Vulnerabilities (CVE)

Filtered by CWE-89
Total 20789 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-28557 1 Mayurik 1 Php Task Management System 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to update-admin.php.
CVE-2024-28556 1 Mayurik 1 Php Task Management System 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin-manage-user.php.
CVE-2024-28521 1 Netentsec 2 Application Security Gateway Firmware, Ns-asg 2026-06-17 N/A 7.8 HIGH
SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted script to the loginid parameter of the /singlelogin.php component.
CVE-2024-28421 1 Cobub 1 Razor 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updateapk method of the channelmodle.php
CVE-2024-28395 1 Best-kit 1 Bestkit Popup 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component.
CVE-2024-28393 1 Scalapay 1 Scalapay 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in scalapay v.1.2.41 and before allows a remote attacker to escalate privileges via the ScalapayReturnModuleFrontController::postProcess() method.
CVE-2024-28392 1 Prestashop 1 Abandoned Cart Reminder Pro 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method.
CVE-2024-28389 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail() method.
CVE-2024-28388 1 Sunnytoo 1 Product Comments 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method.
CVE-2024-28323 1 Phpgurukul 1 User Registration \& Login And User Management System 2026-06-17 N/A 6.5 MEDIUM
The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The script retrieves user-provided date inputs without proper validation, making it susceptible to SQL injection attacks.
CVE-2024-28322 1 Puneethreddyhc 1 Event Management 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST request.
CVE-2024-28303 2026-06-17 N/A 9.8 CRITICAL
Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php.
CVE-2024-28298 1 E-bmsoft 1 Bmplanning 2026-06-17 N/A 8.8 HIGH
SQL injection vulnerability in BM SOFT BMPlanning 1.0.0.1 allows authenticated users to execute arbitrary SQL commands via the SEC_IDF, LIE_IDF, PLANF_IDF, CLI_IDF, DOS_IDF, and possibly other parameters to /BMServerR.dll/BMRest.
CVE-2024-28297 2026-06-17 N/A 7.5 HIGH
SQL injection vulnerability in AzureSoft MyHorus 4.3.5 allows authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2024-28294 1 Limbas 1 Limbas 2026-06-17 N/A 6.5 MEDIUM
Limbas up to v5.2.14 was discovered to contain a SQL injection vulnerability via the ftid parameter.
CVE-2024-28279 1 Carmelo 1 Computer Book Store 2026-06-17 N/A 7.3 HIGH
Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.
CVE-2024-28145 2026-06-17 N/A 5.9 MEDIUM
An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.
CVE-2024-28107 1 Phpmyfaq 1 Phpmyfaq 2026-06-17 N/A 8.8 HIGH
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection vulnerability has been discovered in the `insertentry` & `saveentry` when modifying records due to improper escaping of the email address. This allows any authenticated user with the rights to add/edit FAQ news to exploit this vulnerability to exfiltrate data, take over accounts and in some cases, even achieve RCE. This vulnerability is fixed in 3.2.6.
CVE-2024-28094 1 Schoolbox 1 Schoolbox 2026-06-17 N/A 8.8 HIGH
Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the authenticated attackers to read, modify, and delete database records.
CVE-2024-28040 1 Deltaww 1 Diaenergie 2026-06-17 N/A 8.8 HIGH
SQL injection vulnerability exists in GetDIAE_astListParameters.