Vulnerabilities (CVE)

Filtered by CWE-89
Total 20803 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-41891 1 Flyte 1 Flyteadmin 2026-06-17 N/A 3.5 LOW
FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. Prior to version 1.1.124, list endpoints on FlyteAdmin have a SQL vulnerability where a malicious user can send a REST request with custom SQL statements as list filters. The attacker needs to have access to the FlyteAdmin installation, typically either behind a VPN or authentication. Version 1.1.124 contains a patch for this issue.
CVE-2023-41887 1 Openrefine 1 Openrefine 2026-06-17 N/A 9.8 CRITICAL
OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any unauthenticated user to execute code on the server. Version 3.7.5 has a patch for this issue.
CVE-2023-41886 1 Openrefine 1 Openrefine 2026-06-17 N/A 7.5 HIGH
OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, an arbitrary file read vulnerability allows any unauthenticated user to read a file on a server. Version 3.7.5 fixes this issue.
CVE-2023-41884 1 Zoneminder 1 Zoneminder 2026-06-17 N/A 7.1 HIGH
ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query without sanitizing it which makes it vulnerable to sql injection. This vulnerability is fixed in 1.36.34.
CVE-2023-41685 1 Ilghera 1 Woocommerce Support System 2026-06-17 N/A 7.6 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ilGhera Woocommerce Support System allows SQL Injection.This issue affects Woocommerce Support System: from n/a through 1.2.1.
CVE-2023-41652 1 Carrcommunications 1 Rsvpmaker 2026-06-17 N/A 8.2 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 10.6.6.
CVE-2023-41640 1 Grupposcai 1 Realgimm 2026-06-17 N/A 8.8 HIGH
An improper error handling vulnerability in the component ErroreNonGestito.aspx of GruppoSCAI RealGimm 1.1.37p38 allows attackers to obtain sensitive technical information via a crafted SQL query.
CVE-2023-41636 1 Grupposcai 1 Realgimm 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in the Data Richiesta dal parameter of GruppoSCAI RealGimm v1.1.37p38 allows attackers to access the database and execute arbitrary commands via a crafted SQL query.
CVE-2023-41623 1 Emlog 1 Emlog 2026-06-17 N/A 7.2 HIGH
Emlog version pro2.1.14 was discovered to contain a SQL injection vulnerability via the uid parameter at /admin/media.php.
CVE-2023-41615 1 Phpgurukul 1 Zoo Management System 2026-06-17 N/A 9.8 CRITICAL
Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password fields.
CVE-2023-41594 1 Phpgurukul 1 Dairy Farm Shop Management System 2026-06-17 N/A 7.5 HIGH
Dairy Farm Shop Management System Using PHP and MySQL v1.1 was discovered to contain multiple SQL injection vulnerabilities in the Login function via the Username and Password parameters.
CVE-2023-41543 1 Jeecg 1 Jeecg Boot 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the component /sys/replicate/check.
CVE-2023-41542 1 Jeecg 1 Jeecg Boot 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component.
CVE-2023-41539 1 Phpjabbers 1 Business Directory Script 2026-06-17 N/A 7.5 HIGH
phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter.
CVE-2023-41532 1 Kishan0725 1 Hospital Management System 2026-06-17 N/A 8.8 HIGH
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch.php.
CVE-2023-41531 1 Kishan0725 1 Hospital Management System 2026-06-17 N/A 8.8 HIGH
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameters.
CVE-2023-41530 1 Kishan0725 1 Hospital Management System 2026-06-17 N/A 9.8 CRITICAL
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.
CVE-2023-41528 1 Kishan0725 1 Hospital Management System 2026-06-17 N/A 9.8 CRITICAL
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters.
CVE-2023-41527 1 Kishan0725 1 Hospital Management System 2026-06-17 N/A 9.8 CRITICAL
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.
CVE-2023-41526 1 Kishan0725 1 Hospital Management System 2026-06-17 N/A 9.8 CRITICAL
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters.