Vulnerabilities (CVE)

Filtered by CWE-89
Total 20784 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-44074 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php.
CVE-2025-44073 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.
CVE-2025-44072 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php.
CVE-2025-44034 1 Aaluoxiang 1 Oa System 2026-06-17 N/A 8.0 HIGH
SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph parameters in src/main/Java/cn/gson/oasys/controller/address/AddrController
CVE-2025-44033 1 Aaluoxiang 1 Oa System 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the allDirector() method declaration in src/main/java/cn/gson/oasys/mappers/AddressMapper.java
CVE-2025-43949 2026-06-17 N/A 9.8 CRITICAL
MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to execute malicious SQL statements that control a web application's database server.
CVE-2025-43923 1 Unicomsi 1 Focal Point 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered in ReportController in Unicom Focal Point 7.6.1. A user who has administrative privilege in Focal Point can perform SQL injection via the image parameter during a delete report image operation.
CVE-2025-43833 2026-06-17 N/A 7.6 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Amir Helzer Absolute Links absolute-links allows Blind SQL Injection.This issue affects Absolute Links: from n/a through <= 1.1.1.
CVE-2025-43022 1 Hp 1 Poly Clariti Manager 2026-06-17 N/A 7.2 HIGH
A potential SQL injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow a privileged user to execute SQL commands. HP has addressed the issue in the latest software update.
CVE-2025-42889 2026-06-17 N/A 5.4 MEDIUM
SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end database. As a result, this vulnerability has a low impact on the application's confidentiality and integrity but no impact on its availability.
CVE-2025-41678 1 Mbconnectline 2 Mbnet.mini, Mbnet.mini Firmware 2026-06-17 N/A 6.5 MEDIUM
A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement.
CVE-2025-41444 1 Zohocorp 1 Manageengine Adaudit Plus 2026-06-17 N/A 8.3 HIGH
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module.
CVE-2025-41407 1 Zohocorp 1 Manageengine Adaudit Plus 2026-06-17 N/A 8.3 HIGH
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.
CVE-2025-41403 1 Zohocorp 1 Manageengine Adaudit Plus 2026-06-17 N/A 8.3 HIGH
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.
CVE-2025-41377 2026-06-17 N/A N/A
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/consultacuotasred.php.
CVE-2025-41375 1 Limesurvey 1 Limesurvey 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via 'token' parameter in '/index.php' endpoint.
CVE-2025-41374 1 Tesigandia 1 Gandia Integra Total 2026-06-17 N/A 8.8 HIGH
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/hislistadoacciones.php.
CVE-2025-41373 1 Tesigandia 1 Gandia Integra Total 2026-06-17 N/A 8.8 HIGH
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/hislistadoacciones.php.
CVE-2025-41372 1 Tesigandia 1 Gandia Integra Total 2026-06-17 N/A 8.8 HIGH
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/informe_campo_entrevistas.php.
CVE-2025-41371 1 Tesigandia 1 Gandia Integra Total 2026-06-17 N/A 8.8 HIGH
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb_v4/integra/html/view/acceso.php