Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-45600 2026-06-17 N/A 7.7 HIGH
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13, an authenticated user can perform a SQL injection when the plugin is active. The vulnerability is fixed in 1.21.13.
CVE-2024-45387 1 Apache 1 Traffic Control 2026-06-17 N/A 9.9 CRITICAL
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request. Users are recommended to upgrade to version Apache Traffic Control 8.0.2 if you run an affected version of Traffic Ops.
CVE-2024-45265 1 Skyss 1 Arfa-cms 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.
CVE-2024-45249 1 Peak-14 1 Cavok 2026-06-17 N/A 9.8 CRITICAL
Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-45174 1 C-mor 1 C-mor Video Surveillance 2026-06-17 N/A 8.1 HIGH
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper validation of user-supplied data, different functionalities of the C-MOR web interface are vulnerable to SQL injection attacks. This kind of attack allows an authenticated user to execute arbitrary SQL commands in the context of the corresponding MySQL database.
CVE-2024-45059 1 Portabilis 1 I-educar 2026-06-17 N/A 8.8 HIGH
i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. A SQL Injection vulnerability was found prior to the 2.9 branch in the `ieducar/intranet/funcionario_vinculo_det.php` file, which creates the query by concatenating the unsanitized GET parameter `cod_func`, allowing the attacker to obtain sensitive information such as emails and password hashes. Commit 7824b95745fa2da6476b9901041d9c854bf52ffe fixes the issue.
CVE-2024-44921 1 Seacms 1 Seacms 2026-06-17 N/A 9.8 CRITICAL
SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.
CVE-2024-44906 1 Uptrace 1 Pgdriver 2026-06-17 N/A 6.5 MEDIUM
uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/format.go. The maintainer has stated that the issue is fixed in v1.2.15.
CVE-2024-44905 1 Uptrace 1 Pg 2026-06-17 N/A 6.5 MEDIUM
go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.
CVE-2024-44903 2026-06-17 N/A 7.5 HIGH
SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable.
CVE-2024-44839 1 Openrapid 1 Rapidcms 2026-06-17 N/A 9.8 CRITICAL
RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.php.
CVE-2024-44838 1 Openrapid 1 Rapidcms 2026-06-17 N/A 9.8 CRITICAL
RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin.php.
CVE-2024-44817 1 Zzcms 1 Zzcms 2026-06-17 N/A 8.8 HIGH
SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component.
CVE-2024-44812 1 Janobe 1 Online Complaint Site 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the username and password parameters in the /admin.index.php component.
CVE-2024-44761 1 Gzequan 1 Eq Enterprise Management System 2026-06-17 N/A 9.8 CRITICAL
An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.
CVE-2024-44756 1 Nuserp 1 Nus-m9 Erp 2026-06-17 N/A 9.8 CRITICAL
NUS-M9 ERP Management Software v3.0.0 was discovered to contain a SQL injection vulnerability via the usercode parameter at /UserWH/checkLogin.
CVE-2024-44739 1 Oretnom23 1 Simple Forum Website 2026-06-17 N/A 8.8 HIGH
Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.
CVE-2024-44727 1 Angeljudesuarez 1 Event Management System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.
CVE-2024-44725 1 Autocms Project 1 Autocms 2026-06-17 N/A 7.2 HIGH
AutoCMS v5.4 was discovered to contain a SQL injection vulnerability via the sidebar parameter at /admin/robot.php.
CVE-2024-44664 1 Phpgurukul 1 Online Shopping Portal 2026-06-17 N/A 6.5 MEDIUM
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php.