Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-57622 1 Monetdb 1 Monetdb 2026-06-17 N/A 7.5 HIGH
An issue in the exp_bin component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57621 1 Monetdb 1 Monetdb 2026-06-17 N/A 7.5 HIGH
An issue in the GDKanalytical_correlation component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57620 1 Monetdb 1 Monetdb 2026-06-17 N/A 7.5 HIGH
An issue in the trimchars component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57619 1 Monetdb 1 Monetdb 2026-06-17 N/A 7.5 HIGH
An issue in the atom_get_int component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57617 1 Monetdb 1 Monetdb 2026-06-17 N/A 7.5 HIGH
An issue in the dameraulevenshtein component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57616 1 Monetdb 1 Monetdb 2026-06-17 N/A 7.5 HIGH
An issue in the vscanf component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57615 1 Monetdb 1 Monetdb 2026-06-17 N/A 7.5 HIGH
An issue in the BATcalcbetween_intern component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2024-57606 1 Guojusoft 1 Jeecgboot 2026-06-17 N/A 7.5 HIGH
SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2 allows a remote attacker to obtain sensitive information via the getTotalData component.
CVE-2024-57587 1 Easyvirt 2 Co2scope, Dcscope 2026-06-17 N/A 9.1 CRITICAL
Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to /api/auth/login.
CVE-2024-57521 1 Ruoyi 1 Ruoyi 2026-06-17 N/A 10.0 CRITICAL
SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.
CVE-2024-57459 1 Vishalmathur 1 Cloudclassroom-php Project 2026-06-17 N/A 7.3 HIGH
A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds parameter does not properly validate user input, allowing an attacker to inject arbitrary SQL commands.
CVE-2024-57437 1 Ruoyi 1 Ruoyi 2026-06-17 N/A 6.5 MEDIUM
RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list.
CVE-2024-57430 1 Phpjabbers 1 Cinema Booking System 2026-06-17 N/A 9.8 CRITICAL
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.
CVE-2024-57328 1 Projectworlds 1 Online Food Ordering System 2026-06-17 N/A 9.8 CRITICAL
A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises because the input fields username and password are not properly sanitized, allowing attackers to inject malicious SQL queries to bypass authentication and gain unauthorized access.
CVE-2024-57238 2026-06-17 N/A 7.3 HIGH
Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The vulnerability allows an attacker to manipulate SQL queries by injecting malicious SQL code into the order_by parameter.
CVE-2024-57178 2026-06-17 N/A 5.9 MEDIUM
An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' parameter to the portofolio() endpoint, it is possible to trigger an SQL injection in the application. As a result, the attacker will be able the user data or manipulate the software behavior.
CVE-2024-57162 1 Campcodes 1 Cybercafe Management System 2026-06-17 N/A 7.2 HIGH
Campcodes Cybercafe Management System v1.0 is vulnerable to SQL Injection in /ccms/view-user-detail.php.
CVE-2024-57151 1 Rockoa 1 Xinhu 2026-06-17 N/A 6.8 MEDIUM
SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and the saveAjax function
CVE-2024-57098 1 Deep-project 1 Moss 2026-06-17 N/A 9.8 CRITICAL
Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into the order parameter.
CVE-2024-57095 1 Go-admin 1 Go-cms 2026-06-17 N/A 6.8 MEDIUM
SQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload.