Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-41947 1 Intelliants 1 Subrion Cms 2026-06-17 6.5 MEDIUM 7.2 HIGH
A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.
CVE-2021-41942 1 Msvod 1 Msvod Cms 2026-06-17 5.0 MEDIUM 7.5 HIGH
The Magic CMS MSVOD v10 video system has a SQL injection vulnerability. Attackers can use vulnerabilities to obtain sensitive information in the database.
CVE-2021-41932 1 Wolterskluwer 1 Teammate\+ Audit 2026-06-17 6.5 MEDIUM 8.8 HIGH
A blind SQL injection vulnerability in search form in TeamMate+ Audit version 28.0.19.0 allows any authenticated user to create malicious SQL injections, which can result in complete database compromise, gaining information about other users, unauthorized access to audit data etc.
CVE-2021-41931 1 Recruitment Management System Project 1 Recruitment Management System 2026-06-17 7.5 HIGH 9.8 CRITICAL
The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnerable to SQL injection. The payloads 19424269' or '1309'='1309 and 39476597' or '2917'='2923 were each submitted in the id parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.
CVE-2021-41928 1 Try My Recipe Project 1 Try My Recipe 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code via the rid parameter to the view_recipe page.
CVE-2021-41920 1 Webtareas Project 1 Webtareas 2026-06-17 5.0 MEDIUM 7.5 HIGH
webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker to access all the data in the database and obtain access to the webTareas application.
CVE-2021-41845 1 Thycotic 1 Secret Server 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
A SQL injection issue was discovered in ThycoticCentrify Secret Server before 11.0.000007. The only affected versions are 10.9.000032 through 11.0.000006.
CVE-2021-41843 1 Open-emr 1 Openemr 2026-06-17 6.8 MEDIUM 6.5 MEDIUM
An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables of the database via the parameter provider_id, as demonstrated by the /interface/main/calendar/index.php?module=PostCalendar&func=search URI.
CVE-2021-41765 1 Montala 1 Resourcespace 2026-06-17 7.5 HIGH 9.8 CRITICAL
A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote unauthenticated attackers to execute arbitrary SQL commands via the k parameter. This allows attackers to uncover the full contents of the ResourceSpace database, including user session cookies. An attacker who gets an admin user session cookie can use the session cookie to execute arbitrary code on the server.
CVE-2021-41756 1 Dynamicvision 1 Dynamicmarkt 2026-06-17 7.5 HIGH 9.8 CRITICAL
dynamicMarkt <= 3.10 is affected by SQL injection in the kat parameter of index.php.
CVE-2021-41755 1 Dynamicvision 1 Dynamicmarkt 2026-06-17 7.5 HIGH 9.8 CRITICAL
dynamicMarkt <= 3.10 is affected by SQL injection in the kat1 parameter of index.php.
CVE-2021-41754 1 Dynamicvision 1 Dynamicmarkt 2026-06-17 7.5 HIGH 9.8 CRITICAL
dynamicMarkt <= 3.10 is affected by SQL injection in the parent parameter of index.php.
CVE-2021-41746 1 Yonyou 1 Turbocrm 2026-06-17 5.0 MEDIUM 7.5 HIGH
SQL Injection vulnerability exists in all versions of Yonyou TurboCRM.via the orgcode parameter in changepswd.php. Attackers can use the vulnerabilities to obtain sensitive database information.
CVE-2021-41695 1 Globaldatingsoftware 1 Premiumdatingscript 2026-06-17 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. .
CVE-2021-41691 1 Os4ed 1 Opensis 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.
CVE-2021-41679 1 Os4ed 1 Opensis 2026-06-17 6.8 MEDIUM 9.8 CRITICAL
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.php, period parameter.
CVE-2021-41678 1 Os4ed 1 Opensis 2026-06-17 6.8 MEDIUM 9.8 CRITICAL
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter.
CVE-2021-41677 1 Os4ed 1 Opensis 2026-06-17 6.8 MEDIUM 9.8 CRITICAL
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade= parameter.
CVE-2021-41676 1 Pharmacy Point Of Sale System Project 1 Pharmacy Point Of Sale System 2026-06-17 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerabilty exists in the oretnom23 Pharmacy Point of Sale System 1.0 in the login function in actions.php.
CVE-2021-41674 1 E-negosyo System Project 1 E-negosyo System 2026-06-17 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester E-Negosyo System 1.0 via the user_email parameter in /admin/login.php.