Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-42786 1 Lopalopa 1 Music Management System 2026-06-17 N/A 8.8 HIGH
A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter of View User Profile Page.
CVE-2024-42785 1 Lopalopa 1 Music Management System 2026-06-17 N/A 8.8 HIGH
A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.
CVE-2024-42784 1 Lopalopa 1 Music Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.
CVE-2024-42783 1 Lopalopa 1 Music Management System 2026-06-17 N/A 9.8 CRITICAL
Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php. An attacker can execute arbitrary SQL commands via the "pid" parameter.
CVE-2024-42782 1 Lopalopa 1 Music Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "search" parameter.
CVE-2024-42781 1 Lopalopa 1 Music Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email parameter.
CVE-2024-42765 1 Kjayvik 1 Bus Ticket Reservation System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in "/login.php" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the "email" or "password" Login page parameters.
CVE-2024-42760 1 Ellevo 1 Ellevo 2026-06-17 N/A 7.5 HIGH
SQL Injection vulnerability in Ellevo v.6.2.0.38160 allows a remote attacker to obtain sensitive information via the /api/mob/instrucao/conta/destinatarios component.
CVE-2024-42679 1 Cysoft168 1 Super Easy Enterprise Management System 2026-06-17 N/A 7.8 HIGH
SQL Injection vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the/ajax/Login.ashx component.
CVE-2024-42575 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php.
CVE-2024-42574 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php.
CVE-2024-42573 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php.
CVE-2024-42572 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.
CVE-2024-42571 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.
CVE-2024-42570 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php.
CVE-2024-42569 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.
CVE-2024-42568 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php.
CVE-2024-42567 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2.
CVE-2024-42566 1 Arajajyothibabu 1 School Management System 2026-06-17 N/A 9.8 CRITICAL
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php
CVE-2024-42565 1 Jerryhanjj 1 Erp 2026-06-17 N/A 9.8 CRITICAL
ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete.