Vulnerabilities (CVE)

Filtered by CWE-89
Total 20789 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-44347 1 Sanitization Management System Project 1 Sanitization Management System 2026-06-17 N/A 7.2 HIGH
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=inquiries/view_inquiry&id=.
CVE-2022-44345 1 Sanitization Management System Project 1 Sanitization Management System 2026-06-17 N/A 7.2 HIGH
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=quotes/view_quote&id=.
CVE-2022-44298 1 Sscms 1 Siteserver Cms 2026-06-17 N/A 9.8 CRITICAL
SiteServer CMS 7.1.3 is vulnerable to SQL Injection.
CVE-2022-44297 1 Sscms 1 Siteserver Cms 2026-06-17 N/A 9.8 CRITICAL
SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
CVE-2022-44296 1 Sanitization Management System Project 1 Sanitization Management System 2026-06-17 N/A 7.2 HIGH
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/quotes/manage_remark.php?id=.
CVE-2022-44295 1 Sanitization Management System Project 1 Sanitization Management System 2026-06-17 N/A 7.2 HIGH
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/assign_team.php?id=.
CVE-2022-44294 1 Sanitization Management System Project 1 Sanitization Management System 2026-06-17 N/A 7.2 HIGH
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/manage_service&id=.
CVE-2022-44278 1 Sanitization Management System Project 1 Sanitization Management System 2026-06-17 N/A 7.2 HIGH
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=user/manage_user&id=.
CVE-2022-44277 1 Sanitization Management System Project 1 Sanitization Management System 2026-06-17 N/A 7.2 HIGH
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/classes/Master.php?f=delete_product.
CVE-2022-44151 1 Sanitization Management System Project 1 Sanitization Management System 2026-06-17 N/A 9.8 CRITICAL
Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.
CVE-2022-44140 1 Jizhicms 1 Jizhicms 2026-06-17 N/A 8.8 HIGH
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component.
CVE-2022-44139 1 Apartment Visitors Management System Project 1 Apartment Visitors Management System 2026-06-17 N/A 9.8 CRITICAL
Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.
CVE-2022-44137 1 Sanitization Management System Project 1 Sanitization Management System 2026-06-17 N/A 7.2 HIGH
SourceCodester Sanitization Management System 1.0 is vulnerable to SQL Injection.
CVE-2022-44120 1 Dedebiz 1 Dedecmsv6 2026-06-17 N/A 9.8 CRITICAL
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.
CVE-2022-44117 1 Boa 1 Boa 2026-06-17 N/A 9.8 CRITICAL
Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any support for SQL.
CVE-2022-44015 1 Simmeth 1 Lieferantenmanager 2026-06-17 N/A 9.8 CRITICAL
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating MSSQL features, the attacker is able to execute arbitrary commands on the MSSQL server via the xp_cmdshell extended procedure.
CVE-2022-44003 1 Backclick 1 Backclick 2026-06-17 N/A 9.8 CRITICAL
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.
CVE-2022-43860 1 Ibm 1 I 2026-06-17 N/A 4.3 MEDIUM
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authorized to but not while using this interface. By performing an SQL injection an attacker could see user profile attributes through this interface. IBM X-Force ID: 239305.
CVE-2022-43859 1 Ibm 1 I 2026-06-17 N/A 6.3 MEDIUM
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while using this interface. By performing a UNION based SQL injection an attacker could see file permissions through this interface. IBM X-Force ID: 239304.
CVE-2022-43842 3 Ibm, Linux, Microsoft 3 Aspera Console, Linux Kernel, Windows 2026-06-17 N/A 8.6 HIGH
IBM Aspera Console 3.4.0 through 3.4.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 239079.