Vulnerabilities (CVE)

Filtered by CWE-89
Total 20786 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-36299 1 Dell 1 Emc Idrac9 Firmware 2026-06-17 5.5 MEDIUM 7.1 HIGH
Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to the affected application.
CVE-2021-36184 1 Fortinet 1 Fortiwlm 2026-06-17 4.0 MEDIUM 8.8 HIGH
A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclosure device, users and database information via crafted HTTP requests.
CVE-2021-35487 1 Nokia 1 Broadcast Message Center 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifier HTTP POST parameter. This allows an attacker to obtain the database user, database name, and database version information, and potentially database data.
CVE-2021-35484 1 Nokia 1 Impact 2026-06-17 N/A 8.2 HIGH
Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version information.
CVE-2021-35458 1 Online Pet Shop We App Project 1 Online Pet Shop We App 2026-06-17 7.5 HIGH 9.8 CRITICAL
Online Pet Shop We App 1.0 is vulnerable to Union SQL Injection in products.php (aka p=products) via the c or s parameter.
CVE-2021-35456 1 Online Pet Shop Web Application Project 1 Online Pet Shop Web Application 2026-06-17 7.5 HIGH 9.8 CRITICAL
Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload
CVE-2021-35437 1 Lmxcms 1 Lmxcms 2026-06-17 N/A 9.8 CRITICAL
SQL injection vulnerability in LMXCMS v.1.4 allows attacker to execute arbitrary code via the TagsAction.class.
CVE-2021-35414 1 Chamilo 1 Chamilo Lms 2026-06-17 7.5 HIGH 9.8 CRITICAL
Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.
CVE-2021-35387 1 Phpgurukul 1 Hospital Management System 2026-06-17 N/A 8.8 HIGH
Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.
CVE-2021-35284 1 Cms-php Project 1 Cms-php 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in function get_user in login_manager.php in rizalafani cms-php v1.
CVE-2021-35283 1 Atoms183 Cms Project 1 Atoms183 Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via the Name, Fname, and ID parameters to search.php.
CVE-2021-35234 1 Solarwinds 1 Orion Platform 2026-06-17 6.5 MEDIUM 8.0 HIGH
Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information.
CVE-2021-35212 1 Solarwinds 1 Orion Platform 2026-06-17 9.0 HIGH 8.9 HIGH
An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection which could lead to full read/write over the Orion database content including the Orion certificate for any authenticated user.
CVE-2021-35049 1 Fidelissecurity 2 Deception, Network 2026-06-17 6.5 MEDIUM 9.9 CRITICAL
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response in an authenticated session. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.
CVE-2021-35048 1 Fidelissecurity 2 Deception, Network 2026-06-17 7.5 HIGH 9.8 CRITICAL
Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis software. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.
CVE-2021-35042 2 Djangoproject, Fedoraproject 2 Django, Fedora 2026-06-17 7.5 HIGH 9.8 CRITICAL
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.
CVE-2021-34684 1 Hitachi 1 Vantara Pentaho 2026-06-17 7.5 HIGH 9.8 CRITICAL
Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and thus retrieve data from the related databases, as demonstrated by an api/repos/dashboards/editor URI.
CVE-2021-34609 1 Arubanetworks 1 Clearpass Policy Manager 2026-06-17 6.5 MEDIUM 8.8 HIGH
A remote SQL injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.
CVE-2021-34249 1 Online Book Store Project 1 Online Book Store 2026-06-17 N/A 7.5 HIGH
SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL.
CVE-2021-34235 1 Tsg-solutions 1 Tokheim Profleet Dialog 2026-06-17 10.0 HIGH 9.8 CRITICAL
Tokheim Profleet DiaLOG 11.005.02 is affected by SQL Injection. The component is the Field__UserLogin parameter on the logon page.