Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-89
Total 9311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-3013 1 Simple Task Managing System Project 1 Simple Task Managing System 2022-08-31 N/A 9.8 CRITICAL
A vulnerability classified as critical has been found in SourceCodester Simple Task Managing System. This affects an unknown part of the file /loginVaLidation.php. The manipulation of the argument login leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-207423.
CVE-2022-36543 1 Edoc-doctor-appointment-system Project 1 Edoc-doctor-appointment-system 2022-08-31 N/A 9.8 CRITICAL
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php.
CVE-2022-36545 1 Edoc-doctor-appointment-system Project 1 Edoc-doctor-appointment-system 2022-08-31 N/A 9.8 CRITICAL
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php.
CVE-2022-36544 1 Edoc-doctor-appointment-system Project 1 Edoc-doctor-appointment-system 2022-08-31 N/A 9.8 CRITICAL
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php.
CVE-2021-43329 1 Mumara 1 Classic 2022-08-31 N/A 9.8 CRITICAL
A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attacker to execute arbitrary SQL commands via the license parameter.
CVE-2017-17590 1 Stackoverflow-clone Project 1 Stackoverflow-clone 2022-08-29 7.5 HIGH 9.8 CRITICAL
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.
CVE-2022-2957 1 Simple And Nice Shopping Cart Script Project 1 Simple And Nice Shopping Cart Script 2022-08-29 N/A 9.8 CRITICAL
A vulnerability classified as critical was found in SourceCodester Simple and Nice Shopping Cart Script. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation of the argument mem_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-207001 was assigned to this vulnerability.
CVE-2022-37178 1 72crm 1 Wukong Crm 2022-08-28 N/A 8.8 HIGH
An issue was discovered in 72crm 9.0. There is a SQL Injection vulnerability in View the task calendar.
CVE-2022-37333 1 Exceedone 2 Exment, Laravel-admin 2022-08-28 N/A 8.8 HIGH
SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows remote authenticated attackers to execute arbitrary SQL commands.
CVE-2022-36719 1 Library Management System Project 1 Library Management System 2022-08-26 N/A 9.8 CRITICAL
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the ok parameter at /admin/history.php.
CVE-2022-36721 1 Library Management System Project 1 Library Management System 2022-08-26 N/A 8.8 HIGH
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Textbook parameter at /admin/modify.php.
CVE-2022-36720 1 Library Management System Project 1 Library Management System 2022-08-26 N/A 8.8 HIGH
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/modify1.php.
CVE-2022-36696 1 Ingredients Stock Management System Project 1 Ingredients Stock Management System 2022-08-26 N/A 9.8 CRITICAL
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockout.
CVE-2022-36716 1 Library Management System Project 1 Library Management System 2022-08-26 N/A 9.8 CRITICAL
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/changestock.php.
CVE-2022-36695 1 Ingredients Stock Management System Project 1 Ingredients Stock Management System 2022-08-26 N/A 9.8 CRITICAL
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockin.
CVE-2022-36697 1 Ingredients Stock Management System Project 1 Ingredients Stock Management System 2022-08-26 N/A 9.8 CRITICAL
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_waste.
CVE-2022-36715 1 Library Management System Project 1 Library Management System 2022-08-26 N/A 9.8 CRITICAL
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/search.php.
CVE-2022-36693 1 Ingredients Stock Management System Project 1 Ingredients Stock Management System 2022-08-26 N/A 9.8 CRITICAL
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_item.
CVE-2022-36692 1 Ingredients Stock Management System Project 1 Ingredients Stock Management System 2022-08-26 N/A 9.8 CRITICAL
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.
CVE-2022-36703 1 Ingredients Stock Management System Project 1 Ingredients Stock Management System 2022-08-26 N/A 8.8 HIGH
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /stocks/manage_stockin.php.