Vulnerabilities (CVE)

Filtered by CWE-89
Total 20803 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-41525 1 Kishan0725 1 Hospital Management System 2026-06-17 N/A 9.8 CRITICAL
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.
CVE-2023-41524 1 Student Attendance Management System Project 1 Student Attendance Management System 2026-06-17 N/A 8.8 HIGH
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index.php.
CVE-2023-41523 1 Student Attendance Management System Project 1 Student Attendance Management System 2026-06-17 N/A 8.8 HIGH
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher.php.
CVE-2023-41522 1 Student Attendance Management System Project 1 Student Attendance Management System 2026-06-17 N/A 8.8 HIGH
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents.php via the Id, firstname, and admissionNumber parameters.
CVE-2023-41521 1 Student Attendance Management System Project 1 Student Attendance Management System 2026-06-17 N/A 8.8 HIGH
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessionTerm.php via the id, termId, and sessionName parameters.
CVE-2023-41520 1 Student Attendance Management System Project 1 Student Attendance Management System 2026-06-17 N/A 8.8 HIGH
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassArms.php via the classId and classArmName parameters.
CVE-2023-41507 1 Superstorefinder 1 Super Store Finder 2026-06-17 N/A 9.8 CRITICAL
Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters.
CVE-2023-41504 1 Code-projects 1 Student Enrollment 2026-06-17 N/A 8.8 HIGH
SQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Search function.
CVE-2023-41443 1 Xxyopen 1 Novel-plus 2026-06-17 N/A 7.2 HIGH
SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.
CVE-2023-41387 2 Apple, Patreon 2 Iphone Os, Flutter Downloader 2026-06-17 N/A 9.1 CRITICAL
A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses UIFileSharingEnabled and LSSupportsOpeningDocumentsInPlace properties. As a result, local users can obtain the same attack primitives as remote attackers by tampering with the internal database of the framework on the device.
CVE-2023-41364 1 Metaways 1 Tine 2026-06-17 N/A 9.8 CRITICAL
In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection.
CVE-2023-41328 1 Frappe 1 Frappe 2026-06-17 N/A 4.2 MEDIUM
Frappe is a low code web framework written in Python and Javascript. A SQL Injection vulnerability has been identified in the Frappe Framework which could allow a malicious actor to access sensitive information. This issue has been addressed in versions 13.46.1 and 14.20.0. Users are advised to upgrade. There's no workaround to fix this without upgrading.
CVE-2023-41320 1 Glpi-project 1 Glpi 2026-06-17 N/A 8.1 HIGH
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. UI layout preferences management can be hijacked to lead to SQL injection. This injection can be use to takeover an administrator account. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability.
CVE-2023-41287 1 Qnap 1 Video Station 2026-06-17 N/A 4.3 MEDIUM
A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.2 ( 2023/11/23 ) and later
CVE-2023-41285 1 Qnap 1 Qumagie 2026-06-17 N/A 7.4 HIGH
A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: QuMagie 2.1.4 and later
CVE-2023-41284 1 Qnap 1 Qumagie 2026-06-17 N/A 7.4 HIGH
A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: QuMagie 2.1.4 and later
CVE-2023-41262 1 Plixer 1 Scrutinizer 2026-06-17 N/A 9.8 CRITICAL
An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV is vulnerable to SQL injection through the sorting parameter, allowing an unauthenticated user to execute arbitrary SQL statements in the context of the application's backend database server.
CVE-2023-41015 1 Code-projects 1 Online Job Portal 2026-06-17 N/A 5.5 MEDIUM
code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via /Employer/DeleteJob.php?JobId=1.
CVE-2023-41014 1 Code-projects 1 Online Job Portal 2026-06-17 N/A 9.8 CRITICAL
code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer."
CVE-2023-40992 1 Kishan0725 1 Hospital Management System 2026-06-17 N/A 6.5 MEDIUM
Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 parameter.