Vulnerabilities (CVE)

Filtered by CWE-89
Total 20789 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-25212 1 Sherlock 1 Employee Management System 2026-06-17 N/A 7.2 HIGH
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php.
CVE-2024-25211 1 Rems 1 Simple Expense Tracker App 2026-06-17 N/A 9.8 CRITICAL
Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php.
CVE-2024-25210 1 Rems 1 Simple Expense Tracker App 2026-06-17 N/A 9.8 CRITICAL
Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php.
CVE-2024-25209 1 Rems 1 Barangay Population Monitoring System 2026-06-17 N/A 9.8 CRITICAL
Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php.
CVE-2024-25168 1 Dingflow 1 Snow 2026-06-17 N/A 6.3 MEDIUM
SQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope parameter of the system/role/list interface.
CVE-2024-24868 1 Smartypantsplugins 1 Sp Project \& Document Manager 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.69.
CVE-2024-24813 1 Frappe 1 Frappe 2026-06-17 N/A 7.5 HIGH
Frappe is a full-stack web application framework. Prior to versions 14.64.0 and 15.0.0, SQL injection from a particular whitelisted method can result in access to data which the user doesn't have permission to access. Versions 14.64.0 and 15.0.0 contain a patch for this issue. No known workarounds are available.
CVE-2024-24811 1 Zope 1 Sqlalchemyda 2026-06-17 N/A 9.8 CRITICAL
SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbitrary SQL statements on the database to which the SQLAlchemyDA instance is connected. All users are affected. The problem has been patched in version 2.2. There is no workaround for the problem.
CVE-2024-24772 1 Apache 1 Superset 2026-06-17 N/A 4.3 MEDIUM
A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.
CVE-2024-24572 1 Facilemanager 1 Facilemanager 2026-06-17 N/A 6.5 MEDIUM
facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, the $_REQUEST global array was unsafely called inside an extract() function in admin-logs.php. The PHP file fm-init.php prevents arbitrary manipulation of $_SESSION via the GET/POST parameters. However, it does not prevent manipulation of any other sensitive variables such as $search_sql. Knowing this, an authenticated user with privileges to view site logs can manipulate the search_sql variable by appending a GET parameter search_sql in the URL. The information above means that the checks and SQL injection prevention attempts were rendered unusable.
CVE-2024-24495 1 Remyandrade 1 Daily Habit Tracker 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.
CVE-2024-24407 1 Mayurik 1 Best Courier Management System 2026-06-17 N/A 5.3 MEDIUM
SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive information via print_pdets.php component.
CVE-2024-24401 1 Nagios 1 Nagios Xi 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.
CVE-2024-24375 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 N/A 7.5 HIGH
SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter.
CVE-2024-24323 1 Linlinjava 1 Litemall 2026-06-17 N/A 7.2 HIGH
SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via the nickname, consignee, orderSN, orderStatusArray parameters of the AdminOrdercontroller.java component.
CVE-2024-24310 1 Ethercreation 1 Generate Barcode On Invoice \/ Delivery Slip 2026-06-17 N/A 8.8 HIGH
In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaShop, a guest can perform SQL injection.
CVE-2024-24308 1 Boostmyshop 1 Boostmyshop 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php.
CVE-2024-24303 1 Hipresta 1 Gift Wrapping Pro 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information via the HiAdvancedGiftWrappingGiftWrappingModuleFrontController::addGiftWrappingCartValue() method.
CVE-2024-24256 1 Yonyou 1 Yonyou 2026-06-17 N/A 5.9 MEDIUM
SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an attacker to obtain sensitive information via the gwbhAIM parameter in the saveMove.jsp in the hr_position directory.
CVE-2024-24213 1 Supabase 1 Postgres 2026-06-17 N/A 9.8 CRITICAL
Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended feature; also, it exists in the Supabase dashboard product, not the Supabase PostgreSQL product. Specifically, /pg_meta/default/query is for SQL queries that are entered in an intended UI by an authorized user. Nothing is injected.