Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-38733 1 Sem-cms 1 Semcms 2026-06-17 N/A 9.8 CRITICAL
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
CVE-2021-38732 1 Sem-cms 1 Semcms 2026-06-17 N/A 9.8 CRITICAL
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
CVE-2021-38731 1 Sem-cms 1 Semcms 2026-06-17 N/A 9.8 CRITICAL
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
CVE-2021-38730 1 Sem-cms 1 Semcms 2026-06-17 N/A 9.8 CRITICAL
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
CVE-2021-38729 1 Sem-cms 1 Semcms 2026-06-17 N/A 9.8 CRITICAL
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
CVE-2021-38727 1 Thedaylightstudio 1 Fuel Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items
CVE-2021-38723 1 Thedaylightstudio 1 Fuel Cms 2026-06-17 6.5 MEDIUM 8.8 HIGH
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items
CVE-2021-38706 1 Cliniccases 1 Cliniccases 2026-06-17 6.5 MEDIUM 8.8 HIGH
messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter.
CVE-2021-38694 1 Softvibe 1 Saraban 2026-06-17 5.0 MEDIUM 7.5 HIGH
SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection.
CVE-2021-38574 1 Foxitsoftware 2 Foxit Reader, Phantompdf 2026-06-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.
CVE-2021-38481 1 Auvesy 1 Versiondog 2026-06-17 7.5 HIGH 8.1 HIGH
The scheduler service running on a specific TCP port enables the user to start and stop jobs. There is no sanitation of the supplied JOB ID provided to the function. An attacker may send a malicious payload that can enable the user to execute another SQL expression by sending a specific string.
CVE-2021-38393 1 Deltaww 1 Diaenergie 2026-06-17 10.0 HIGH 9.8 CRITICAL
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.
CVE-2021-38391 1 Deltaww 1 Diaenergie 2026-06-17 10.0 HIGH 9.8 CRITICAL
A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.
CVE-2021-38390 1 Deltaww 1 Diaenergie 2026-06-17 10.0 HIGH 9.8 CRITICAL
A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.
CVE-2021-38324 1 Smartypantsplugins 1 Sp Rental Manager 2026-06-17 5.0 MEDIUM 8.2 HIGH
The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3.
CVE-2021-38303 1 Surelinesystems 1 Sureedge Migrator 2026-06-17 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in Sureline SUREedge Migrator 7.0.7.29360.
CVE-2021-38302 1 Newsletter Project 1 Newsletter 2026-06-17 7.5 HIGH 9.8 CRITICAL
The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.
CVE-2021-38239 1 Dataease 1 Dataease 2026-06-17 N/A 7.5 HIGH
SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10.
CVE-2021-38217 1 Sem-cms 1 Semcms 2026-06-17 N/A 9.8 CRITICAL
SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.
CVE-2021-38176 1 Sap 4 Landscape Transformation, Landscape Transformation Replication Server, S\/4hana and 1 more 2026-06-17 9.0 HIGH 8.8 HIGH
Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system.