Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-33806 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /model/get_grade.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33805 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /model/get_student.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33804 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 6.3 MEDIUM
A SQL injection vulnerability in /model/get_subject.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33803 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 5.4 MEDIUM
A SQL injection vulnerability in /model/get_exam.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33802 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 6.5 MEDIUM
A SQL injection vulnerability in /model/get_student_subject.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the index parameter.
CVE-2024-33801 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /model/get_subject_routing.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33800 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /model/get_student1.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the index parameter.
CVE-2024-33799 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /model/get_teacher.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
CVE-2024-33787 2026-06-17 N/A 8.2 HIGH
Hengan Weighing Management Information Query Platform 2019-2021 53.25 was discovered to contain a SQL injection vulnerability via the tuser_Number parameter at search_user.aspx.
CVE-2024-33722 2026-06-17 N/A 6.3 MEDIUM
SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].
CVE-2024-33559 2026-06-17 N/A 9.3 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through 9.3.5.
CVE-2024-33551 1 8theme 1 Xstore Core 2026-06-17 N/A 9.3 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n/a through 5.3.5.
CVE-2024-33546 2026-06-17 N/A 9.6 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10.
CVE-2024-33544 2026-06-17 N/A 9.3 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10.
CVE-2024-33501 1 Fortinet 3 Fortianalyzer, Fortianalyzer Big Data, Fortimanager 2026-06-17 N/A 4.2 MEDIUM
Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attackerĀ to execute unauthorized code or commands via specifically crafted CLI requests.
CVE-2024-33485 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component
CVE-2024-33450 2026-06-17 N/A 7.5 HIGH
SQL Injection in Finereport v.8.0 allows a remote attacker to obtain sensitive information
CVE-2024-33444 1 Onethink 1 Onethink 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to the ModelModel.class.php component.
CVE-2024-33411 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /model/get_admin_profile.php in Campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the my_index parameter.
CVE-2024-33410 1 Campcodes 1 Complete Web-based School Management System 2026-06-17 N/A 8.1 HIGH
SQL injection vulnerability in /model/delete_range_grade.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.