Vulnerabilities (CVE)

Filtered by CWE-89
Total 20793 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-31845 1 Faculty Evaluation System Project 1 Faculty Evaluation System 2026-06-17 N/A 7.2 HIGH
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=.
CVE-2023-31844 1 Faculty Evaluation System Project 1 Faculty Evaluation System 2026-06-17 N/A 7.2 HIGH
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_subject.php?id=.
CVE-2023-31843 1 Faculty Evaluation System Project 1 Faculty Evaluation System 2026-06-17 N/A 7.2 HIGH
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/view_faculty.php?id=.
CVE-2023-31842 1 Faculty Evaluation System Project 1 Faculty Evaluation System 2026-06-17 N/A 7.2 HIGH
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/index.php?page=edit_faculty&id=.
CVE-2023-31753 1 Endonesia 1 Endonesia 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in diskusi.php in eNdonesia 8.7, allows an attacker to execute arbitrary SQL commands via the "rid=" parameter.
CVE-2023-31752 1 Oretnom23 1 Employee And Visitor Gate Pass Logging System 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/classes/Login.php.
CVE-2023-31719 1 Frangoteam 1 Fuxa 2026-06-17 N/A 9.8 CRITICAL
FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.
CVE-2023-31717 1 Frangoteam 1 Fuxa 2026-06-17 N/A 7.5 HIGH
A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.
CVE-2023-31714 1 Waqaskanju 1 Chitor-cms 2026-06-17 N/A 9.8 CRITICAL
Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.
CVE-2023-31707 1 Sem-cms 1 Semcms 2026-06-17 N/A 9.8 CRITICAL
SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.
CVE-2023-31702 1 Escanav 1 Escan Management Console 2026-06-17 N/A 7.2 HIGH
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire database and gain windows XP command shell to perform code execution on database server via GetUserCurrentPwd?UsrId=1.
CVE-2023-31672 1 Ai-dev 1 Ailinear 2026-06-17 N/A 9.8 CRITICAL
In the PrestaShop < 2.4.3 module "Length, weight or volume sell" (ailinear) there is a SQL injection vulnerability.
CVE-2023-31671 1 Webbax 1 Postfinance 2026-06-17 N/A 9.8 CRITICAL
PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via PostfinanceValidationModuleFrontController::postProcess().
CVE-2023-31631 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the sqlo_preds_contradiction component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2023-31630 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the sqlo_query_spec component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2023-31629 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the sqlo_union_scope component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2023-31628 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the stricmp component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2023-31627 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the strhash component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2023-31626 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the gpf_notice component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2023-31625 1 Openlinksw 1 Virtuoso 2026-06-17 N/A 7.5 HIGH
An issue in the psiginfo component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.