Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-33247 1 Oretnom23 1 Employee Task Management System 2026-06-17 N/A 8.8 HIGH
Sourcecodester Employee Task Management System v1.0 is vulnerable to SQL Injection via admin-manage-user.php.
CVE-2024-33164 1 J2eefast 1 J2eefast 2026-06-17 N/A 9.8 CRITICAL
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList() function.
CVE-2024-33161 1 J2eefast 1 J2eefast 2026-06-17 N/A 5.3 MEDIUM
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function.
CVE-2024-33155 1 J2eefast 1 J2eefast 2026-06-17 N/A 9.8 CRITICAL
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function.
CVE-2024-33153 1 J2eefast 1 J2eefast 2026-06-17 N/A 9.8 CRITICAL
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList() function.
CVE-2024-33149 1 J2eefast 1 J2eefast 2026-06-17 N/A 8.1 HIGH
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessList function.
CVE-2024-33148 1 J2eefast 1 J2eefast 2026-06-17 N/A 7.3 HIGH
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function.
CVE-2024-33147 1 J2eefast 1 J2eefast 2026-06-17 N/A 8.8 HIGH
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList function.
CVE-2024-33146 1 J2eefast 1 J2eefast 2026-06-17 N/A 9.1 CRITICAL
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export function.
CVE-2024-33144 1 J2eefast 1 J2eefast 2026-06-17 N/A 8.8 HIGH
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedTasksPage function in BpmTaskMapper.xml.
CVE-2024-33139 1 J2eefast 1 J2eefast 2026-06-17 N/A 7.5 HIGH
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.
CVE-2024-33124 1 Roothub 1 Roothub 2026-06-17 N/A 9.8 CRITICAL
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function..
CVE-2024-33122 1 Roothub 1 Roothub 2026-06-17 N/A 6.3 MEDIUM
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.
CVE-2024-33121 1 Roothub 1 Roothub 2026-06-17 N/A 6.3 MEDIUM
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function.
CVE-2024-33009 2026-06-17 N/A 4.2 MEDIUM
SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted inputs to modify database commands resulting in the retrieval of additional information persisted by the system. This could lead to low impact on Confidentiality and Integrity of the application.
CVE-2024-32888 2026-06-17 N/A 10.0 CRITICAL
The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions. Prior to version 2.1.0.28, SQL injection is possible when using the non-default connection property `preferQueryMode=simple` in combination with application code which has a vulnerable SQL that negates a parameter value. There is no vulnerability in the driver when using the default, extended query mode. Note that `preferQueryMode` is not a supported parameter in Redshift JDBC driver, and is inherited code from Postgres JDBC driver. Users who do not override default settings to utilize this unsupported query mode are not affected. This issue is patched in driver version 2.1.0.28. As a workaround, do not use the connection property `preferQueryMode=simple`. (NOTE: Those who do not explicitly specify a query mode use the default of extended query mode and are not affected by this issue.)
CVE-2024-32872 2026-06-17 N/A 5.5 MEDIUM
Umbraco workflow provides workflows for the Umbraco content management system. Prior to versions 10.3.9, 12.2.6, and 13.0.6, an Umbraco Backoffice user can modify requests to a particular API endpoint to include SQL, which will be executed by the server. Umbraco Workflow versions 10.3.9, 12.2.6, 13.0.6, as well as Umbraco Plumber version 10.1.2, contain a patch for this issue.
CVE-2024-32848 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.2 HIGH
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-32847 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.2 HIGH
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-32846 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.2 HIGH
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.