Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-55517 2026-06-17 N/A 8.8 HIGH
An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the groupType parameter in /SCGController is mishandled before being used in SQL queries, allowing SQL injection in an authenticated session.
CVE-2024-55509 1 Codeastro 1 Complaint Management System 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of the delete.php component.
CVE-2024-55496 1 1000projects 1 Bookstore Management System 2026-06-17 N/A 9.1 CRITICAL
A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects some unknown functionality of add_company.php. Actions on the delete parameter result in SQL injection.
CVE-2024-55460 2026-06-17 N/A 9.8 CRITICAL
A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attackers to execute arbitrary code via a crafted input.
CVE-2024-55270 1 Phpgurukul 1 Student Management System 2026-06-17 N/A 8.8 HIGH
phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter.
CVE-2024-55238 1 Open-metadata 1 Openmetadata 2026-06-17 N/A 7.1 HIGH
OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build a SQL query.
CVE-2024-55212 2026-06-17 N/A 6.5 MEDIUM
DNNGo xBlog v6.5.0 was discovered to contain a SQL injection vulnerability via the Categorys parameter at /DNNGo_xBlog/Resource_Service.aspx.
CVE-2024-55159 2026-06-17 N/A 4.2 MEDIUM
GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the SortName parameter at /system/loginLog/list.
CVE-2024-55104 1 Phpgurukul 1 Online Nurse Hiring System 2026-06-17 N/A 7.2 HIGH
Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters.
CVE-2024-55103 1 Phpgurukul 1 Online Nurse Hiring System 2026-06-17 N/A 7.2 HIGH
Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter.
CVE-2024-55099 1 Phpgurukul 1 Online Nurse Hiring System 2026-06-17 N/A 9.8 CRITICAL
A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.
CVE-2024-55016 1 Phpgurukul 1 Student Record System 2026-06-17 N/A 6.5 MEDIUM
PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.
CVE-2024-54960 1 Nagios 1 Nagios Xi 2026-06-17 N/A 6.5 MEDIUM
A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.
CVE-2024-54934 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 9.8 CRITICAL
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.
CVE-2024-54933 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.2 HIGH
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.
CVE-2024-54932 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 9.8 CRITICAL
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.
CVE-2024-54931 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.
CVE-2024-54930 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.2 HIGH
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.
CVE-2024-54929 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.2 HIGH
KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.
CVE-2024-54928 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.2 HIGH
kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,