Vulnerabilities (CVE)

Filtered by CWE-89
Total 20803 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-42660 1 Progress 1 Moveit Transfer 2026-06-17 N/A 8.8 HIGH
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer machine interface that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to the MOVEit Transfer machine interface which could result in modification and disclosure of MOVEit database content.
CVE-2023-42461 1 Glpi-project 1 Glpi 2026-06-17 N/A 6.5 MEDIUM
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The ITIL actors input field from the Ticket form can be used to perform a SQL injection. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability.
CVE-2023-42406 1 Dlink 2 Dar-7000, Dar-7000 Firmware 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive information and execute arbitrary code via the editrole.php component.
CVE-2023-42405 1 Fit2cloud 1 Rackshift 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` parameter to taskService.list(), bareMetalService.list(), and switchService.list().
CVE-2023-42359 1 Exam Form Submission In Php With Source Code Project 1 Exam Form Submission In Php With Source Code 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Exam Form Submission in PHP with Source Code v.1.0 allows a remote attacker to escalate privileges via the val-username parameter in /index.php.
CVE-2023-42284 1 Tyk 1 Tyk 2026-06-17 N/A 9.8 CRITICAL
Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.
CVE-2023-42283 1 Tyk 1 Tyk 2026-06-17 N/A 9.8 CRITICAL
Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.
CVE-2023-42279 1 Iteachyou 1 Dreamer Cms 2026-06-17 N/A 9.8 CRITICAL
Dreamer CMS v4.1.3 was discovered to contain a SQL injection vulnerability via the model-form-management-field form.
CVE-2023-42268 1 Jeecg 1 Jeecg Boot 2026-06-17 N/A 9.8 CRITICAL
Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show.
CVE-2023-42244 1 Seling 1 Visual Access Manager 2026-06-17 N/A 8.8 HIGH
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_visits.php.
CVE-2023-42243 1 Seling 1 Visual Access Manager 2026-06-17 N/A 5.4 MEDIUM
In Selesta Visual Access Manager < 4.42.2, an authenticated user can access the administrative page /common/vam_Sql.php, which allows for arbitrary SQL queries.
CVE-2023-42242 1 Seling 1 Visual Access Manager 2026-06-17 N/A 3.8 LOW
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /monitor/s_terminal.php.
CVE-2023-42241 1 Seling 1 Visual Access Manager 2026-06-17 N/A 3.8 LOW
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_anagraphic.php.
CVE-2023-42240 1 Seling 1 Visual Access Manager 2026-06-17 N/A 3.8 LOW
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /monitor/s_scheduledfile.php.
CVE-2023-42239 1 Seling 1 Visual Access Manager 2026-06-17 N/A 3.8 LOW
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_ep.php.
CVE-2023-42238 1 Seling 1 Visual Access Manager 2026-06-17 N/A 3.8 LOW
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_eps.php.
CVE-2023-42237 1 Seling 1 Visual Access Manager 2026-06-17 N/A 3.8 LOW
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i_command.php.
CVE-2023-42236 1 Seling 1 Visual Access Manager 2026-06-17 N/A 3.8 LOW
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /common/ajaxfunction.php.
CVE-2023-42235 1 Seling 1 Visual Access Manager 2026-06-17 N/A 3.8 LOW
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple parameters of /monitor/s_normalizedtrans.php.
CVE-2023-42178 1 Lenosp Project 1 Lenosp 2026-06-17 N/A 6.5 MEDIUM
Lenosp 1.0.0-1.2.0 is vulnerable to SQL Injection via the log query module.