Vulnerabilities (CVE)

Filtered by CWE-89
Total 20793 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-35070 1 Vegagroup 1 Web Collection 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VegaGroup Web Collection allows SQL Injection. This issue affects Web Collection: before 31197.
CVE-2023-35068 1 Bma 1 Personnel Tracking System 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BMA Personnel Tracking System allows SQL Injection. This issue affects Personnel Tracking System: before 20230904.
CVE-2023-35066 1 Infodrom 1 E-invoice Approval System 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software E-Invoice Approval System allows SQL Injection. This issue affects E-Invoice Approval System: before v.20230701.
CVE-2023-35065 1 Osoft 1 Dyeing - Printing - Finishing Production Management 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Production Management allows SQL Injection. This issue affects Paint Production Management: before 2.1.
CVE-2023-35064 1 Satos 1 Satos Mobile 2026-06-17 N/A 9.8 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Satos Satos Mobile allows SQL Injection through SOAP Parameter Tampering. This issue affects Satos Mobile: before 20230607.
CVE-2023-35036 1 Progress 1 Moveit Transfer 2026-06-17 N/A 9.1 CRITICAL
In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.
CVE-2023-34991 1 Fortinet 1 Fortiwlm 2026-06-17 N/A 9.8 CRITICAL
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8.4.2 and 8.3.0 through 8.3.2 and 8.2.2 allows attacker to execute unauthorized code or commands via a crafted http request.
CVE-2023-34976 1 Qnap 1 Video Station 2026-06-17 N/A 10.0 CRITICAL
A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.0 ( 2023/07/27 ) and later
CVE-2023-34975 1 Qnap 1 Video Station 2026-06-17 N/A 6.6 MEDIUM
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. QuTScloud is not affected. We have already fixed the vulnerability in the following versions: QuTS hero h4.5.4.2626 build 20231225 and later QTS 4.5.4.2627 build 20231225 and later
CVE-2023-34756 2 Apple, Bloofox 2 Macos, Bloofoxcms 2026-06-17 N/A 9.8 CRITICAL
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.
CVE-2023-34755 2 Apple, Bloofox 2 Macos, Bloofoxcms 2026-06-17 N/A 9.8 CRITICAL
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.
CVE-2023-34754 2 Apple, Bloofox 2 Macos, Bloofoxcms 2026-06-17 N/A 9.8 CRITICAL
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.
CVE-2023-34753 2 Apple, Bloofox 2 Macos, Bloofoxcms 2026-06-17 N/A 9.8 CRITICAL
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.
CVE-2023-34751 2 Apple, Bloofox 2 Macos, Bloofoxcms 2026-06-17 N/A 9.8 CRITICAL
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.
CVE-2023-34750 2 Apple, Bloofox 2 Macos, Bloofoxcms 2026-06-17 N/A 9.8 CRITICAL
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.
CVE-2023-34735 1 Property Cloud Platform Management Center Project 1 Property Cloud Platform Management Center 2026-06-17 N/A 9.8 CRITICAL
Property Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection.
CVE-2023-34659 1 Jeecg 1 Jeecg Boot 2026-06-17 N/A 9.8 CRITICAL
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
CVE-2023-34635 1 Wifi-soft 1 Unibox Administration 2026-06-17 N/A 9.8 CRITICAL
Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page.
CVE-2023-34626 1 Piwigo 1 Piwigo 2026-06-17 N/A 4.3 MEDIUM
Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function.
CVE-2023-34603 1 Jeecg 1 Jeecgboot 2026-06-17 N/A 7.5 HIGH
JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryFilterTableDictInfo at org.jeecg.modules.api.controller.SystemApiController.