Vulnerabilities (CVE)

Filtered by CWE-89
Total 20728 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-33677 1 Oretnom23 1 Lost And Found Information System 2026-07-09 N/A 7.5 HIGH
Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*".
CVE-2023-30243 1 Netentsec 1 Application Security Gateway 2026-07-09 N/A 7.5 HIGH
Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access to sensitive information.
CVE-2023-30242 1 Netentsec 1 Application Security Gateway 2026-07-09 N/A 9.8 CRITICAL
NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php.
CVE-2023-29863 1 Medisys 1 Weblab 2026-07-09 N/A 9.8 CRITICAL
Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files.
CVE-2023-27779 1 Amsystem 1 Am Presencia 2026-07-09 N/A 9.8 CRITICAL
AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.
CVE-2023-27667 1 Auto Dealer Management System Project 1 Auto Dealer Management System 2026-07-09 N/A 9.8 CRITICAL
Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability.
CVE-2023-27167 1 Supremainc 1 Biostar 2 2026-07-09 N/A 6.5 MEDIUM
Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1.
CVE-2022-47770 1 Serinf 1 Fast Checkin 2026-07-09 N/A 9.8 CRITICAL
Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticated SQL Injection.
CVE-2022-46965 1 202-ecommerce 1 Administrative Mandate 2026-07-09 N/A 8.1 HIGH
PrestaShop module, totadministrativemandate before v1.7.1 was discovered to contain a SQL injection vulnerability.
CVE-2022-46501 1 Accruent 1 Maintenance Connection 2026-07-09 N/A 9.8 CRITICAL
Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function.
CVE-2022-45589 1 Talend 1 Esb Runtime 2026-07-09 N/A 7.2 HIGH
All versions before 8.0.1-R2022-10-RT and 7.3.1-R2022-09-RT of the Talend ESB Runtime are potentially vulnerable to SQL Injection attacks in the provisioning service only. Users of the provisioning service should upgrade to either 8.0.1-R2022-10-RT or 7.3.1-R2022-09-RT or a later release and use it in place of the previous version.
CVE-2022-45210 1 Jeecg 1 Jeecg Boot 2026-07-09 N/A 4.3 MEDIUM
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.
CVE-2022-45208 1 Jeecg 1 Jeecg Boot 2026-07-09 N/A 4.3 MEDIUM
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.
CVE-2022-45207 1 Jeecg 1 Jeecg Boot 2026-07-09 N/A 9.8 CRITICAL
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
CVE-2022-45206 1 Jeecg 1 Jeecg Boot 2026-07-09 N/A 9.8 CRITICAL
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
CVE-2022-45205 1 Jeecg 1 Jeecg Boot 2026-07-09 N/A 5.3 MEDIUM
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
CVE-2022-44945 1 Rukovoditel 1 Rukovoditel 2026-07-09 N/A 9.8 CRITICAL
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.
CVE-2022-44291 1 Webtareas Project 1 Webtareas 2026-07-09 N/A 9.8 CRITICAL
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
CVE-2022-44290 1 Webtareas Project 1 Webtareas 2026-07-09 N/A 9.8 CRITICAL
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
CVE-2022-42122 1 Liferay 2 Dxp, Liferay Portal 2026-07-09 N/A 9.8 CRITICAL
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.