Vulnerabilities (CVE)

Filtered by CWE-89
Total 18406 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-52664 1 Revive-adserver 1 Revive Adserver 2025-12-01 N/A 8.8 HIGH
SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users
CVE-2025-13581 1 Facebook-julykringcadayona 1 Student Information System 2025-12-01 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /schedule_edit1.php. Such manipulation of the argument schedule_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
CVE-2025-13770 1 Uniong 1 Webitr 2025-12-01 N/A 6.5 MEDIUM
WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
CVE-2025-61167 1 Sigb 1 Pmb 2025-12-01 N/A 6.5 MEDIUM
SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php component via the id and datas parameters.
CVE-2025-13769 1 Uniong 1 Webitr 2025-12-01 N/A 6.5 MEDIUM
WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
CVE-2025-34245 1 Advantech 1 Webaccess\/vpn 2025-11-28 N/A 6.5 MEDIUM
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
CVE-2025-34247 1 Advantech 1 Webaccess\/vpn 2025-11-28 N/A 6.5 MEDIUM
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
CVE-2025-34246 1 Advantech 1 Webaccess\/vpn 2025-11-28 N/A 6.5 MEDIUM
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
CVE-2025-34244 1 Advantech 1 Webaccess\/vpn 2025-11-28 N/A 6.5 MEDIUM
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDeviceFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
CVE-2025-34243 1 Advantech 1 Webaccess\/vpn 2025-11-28 N/A 6.5 MEDIUM
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
CVE-2025-34242 1 Advantech 1 Webaccess\/vpn 2025-11-28 N/A 6.5 MEDIUM
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
CVE-2025-34241 1 Advantech 1 Webaccess\/vpn 2025-11-28 N/A 6.5 MEDIUM
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
CVE-2025-34240 1 Advantech 1 Webaccess\/vpn 2025-11-28 N/A 6.5 MEDIUM
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
CVE-2025-11972 2025-11-28 N/A 4.9 MEDIUM
The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection via the 'post_types' parameter in all versions up to, and including, 3.40.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2025-13578 1 Code-projects 1 Library System 2025-11-26 7.5 HIGH 7.3 HIGH
A vulnerability has been found in code-projects Library System 1.0. This affects an unknown function of the file /index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-13561 1 Torrahclef 1 Company Website Cms 2025-11-26 7.5 HIGH 7.3 HIGH
A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects unknown code of the file /admin/index.php. This manipulation of the argument Username causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
CVE-2025-13560 1 Torrahclef 1 Company Website Cms 2025-11-26 7.5 HIGH 7.3 HIGH
A vulnerability was found in SourceCodester Company Website CMS 1.0. This affects an unknown part of the file /admin/reset-password.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
CVE-2025-13557 1 Campcodes 1 Online Polling System 2025-11-26 7.5 HIGH 7.3 HIGH
A vulnerability has been found in Campcodes Online Polling System 1.0. Affected by this issue is some unknown functionality of the file /registeracc.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2023-49440 2025-11-26 N/A 8.8 HIGH
AhnLab EPP 1.0.15 is vulnerable to SQL Injection via the "preview parameter."
CVE-2025-28982 1 Thimpress 1 Wp Pipes 2025-11-26 N/A 9.3 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes allows SQL Injection. This issue affects WP Pipes: from n/a through 1.4.3.