Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-51101 1 Phpgurukul 1 Restaurant Table Booking System 2026-06-17 N/A 9.8 CRITICAL
PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /rtbs/check-status.php.
CVE-2024-51030 1 Oretnom23 1 Cab Management System 2026-06-17 N/A 6.5 MEDIUM
A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, leading to unauthorized access and potential compromise of sensitive data within the database.
CVE-2024-50989 1 Phpgurukul 1 Online Marriage Registration System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System v1.0 allows an attacker to execute arbitrary SQL commands via the "searchdata " parameter.
CVE-2024-50972 1 Angeljudesuarez 1 Construction Management System 2026-06-17 N/A 7.2 HIGH
A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.
CVE-2024-50971 1 Angeljudesuarez 1 Construction Management System 2026-06-17 N/A 7.2 HIGH
A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.
CVE-2024-50970 1 Nikoarroyocuraza 1 Online Furniture Shopping Project 2026-06-17 N/A 8.8 HIGH
A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2024-50835 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/edit_student.php in KASHIPARA E-learning Management System Project 1.0 via the cys, un, ln, fn, and id parameters.
CVE-2024-50834 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.2 HIGH
A SQL Injection was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0 via the firstname and lastname parameters.
CVE-2024-50833 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password parameters.
CVE-2024-50832 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.
CVE-2024-50831 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.2 HIGH
A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.
CVE-2024-50830 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Project 1.0 via the date_start, date_end, and title parameters.
CVE-2024-50829 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0 via the unit parameter.
CVE-2024-50828 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project 1.0 via the d parameter.
CVE-2024-50827 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.
CVE-2024-50826 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.
CVE-2024-50825 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter.
CVE-2024-50824 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.
CVE-2024-50823 1 Lopalopa 1 E-learning Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.
CVE-2024-50802 1 Abantecart 1 Abantecart 2026-06-17 N/A 6.0 MEDIUM
A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/email_templates.php. The vulnerability is exploitable via the id parameter.