Vulnerabilities (CVE)

Filtered by CWE-89
Total 20791 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-23470 1 Ibm 1 I 2026-06-17 N/A 6.4 MEDIUM
IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a result of improper SQL processing. By using a specially crafted SQL operation, the administrator could exploit the vulnerability to perform additional administrator operations. IBM X-Force ID: 244510.
CVE-2023-23459 2 Microsoft, Priority-software 2 Windows, Priority 2026-06-17 N/A 9.1 CRITICAL
Priority Windows may allow Command Execution via SQL Injection using an unspecified method.
CVE-2023-23331 1 Amano 1 Xoffice 2026-06-17 N/A 9.8 CRITICAL
Amano Xoffice parking solutions 7.1.3879 is vulnerable to SQL Injection.
CVE-2023-23315 1 Stripe 1 Stripe Payment Pro 2026-06-17 N/A 9.8 CRITICAL
The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
CVE-2023-23279 1 Canteen Management System Project 1 Canteen Management System 2026-06-17 N/A 9.8 CRITICAL
Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php.
CVE-2023-23163 1 Phpgurukul 1 Art Gallery Management System 2026-06-17 N/A 9.8 CRITICAL
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.
CVE-2023-23162 1 Phpgurukul 1 Art Gallery Management System 2026-06-17 N/A 9.8 CRITICAL
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.
CVE-2023-23156 1 Phpgurukul 1 Art Gallery Management System 2026-06-17 N/A 9.8 CRITICAL
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.
CVE-2023-23155 1 Phpgurukul 1 Art Gallery Management System 2026-06-17 N/A 9.8 CRITICAL
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login.
CVE-2023-23007 1 Ecisp 1 Espcms 2026-06-17 N/A 7.2 HIGH
An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability in the function node where members are added.
CVE-2023-22959 1 Webchess Project 1 Webchess 2026-06-17 N/A 8.8 HIGH
WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName).
CVE-2023-22900 1 Thinkingsoftware 1 Efence 2026-06-17 N/A 9.8 CRITICAL
Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.
CVE-2023-22794 1 Activerecord Project 1 Activerecord 2026-06-17 N/A 8.8 HIGH
A vulnerability in ActiveRecord <6.0.6.1, v6.1.7.1 and v7.0.4.1 related to the sanitization of comments. If malicious user input is passed to either the `annotate` query method, the `optimizer_hints` query method, or through the QueryLogs interface which automatically adds annotations, it may be sent to the database withinsufficient sanitization and be able to inject SQL outside of the comment.
CVE-2023-22727 1 Cakephp 1 Cakephp 2026-06-17 N/A 9.8 CRITICAL
CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users unable to upgrade may mitigate this issue by using CakePHP's Pagination library. Manually validating or casting parameters to these methods will also mitigate the issue.
CVE-2023-22630 1 Izybat 1 Orange Casiers 2026-06-17 N/A 4.3 MEDIUM
IzyBat Orange casiers before 20221102_1 allows SQL Injection via a getCasier.php?taille= URI.
CVE-2023-22583 1 Danfoss 2 Ak-em100, Ak-em100 Firmware 2026-06-17 N/A 10.0 CRITICAL
The Danfoss AK-EM100 web forms allow for SQL injection in the login forms.
CVE-2023-22491 1 Gatsbyjs 1 Gatsby 2026-06-17 N/A 8.1 HIGH
Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` npm package, which is vulnerable to JavaScript injection in its default configuration, unless input is sanitized. The vulnerability is present in gatsby-transformer-remark when passing input in data mode (querying MarkdownRemark nodes via GraphQL). Injected JavaScript executes in the context of the build server. To exploit this vulnerability untrusted/unsanitized input would need to be sourced by or added into a file processed by gatsby-transformer-remark. A patch has been introduced in `gatsby-transformer-remark@5.25.1` and `gatsby-transformer-remark@6.3.2` which mitigates the issue by disabling the `gray-matter` JavaScript Frontmatter engine. As a workaround, if an older version of `gatsby-transformer-remark` must be used, input passed into the plugin should be sanitized ahead of processing. It is encouraged for projects to upgrade to the latest major release branch for all Gatsby plugins to ensure the latest security updates and bug fixes are received in a timely manner.
CVE-2023-22378 1 Nozominetworks 2 Cmc, Guardian 2026-06-17 N/A 8.8 HIGH
A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting parameter, allows an authenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application. Authenticated users may be able to extract arbitrary information from the DBMS in an uncontrolled way, alter its structure and data, and/or affect its availability.
CVE-2023-22324 1 Contec 1 Conprosys Hmi System 2026-06-17 N/A 6.5 MEDIUM
SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in the database may be obtained.
CVE-2023-22319 1 Milesight 1 Milesightvpn 2026-06-17 N/A 7.3 HIGH
A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a malicious packet to trigger this vulnerability.