Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-34532 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allows a remote attacker to gain privileges via the query parameter to models/querydeluxe.py:QueryDeluxe::get_result_from_query.
CVE-2024-34480 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.
CVE-2024-34479 1 Oretnom23 1 Computer Laboratory Management System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection.
CVE-2024-34472 1 Hsclabs 1 Mailinspector 2026-06-17 N/A 5.5 MEDIUM
An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in a POST request to /mailinspector/mliRealtimeEmails.php does not properly sanitize input, allowing an authenticated attacker to execute arbitrary SQL commands, leading to the potential disclosure of the entire application database.
CVE-2024-34458 1 Keyfactor 1 Command 2026-06-17 N/A 7.5 HIGH
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure.
CVE-2024-34412 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Parcel Panel ParcelPanel.This issue affects ParcelPanel: from n/a through 3.8.1.
CVE-2024-34386 2026-06-17 N/A 7.6 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Auto Affiliate Links.This issue affects Auto Affiliate Links: from n/a through 6.4.3.1.
CVE-2024-34327 1 Sielox 1 Anyware 2026-06-17 N/A 6.5 MEDIUM
Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the password reset form.
CVE-2024-34310 2026-06-17 N/A 8.8 HIGH
Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter.
CVE-2024-34256 1 Ofcms Project 1 Ofcms 2026-06-17 N/A 9.8 CRITICAL
OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.
CVE-2024-34226 1 Oretnom23 1 Visitor Management System 2026-06-17 N/A 9.4 CRITICAL
SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.
CVE-2024-34222 1 Oretnom23 1 Human Resource Management System 2026-06-17 N/A 5.9 MEDIUM
Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.
CVE-2024-34220 1 Oretnom23 1 Human Resource Management System 2026-06-17 N/A 7.5 HIGH
Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.
CVE-2024-34032 1 Deltaww 1 Diaenergie 2026-06-17 N/A 8.8 HIGH
Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.
CVE-2024-34031 1 Deltaww 1 Diaenergie 2026-06-17 N/A 8.8 HIGH
Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.
CVE-2024-33974 1 Janobe 2 School Attendence Monitoring System, School Event Management System 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Users in '/report/printlogs.php' parameter.
CVE-2024-33973 1 Janobe 5 Credit Card, Debit Card Payment, Paypal and 2 more 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Attendance' and 'YearLevel' in '/report/attendance_print.php' parameter.
CVE-2024-33972 1 Janobe 5 Credit Card, Debit Card Payment, Paypal and 2 more 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'events' in '/report/event_print.php' parameter.
CVE-2024-33971 1 Janobe 5 Credit Card, Debit Card Payment, Paypal and 2 more 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'username' in '/login.php' parameter.
CVE-2024-33970 1 Janobe 5 Credit Card, Debit Card Payment, Paypal and 2 more 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'studid' in '/candidate/controller.php' parameter.