Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-36789 1 Dated News Project 1 Dated News 2026-06-17 7.5 HIGH 9.8 CRITICAL
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.
CVE-2021-36748 1 Prestahome 1 Blog 2026-06-17 5.0 MEDIUM 7.5 HIGH
A SQL Injection issue in the list controller of the Prestahome Blog (aka ph_simpleblog) module before 1.7.8 for Prestashop allows a remote attacker to extract data from the database via the sb_category parameter.
CVE-2021-36722 1 Emuse - Eservices \/ Envoice Project 1 Emuse - Eservices \/ Envoice 2026-06-17 10.0 HIGH 7.1 HIGH
Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot location , information an attacker can leverage to further compromise the host.
CVE-2021-36625 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 6.5 MEDIUM 8.8 HIGH
An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.
CVE-2021-36624 1 Phone Shop Sales Management System Project 1 Phone Shop Sales Management System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
CVE-2021-36621 1 Online Covid Vaccination Scheduler System Project 1 Online Covid Vaccination Scheduler System 2026-06-17 6.8 MEDIUM 8.1 HIGH
Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker can decrypt and obtain the plain-text password. Hence, the attacker could authenticate as Administrator.
CVE-2021-36520 1 Washington 1 I-tech Trainsmart 2026-06-17 N/A 7.5 HIGH
A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI.
CVE-2021-36503 1 Native-php-cms Project 1 Native-php-cms 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in native-php-cms 1.0 allows remote attackers to run arbitrary SQL commands via the cat parameter to /list.php file.
CVE-2021-36484 1 Jizhicms 1 Jizhicms 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page.
CVE-2021-36455 1 Naviwebs 1 Navigate Cms 2026-06-17 6.5 MEDIUM 8.8 HIGH
SQL Injection vulnerability in Naviwebs Navigate CMS 2.9 via the quicksearch parameter in \lib\packages\comments\comments.php.
CVE-2021-36438 2026-06-17 N/A 6.5 MEDIUM
SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobportal/index.php.
CVE-2021-36434 1 Jocms Project 1 Jocms 2026-06-17 N/A 9.1 CRITICAL
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check function in jocms/apps/mask/inc/getmask.php.
CVE-2021-36433 1 Jocms Project 1 Jocms 2026-06-17 N/A 9.1 CRITICAL
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_delete_mask function in jocms/apps/mask/mask.php.
CVE-2021-36432 1 Jocms Project 1 Jocms 2026-06-17 N/A 7.5 HIGH
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_set_mask() function in jocms/apps/mask/mask.php.
CVE-2021-36431 1 Jocms Project 1 Jocms 2026-06-17 N/A 9.1 CRITICAL
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check() function in jocms/apps/mask/inc/mask.php.
CVE-2021-36393 1 Moodle 1 Moodle 2026-06-17 N/A 9.8 CRITICAL
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
CVE-2021-36392 1 Moodle 1 Moodle 2026-06-17 N/A 9.8 CRITICAL
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.
CVE-2021-36385 1 Cerner 1 Mobile Care 2026-06-17 10.0 HIGH 9.8 CRITICAL
A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the default.aspx User ID field. Arbitrary system commands can be executed through the use of xp_cmdshell.
CVE-2021-36351 1 Care2x 1 Hospital Information Management System 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth, and (3) pyear parameters in GET requests sent to /modules/nursing/nursing-station.php.
CVE-2021-36348 1 Dell 2 Integrated Dell Remote Access Controller 9, Integrated Dell Remote Access Controller 9 Firmware 2026-06-17 5.5 MEDIUM 8.1 HIGH
iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to iDRAC.