Vulnerabilities (CVE)

Filtered by CWE-89
Total 20803 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-45019 1 Online Bus Booking System Project 1 Online Bus Booking System 2026-06-17 N/A 9.8 CRITICAL
Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'category' parameter of the category.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-45018 1 Online Bus Booking System Project 1 Online Bus Booking System 2026-06-17 N/A 9.8 CRITICAL
Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the includes/login.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-45015 1 Online Bus Booking System Project 1 Online Bus Booking System 2026-06-17 N/A 9.8 CRITICAL
Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'date' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-45012 1 Online Bus Booking System Project 1 Online Bus Booking System 2026-06-17 N/A 9.8 CRITICAL
Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'user_email' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-45001 1 Castos 1 Seriously Simple Stats 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Castos Seriously Simple Stats allows SQL Injection.This issue affects Seriously Simple Stats: from n/a through 1.5.0.
CVE-2023-44961 1 Koha-community 1 Koha Library Software 2026-06-17 N/A 7.5 HIGH
SQL Injection vulnerability in Koha Library Software 23.0.5.04 and before allows a remote attacker to obtain sensitive information via the intranet/cgi bin/cataloging/ysearch.pl. component.
CVE-2023-44755 1 Mayurik 1 Sacco Management System 2026-06-17 N/A 9.8 CRITICAL
Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php.
CVE-2023-44694 1 Dlink 2 Dar-7000, Dar-7000 Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /log/mailrecvview.php.
CVE-2023-44693 1 Dlink 2 Dar-7000, Dar-7000 Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php.
CVE-2023-44482 1 Projectworlds 1 Leave Management System 2026-06-17 N/A 8.8 HIGH
Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setsickleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-44481 1 Projectworlds 1 Leave Management System 2026-06-17 N/A 8.8 HIGH
Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearnleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-44480 1 Projectworlds 1 Leave Management System 2026-06-17 N/A 8.8 HIGH
Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setcasualleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-44450 1 Netgear 1 Prosafe Network Management System 2026-06-17 N/A 8.8 HIGH
NETGEAR ProSAFE Network Management System getNodesByTopologyMapSearch SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the getNodesByTopologyMapSearch function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-21858.
CVE-2023-44449 1 Netgear 1 Prosafe Network Management System 2026-06-17 N/A 8.8 HIGH
NETGEAR ProSAFE Network Management System clearAlertByIds SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the clearAlertByIds function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-21875.
CVE-2023-44294 1 Dell 1 Secure Connect Gateway 2026-06-17 N/A 5.4 MEDIUM
In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of Collection Rest API. This issue may potentially lead to unintentional information disclosure from the product database.
CVE-2023-44293 1 Dell 1 Secure Connect Gateway 2026-06-17 N/A 5.4 MEDIUM
In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of IP Range Rest API. This issue may potentially lead to unintentional information disclosure from the product database.
CVE-2023-44284 1 Dell 12 Apex Protection Storage, Dd3300, Dd6400 and 9 more 2026-06-17 N/A 4.3 MEDIUM
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database causing unauthorized read access to application data.
CVE-2023-44267 1 Projectworlds 1 Online Art Gallery 2026-06-17 N/A 9.8 CRITICAL
Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'lnm' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-44166 1 Projectworlds 1 Online Movie Ticket Booking System 2026-06-17 N/A 9.8 CRITICAL
The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-44164 1 Projectworlds 1 Online Movie Ticket Booking System 2026-06-17 N/A 9.8 CRITICAL
The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.