Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-48465 2026-06-17 N/A 9.8 CRITICAL
The MRBS version 1.5.0 has an SQL injection vulnerability in the edit_entry_handler.php file, specifically in the rooms%5B%5D parameter
CVE-2024-48427 1 Oretnom23 1 Packers And Movers Management System 2026-06-17 N/A 8.8 HIGH
A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id
CVE-2024-48411 1 Mayurik 1 Online Tours \& Travels Management System 2026-06-17 N/A 9.8 CRITICAL
itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.
CVE-2024-48357 1 Lylme 1 Lylme Spage 2026-06-17 N/A 9.8 CRITICAL
LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php.
CVE-2024-48356 1 Lylme 1 Lylme Spage 2026-06-17 N/A 9.8 CRITICAL
LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php.
CVE-2024-48343 1 Esafenet 1 Cdg 2026-06-17 N/A 6.3 MEDIUM
A SQL Injection vulnerability in ESAFENET CDG 5 and earlier allows an attacker to execute arbitrary code via the id parameter of the dataSearch.jsp page.
CVE-2024-48325 1 Portabilis 1 I-educar 2026-06-17 N/A 8.1 HIGH
Portabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the "getDocuments" function of the "InstituicaoDocumentacaoController" class. The "instituicao_id" parameter in "/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id" is not properly sanitized, allowing an unauthenticated remote attacker to inject malicious SQL commands.
CVE-2024-48307 1 Jeecg 1 Jeecg Boot 2026-06-17 N/A 9.8 CRITICAL
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.
CVE-2024-48283 1 Phpgurukul 1 User Registration \& Login And User Management System 2026-06-17 N/A 9.8 CRITICAL
Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter.
CVE-2024-48282 1 Phpgurukul 1 User Registration \& Login And User Management System 2026-06-17 N/A 7.6 HIGH
A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request.
CVE-2024-48280 1 Phpgurukul 1 User Registration \& Login And User Management System 2026-06-17 N/A 7.6 HIGH
A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request.
CVE-2024-48259 1 Magicbug 1 Cloudlog 2026-06-17 N/A 7.3 HIGH
Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.
CVE-2024-48257 1 Wavelog 1 Wavelog 2026-06-17 N/A 9.8 CRITICAL
Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.
CVE-2024-48255 1 Magicbug 1 Cloudlog 2026-06-17 N/A 9.8 CRITICAL
Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.
CVE-2024-48253 1 Magicbug 1 Cloudlog 2026-06-17 N/A 9.8 CRITICAL
Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.
CVE-2024-48251 1 Wavelog 1 Wavelog 2026-06-17 N/A 9.8 CRITICAL
Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
CVE-2024-48249 1 Wavelog 1 Wavelog 2026-06-17 N/A 7.3 HIGH
Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
CVE-2024-48238 1 Wtcms Project 1 Wtcms 2026-06-17 N/A 4.7 MEDIUM
WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter.
CVE-2024-48231 1 Funadmin 1 Funadmin 2026-06-17 N/A 7.2 HIGH
Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php.
CVE-2024-48230 1 Funadmin 1 Funadmin 2026-06-17 N/A 7.2 HIGH
funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.