Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-40541 1 Codermy 1 My-springsecurity-plus 2026-06-17 N/A 9.8 CRITICAL
my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/dept/build.
CVE-2024-40540 1 Codermy 1 My-springsecurity-plus 2026-06-17 N/A 9.8 CRITICAL
my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/dept.
CVE-2024-40539 1 Codermy 1 My-springsecurity-plus 2026-06-17 N/A 9.8 CRITICAL
my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/user.
CVE-2024-40502 1 Angeljudesuarez 1 Hospital Management System 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute arbitrary code via the btn_login_b_Click function of the Loginpage.aspx
CVE-2024-40498 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php
CVE-2024-40486 1 Lopalopa 1 Live Membership System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters.
CVE-2024-40479 1 Jayesh 1 Online Exam System 2026-06-17 N/A 8.1 HIGH
A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers to execute arbitrary SQL commands via the "eid" parameter.
CVE-2024-40477 1 Phpgurukul 1 Old Age Home Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in "/oahms/admin/forgot-password.php" in PHPGurukul Old Age Home Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "email" parameter.
CVE-2024-40472 1 Rems 1 Daily Calories Monitoring Tool 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."
CVE-2024-40456 1 Thinksaas 1 Thinksaas 2026-06-17 N/A 9.8 CRITICAL
ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php.
CVE-2024-40443 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 4.3 MEDIUM
SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php
CVE-2024-40402 1 Nikhil-bhalerao 1 Simple Library Management System 2026-06-17 N/A 6.3 MEDIUM
A SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulnerability stems from insufficient user input validation of the 'username' parameter, allowing attackers to inject malicious SQL queries.
CVE-2024-40393 1 Angeljudesuarez 1 Online Clinic Management System 2026-06-17 N/A 9.8 CRITICAL
Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user parameter at login.php.
CVE-2024-40392 1 Fkgeo 1 Pharmacy\/medical Store Point Of Sale System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and Bootstrap Framework with Source Code 1.0 was discovered to contain a SQL injection vulnerability via the name parameter under addnew.php.
CVE-2024-40322 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 N/A 8.8 HIGH
An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data
CVE-2024-40120 1 Seaweedfs 1 Seaweedfs 2026-06-17 N/A 6.5 MEDIUM
seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_store.go.
CVE-2024-40073 1 Oretnom23 1 Online Id Generator System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4.
CVE-2024-40072 1 Oretnom23 1 Online Id Generator System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.
CVE-2024-40068 1 Oretnom23 1 Online Id Generator System 2026-06-17 N/A 5.9 MEDIUM
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=templates/manage_template&id=1.
CVE-2024-3922 1 Dokan 1 Dokan 2026-06-17 N/A 10.0 CRITICAL
The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.