Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-57770 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 8.8 HIGH
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.
CVE-2024-57769 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 8.8 HIGH
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.
CVE-2024-57768 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 9.8 CRITICAL
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.
CVE-2024-57765 1 Wangl1989 1 Mysiteforme 2026-06-17 N/A 7.5 HIGH
MSFM before 2025.01.01 was discovered to contain a SQL injection vulnerability via the s_name parameter at table/list.
CVE-2024-57760 1 Jeewms 1 Jeewms 2026-06-17 N/A 6.5 MEDIUM
JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CGReportDao.java.
CVE-2024-57665 1 Heyewei 1 Jfinalcms 2026-06-17 N/A 9.8 CRITICAL
JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that the title parameter is controllable and is concatenated directly into filterSql without filtering.
CVE-2024-57660 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the sqlo_expand_jts component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57658 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the sql_tree_hash_1 component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57657 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the sqlg_vec_upd component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57656 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the sqlc_add_distinct_node component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57653 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the qst_vec_set_copy component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57652 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the numeric_to_dv component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57651 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the jp_add component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57650 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the qi_inst_state_free component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57649 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the qst_vec_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57648 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the itc_set_param_row component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57647 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the row_insert_cast component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57646 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the psiginfo component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57645 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the qi_inst_state_free component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57644 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the itc_hash_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.