Vulnerabilities (CVE)

Filtered by CWE-89
Total 20803 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-46349 1 Myprestamodules 1 Updateproducts 2026-06-17 N/A 9.8 CRITICAL
In the module "Product Catalog (CSV, Excel) Export/Update" (updateproducts) < 3.8.5 from MyPrestaModules for PrestaShop, a guest can perform SQL injection. The method `productsUpdateModel::getExportIds()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
CVE-2023-46348 1 Sunnytoo 1 Sturls 2026-06-17 N/A 9.8 CRITICAL
SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and StUrls::getInstanceId methods.
CVE-2023-46347 1 Ndkdesign 1 Ndk Steppingpack 2026-06-17 N/A 9.8 CRITICAL
In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getPacks()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
CVE-2023-46097 1 Siemens 1 Simatic Pcs Neo 2026-06-17 N/A 6.3 MEDIUM
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of affected products does not properly neutralize user provided inputs. This could allow an authenticated adjacent attacker to execute SQL statements in the underlying database.
CVE-2023-46084 1 Bplugins 1 Icons Font Loader 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2.
CVE-2023-46025 1 Phpgurukul 1 Teacher Subject Allocation Management System 2026-06-17 N/A 4.9 MEDIUM
SQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to obtain sensitive information via the 'editid' parameter.
CVE-2023-46024 1 Phpgurukul 1 Teacher Subject Allocation Management System 2026-06-17 N/A 7.5 HIGH
SQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary SQL commands and obtain sensitive information via the 'searchdata' parameter.
CVE-2023-46023 1 Code-projects 1 Simple Task List 2026-06-17 N/A 6.5 MEDIUM
SQL injection vulnerability in addTask.php in Code-Projects Simple Task List 1.0 allows attackers to obtain sensitive information via the 'status' parameter.
CVE-2023-46022 1 Code-projects 1 Blood Bank 2026-06-17 N/A 7.8 HIGH
SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via the 'bid' parameter.
CVE-2023-46021 1 Code-projects 1 Blood Bank 2026-06-17 N/A 5.5 MEDIUM
SQL Injection vulnerability in cancel.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary commands via the 'reqid' parameter.
CVE-2023-46018 1 Code-projects 1 Blood Bank 2026-06-17 N/A 5.5 MEDIUM
SQL injection vulnerability in receiverReg.php in Code-Projects Blood Bank 1.0 \allows attackers to run arbitrary SQL commands via 'remail' parameter.
CVE-2023-46017 1 Code-projects 1 Blood Bank 2026-06-17 N/A 5.5 MEDIUM
SQL Injection vulnerability in receiverLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'remail' and 'rpassword' parameters.
CVE-2023-46014 1 Code-projects 1 Blood Bank 2026-06-17 N/A 5.5 MEDIUM
SQL Injection vulnerability in hospitalLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'hemail' and 'hpassword' parameters.
CVE-2023-46007 1 Mayurik 1 Best Courier Management System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_staff.php.
CVE-2023-46006 1 Mayurik 1 Best Courier Management System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_user.php.
CVE-2023-46005 1 Mayurik 1 Best Courier Management System 2026-06-17 N/A 9.8 CRITICAL
Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_branch.php.
CVE-2023-45996 1 Slims 2 Senayan Library Management System, Senayan Library Management System Bulian 2026-06-17 N/A 8.8 HIGH
SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the reborrowLimit parameter in the member_type.php.
CVE-2023-45951 1 Lylme 1 Lylme Spage 2026-06-17 N/A 9.8 CRITICAL
lylme_spage v1.7.0 was discovered to contain a SQL injection vulnerability via the $userip parameter at function.php.
CVE-2023-45860 1 Hazelcast 1 Hazelcast 2026-06-17 N/A 6.5 MEDIUM
In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.
CVE-2023-45830 1 Adaplugin 1 Accessibility Suite By Online Ada 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Online ADA Accessibility Suite by Online ADA allows SQL Injection.This issue affects Accessibility Suite by Online ADA: from n/a through 4.12.