Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-27368 1 Chshcms 1 Cscms 2026-06-17 6.5 MEDIUM 7.2 HIGH
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Lists.php_zhuan.
CVE-2022-27367 1 Chshcms 1 Cscms 2026-06-17 6.5 MEDIUM 7.2 HIGH
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Topic.php_del.
CVE-2022-27366 1 Chshcms 1 Cscms 2026-06-17 6.5 MEDIUM 7.2 HIGH
Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the component dance_Dance.php_hy.
CVE-2022-27365 1 Chshcms 1 Cscms 2026-06-17 6.5 MEDIUM 7.2 HIGH
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del.
CVE-2022-27360 1 Bladex 1 Springblade 2026-06-17 7.5 HIGH 9.8 CRITICAL
SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.
CVE-2022-27342 1 Link-admin Project 1 Link-admin 2026-06-17 7.5 HIGH 9.8 CRITICAL
Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest.ResponseResult().
CVE-2022-27341 1 Jfinalcms Project 1 Jfinalcms 2026-06-17 7.5 HIGH 9.8 CRITICAL
JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function.
CVE-2022-27304 1 Oretnom23 1 Student Grading System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
CVE-2022-27299 1 Hospital Management System Project 1 Hospital Management System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.
CVE-2022-27175 1 Deltaww 1 Diaenergie 2026-06-17 10.0 HIGH 9.8 CRITICAL
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetCalcTagList. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
CVE-2022-27165 1 Cszcms 1 Csz Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus
CVE-2022-27164 1 Cszcms 1 Csz Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers
CVE-2022-27163 1 Cszcms 1 Csz Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser
CVE-2022-27162 1 Cszcms 1 Csz Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser
CVE-2022-27161 1 Cszcms 1 Csz Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers
CVE-2022-27127 1 Zbzcms 1 Zbzcms 2026-06-17 6.4 MEDIUM 6.5 MEDIUM
zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php/ajax.php.
CVE-2022-27126 1 Zbzcms 1 Zbzcms 2026-06-17 7.5 HIGH 9.8 CRITICAL
zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the art parameter at /include/make.php.
CVE-2022-27124 1 Angeljudesuarez 1 Insurance Management System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Insurance Management System 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
CVE-2022-27123 1 Employee Performance Evaluation Project 1 Employee Performance Evaluation 2026-06-17 7.5 HIGH 9.8 CRITICAL
Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter.
CVE-2022-27104 1 Formalms 1 Formalms 2026-06-17 7.5 HIGH 9.8 CRITICAL
An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3.