Vulnerabilities (CVE)

Filtered by CWE-89
Total 20789 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-39072 1 Zte 4 Mf286r, Mf286r Firmware, Mf289d and 1 more 2026-06-17 N/A 5.4 MEDIUM
There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP interface, an authenticated attacker could use the vulnerability to execute stored XSS attacks.
CVE-2022-39069 1 Zte 1 Zaip-aie 2026-06-17 N/A 5.3 MEDIUM
There is a SQL injection vulnerability in ZTE ZAIP-AIE. Due to lack of input verification by the server, an attacker could trigger an attack by building malicious requests. Exploitation of this vulnerability could cause the leakage of the current table content.
CVE-2022-39066 1 Zte 2 Mf286r, Mf286r Firmware 2026-06-17 N/A 8.8 HIGH
There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execute arbitrary SQL injection.
CVE-2022-39056 1 Changingtec 1 Rava Certificate Validation System 2026-06-17 N/A 9.8 CRITICAL
RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify and delete database.
CVE-2022-39041 1 Aenrich 1 A\+hrd 2026-06-17 N/A 9.8 CRITICAL
aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.
CVE-2022-38947 1 Jigar-sable 1 Flipkart-clone-php 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in Flipkart-Clone-PHP version 1.0 in entry.php in product_title parameter, allows attackers to execute arbitrary code.
CVE-2022-38923 1 Iss-oberlausitz 1 Bluepage Cms 2026-06-17 N/A 9.8 CRITICAL
BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' field using a Time-based blind SLEEP payload.
CVE-2022-38922 1 Iss-oberlausitz 1 Bluepage Cms 2026-06-17 N/A 9.8 CRITICAL
BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the 'users-cookie-settings' token using a Time-based blind SLEEP payload.
CVE-2022-38878 1 School Activity Updates With Sms Notification Project 1 School Activity Updates With Sms Notification 2026-06-17 N/A 7.2 HIGH
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=.
CVE-2022-38868 1 Ehoney Project 1 Ehoney 2026-06-17 N/A 7.2 HIGH
SQL Injection vulnerability in Ehoney version 2.0.0 in models/protocol.go and models/images.go, allows attackers to execute arbitrary code.
CVE-2022-38867 1 Rttys Project 1 Rttys 2026-06-17 N/A 8.8 HIGH
SQL Injection vulnerability in rttys versions 4.0.0, 4.0.1, 4.0.2, and 4.4.x in api.go, allows attackers to execute arbitrary code.
CVE-2022-38833 1 School Activity Updates With Sms Notification Project 1 School Activity Updates With Sms Notification 2026-06-17 N/A 7.2 HIGH
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=.
CVE-2022-38832 1 School Activity Updates With Sms Notification Project 1 School Activity Updates With Sms Notification 2026-06-17 N/A 7.2 HIGH
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=.
CVE-2022-38812 1 Aerocms Project 1 Aerocms 2026-06-17 N/A 6.5 MEDIUM
AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.
CVE-2022-38808 1 Yimihome 1 Ywoa 2026-06-17 N/A 8.8 HIGH
ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface.
CVE-2022-38771 1 Transtek 1 Mojodat Fixed Asset Management 2026-06-17 N/A 9.8 CRITICAL
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tags as injected input to the API request.
CVE-2022-38637 1 Hospital Management System Project 1 Hospital Management System 2026-06-17 N/A 9.8 CRITICAL
Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.
CVE-2022-38627 1 Niceforyou 2 Linear Emerge E3 Access Control, Linear Emerge E3 Access Control Firmware 2026-06-17 N/A 9.8 CRITICAL
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.
CVE-2022-38610 1 Garage Management System Project 1 Garage Management System 2026-06-17 N/A 7.2 HIGH
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editclient.php.
CVE-2022-38606 1 Garage Management System Project 1 Garage Management System 2026-06-17 N/A 7.2 HIGH
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editcategory.php.