Vulnerabilities (CVE)

Filtered by CWE-89
Total 19951 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-37858 1 Oretnom23 1 Lost And Found Information System 2026-07-09 N/A 9.8 CRITICAL
SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php.
CVE-2024-37857 1 Oretnom23 1 Lost And Found Information System 2026-07-09 N/A 8.8 HIGH
SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via id parameter to php-lfis/admin/categories/view_category.php.
CVE-2024-35563 2026-07-09 N/A 9.8 CRITICAL
CDG-Server-V5.6.2.126.139 and earlier was discovered to contain a SQL injection vulnerability via the permissionId parameter in CDGTempPermissions.
CVE-2024-30801 2026-07-09 N/A 5.5 MEDIUM
SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp component.
CVE-2024-28714 1 Crmeb 1 Crmeb Java 2026-07-09 N/A 8.1 HIGH
SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.
CVE-2024-22983 1 Projectworlds 1 Visitor Management System 2026-07-09 N/A 8.1 HIGH
SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate privileges via the name parameter in the myform.php endpoint.
CVE-2023-51927 1 Yonyou 1 Yonbip 2026-07-09 N/A 9.8 CRITICAL
YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScriptController.runScript() method.
CVE-2023-51810 1 Stackideas 1 Easydiscuss 2026-07-09 N/A 7.5 HIGH
SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted request to the search parameter in the Users module.
CVE-2023-45379 1 Posthemes 1 Posrotatorimg 2026-07-09 N/A 9.8 CRITICAL
In the module "Rotator Img" (posrotatorimg) in versions at least up to 1.1 from PosThemes for PrestaShop, a guest can perform SQL injection.
CVE-2023-40934 1 Nagios 1 Nagios Xi 2026-07-09 N/A 7.2 HIGH
A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.
CVE-2023-40933 1 Nagios 1 Nagios Xi 2026-07-09 N/A 8.8 HIGH
A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.
CVE-2023-40931 1 Nagios 1 Nagios Xi 2026-07-09 N/A 6.5 MEDIUM
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php
CVE-2023-39807 1 Nvki 1 Intelligent Broadband Subscriber Gateway 2026-07-09 N/A 9.8 CRITICAL
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php.
CVE-2023-39806 1 Idreamsoft 1 Icms 2026-07-09 N/A 9.8 CRITICAL
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
CVE-2023-39805 1 Idreamsoft 1 Icms 2026-07-09 N/A 9.8 CRITICAL
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
CVE-2023-38954 1 Zkteco 1 Bioaccess Ivs 2026-07-09 N/A 9.8 CRITICAL
ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.
CVE-2023-38899 1 Berkaygediz 1 O Blog 2026-07-09 N/A 7.8 HIGH
SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component.
CVE-2023-38838 1 Kiduswb 1 Minimati 2026-07-09 N/A 7.5 HIGH
SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via the edit.php component.
CVE-2023-37847 1 Xxyopen 1 Novel-plus 2026-07-09 N/A 9.8 CRITICAL
novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.
CVE-2023-37687 1 Phpgurukul 1 Online Nurse Hiring System 2026-07-09 N/A 7.2 HIGH
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal.