Vulnerabilities (CVE)

Filtered by CWE-89
Total 20792 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-27843 1 Ask For A Quote Project 1 Ask For A Quote 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability found in PrestaShop askforaquote v.5.4.2 and before allow a remote attacker to gain privileges via the QuotesProduct::deleteProduct component.
CVE-2023-27742 1 Idurarapp 1 Idurar 2026-06-17 N/A 9.8 CRITICAL
IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.
CVE-2023-27733 1 Dedecms 1 Dedecms 2026-06-17 N/A 7.2 HIGH
DedeCMS v5.7.106 was discovered to contain a SQL injection vulnerability via the component /dede/sys_sql_query.php.
CVE-2023-27709 1 Dedecms 1 Dedecms 2026-06-17 N/A 7.2 HIGH
SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint.
CVE-2023-27707 1 Dedecms 1 Dedecms 2026-06-17 N/A 7.2 HIGH
SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dede/group_store.php endpoint.
CVE-2023-27649 1 Bestools 1 Trusted Tools Free Music 2026-06-17 N/A 7.5 HIGH
SQL injection vulnerability found in Trusted Tools Free Music v.2.1.0.47, v.2.0.0.46, v.1.9.1.45, v.1.8.2.43 allows a remote attacker to cause a denial of service via the search history table
CVE-2023-27638 1 Tshirtecommerce 1 Custom Product Designer 2026-06-17 N/A 9.8 CRITICAL
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions hookActionCartSave and updateCustomizationTable, which could lead to a SQL injection. This is exploited in the wild in March 2023.
CVE-2023-27637 1 Tshirtecommerce 1 Custom Product Designer 2026-06-17 N/A 9.8 CRITICAL
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is exploited in the wild in March 2023.
CVE-2023-27610 1 Transbank 1 Transbank Webpay Rest 2026-06-17 N/A 5.5 MEDIUM
Auth. (admin+) SQL Injection (SQLi) vulnerability in TransbankDevelopers Transbank Webpay REST plugin <= 1.6.6 versions.
CVE-2023-27605 1 Wp Reroute Email Project 1 Wp Reroute Email 2026-06-17 N/A 5.5 MEDIUM
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sajjad Hossain WP Reroute Email allows SQL Injection.This issue affects WP Reroute Email: from n/a through 1.4.6.
CVE-2023-27570 1 Prestashop 1 Eo Tags 2026-06-17 N/A 9.8 CRITICAL
The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie.
CVE-2023-27569 1 Prestashop 1 Eo Tags 2026-06-17 N/A 9.8 CRITICAL
The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.
CVE-2023-27568 1 Spryker 1 Commerce Os 2026-06-17 N/A 8.8 HIGH
SQL injection vulnerability inSpryker Commerce OS 0.9 that allows for access to sensitive data via customer/order?orderSearchForm[searchText]=
CVE-2023-27463 1 Siemens 1 Ruggedcom Crossbow 2026-06-17 N/A 8.8 HIGH
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The audit log form of affected applications is vulnerable to SQL injection. This could allow authenticated remote attackers to execute arbitrary SQL queries on the server database.
CVE-2023-27411 1 Siemens 1 Ruggedcom Crossbow 2026-06-17 N/A 8.8 HIGH
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. This could allow an authenticated remote attackers to execute arbitrary SQL queries on the server database and escalate privileges.
CVE-2023-27358 1 Netgear 10 Rax30, Rax30 Firmware, Rax35 and 7 more 2026-06-17 N/A 8.8 HIGH
NETGEAR RAX30 SOAP Request SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of specific SOAP requests. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. Was ZDI-CAN-19754.
CVE-2023-27262 1 Idattend 1 Idweb 2026-06-17 N/A 9.8 CRITICAL
Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.
CVE-2023-27260 1 Idattend 1 Idweb 2026-06-17 N/A 9.8 CRITICAL
Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.
CVE-2023-27255 1 Idattend 1 Idweb 2026-06-17 N/A 9.8 CRITICAL
Unauthenticated SQL injection in the DeleteRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.
CVE-2023-27254 1 Idattend 1 Idweb 2026-06-17 N/A 9.8 CRITICAL
Unauthenticated SQL injection in the GetRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.