL
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
CVE-2021-35284 1 Cms-php Project 1 Cms-php 2022-11-28 N/A 9.8 CRITICAL
SQL Injection vulnerability in function get_user in login_manager.php in rizalafani cms-php v1.
CVE-2022-44278 1 Sanitization Management System Project 1 Sanitization Management System 2022-11-28 N/A 7.2 HIGH
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=user/manage_user&id=.
CVE-2022-43212 1 Billing System Project Project Project 1 Billing System Project 2022-11-28 N/A 9.8 CRITICAL
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.
CVE-2022-44139 1 Apartment Visitors Management System Project 1 Apartment Visitors Management System 2022-11-25 N/A 9.8 CRITICAL
Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.
CVE-2022-37773 1 Maarch 1 Maarch Rm 2022-11-25 N/A 6.5 MEDIUM
An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allows the complete disclosure of all databases.
CVE-2022-42098 1 Klik-socialmediawebsite Project 1 Klik-socialmediawebsite 2022-11-23 N/A 8.8 HIGH
KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.
CVE-2022-45331 1 Aerocms Project 1 Aerocms 2022-11-23 N/A 7.5 HIGH
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.
CVE-2022-45330 1 Aerocms Project 1 Aerocms 2022-11-23 N/A 7.5 HIGH
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.
CVE-2022-45536 1 Aerocms Project 1 Aerocms 2022-11-23 N/A 4.9 MEDIUM
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information.