Vulnerabilities (CVE)

Filtered by CWE-89
Total 20789 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-47072 1 Sparxsystems 1 Enterprise Architect 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classifier dialog box..
CVE-2022-46999 1 Tuzicms 1 Tuzicms 2026-06-17 N/A 9.8 CRITICAL
Tuzicms v2.0.6 was discovered to contain a SQL injection vulnerability via the component \App\Manage\Controller\UserController.class.php.
CVE-2022-46966 1 Revenue Collection System Project 1 Revenue Collection System 2026-06-17 N/A 9.8 CRITICAL
Revenue Collection System v1.0 was discovered to contain a SQL injection vulnerability at step1.php.
CVE-2022-46956 1 Dynamic Transaction Queuing System Project 1 Dynamic Transaction Queuing System 2026-06-17 N/A 7.2 HIGH
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.
CVE-2022-46955 1 Dynamic Transaction Queuing System Project 1 Dynamic Transaction Queuing System 2026-06-17 N/A 9.8 CRITICAL
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=save_queue.
CVE-2022-46954 1 Dynamic Transaction Queuing System Project 1 Dynamic Transaction Queuing System 2026-06-17 N/A 9.8 CRITICAL
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_transaction.
CVE-2022-46953 1 Dynamic Transaction Queuing System Project 1 Dynamic Transaction Queuing System 2026-06-17 N/A 7.2 HIGH
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=save_window.
CVE-2022-46952 1 Dynamic Transaction Queuing System Project 1 Dynamic Transaction Queuing System 2026-06-17 N/A 7.2 HIGH
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_user.
CVE-2022-46951 1 Dynamic Transaction Queuing System Project 1 Dynamic Transaction Queuing System 2026-06-17 N/A 7.2 HIGH
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_uploads.
CVE-2022-46950 1 Dynamic Transaction Queuing System Project 1 Dynamic Transaction Queuing System 2026-06-17 N/A 7.2 HIGH
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_window.
CVE-2022-46949 1 Helmet Store Showroom Site Project 1 Helmet Store Showroom Site 2026-06-17 N/A 7.2 HIGH
Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_helmet.
CVE-2022-46947 1 Helmet Store Showroom Site Project 1 Helmet Store Showroom Site 2026-06-17 N/A 7.2 HIGH
Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.
CVE-2022-46946 1 Helmet Store Showroom Site Project 1 Helmet Store Showroom Site 2026-06-17 N/A 7.2 HIGH
Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_brand.
CVE-2022-46887 1 Nexusphp 1 Nexusphp 2026-06-17 N/A 9.8 CRITICAL
Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php.
CVE-2022-46860 1 Kaizencoders 1 Short Url 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaizenCoders Short URL allows SQL Injection.This issue affects Short URL: from n/a through 1.6.4.
CVE-2022-46859 1 Spiffyplugins 1 Spiffy Calendar 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.1.
CVE-2022-46849 1 Weblizar 1 Responsive Coming Soon \& Maintenance Mode 2026-06-17 N/A 7.6 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar Coming Soon Page – Responsive Coming Soon & Maintenance Mode allows SQL Injection.This issue affects Coming Soon Page – Responsive Coming Soon & Maintenance Mode: from n/a through 1.5.9.
CVE-2022-46818 1 Gopiplus 1 Email Posts To Subscribers 2026-06-17 N/A 8.2 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopi Ramasamy Email posts to subscribers allows SQL Injection.This issue affects Email posts to subscribers: from n/a through 6.2.
CVE-2022-46808 1 Reputeinfosystems 1 Armember 2026-06-17 N/A 8.2 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Repute Infosystems ARMember armember-membership allows SQL Injection.This issue affects ARMember: from n/a through 3.4.11.
CVE-2022-46764 2 Microsoft, Trueconf 2 Windows, Server 2026-06-17 N/A 9.8 CRITICAL
A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.