Vulnerabilities (CVE)

Filtered by CWE-89
Total 16225 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-30862 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2025-04-04 N/A 8.8 HIGH
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/index.php.
CVE-2024-30863 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2025-04-04 N/A 6.3 MEDIUM
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/history.php.
CVE-2024-30867 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2025-04-04 N/A 9.8 CRITICAL
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_virtual_site_info.php.
CVE-2025-1850 1 Codezips 1 College Management System 2025-04-04 7.5 HIGH 7.3 HIGH
A vulnerability, which was classified as critical, has been found in Codezips College Management System 1.0. Affected by this issue is some unknown functionality of the file /university.php. The manipulation of the argument book_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2021-43084 1 Iteachyou 1 Dreamer Cms 2025-04-04 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter.
CVE-2024-52725 1 Sem-cms 1 Semcms 2025-04-04 N/A 4.9 MEDIUM
SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component.
CVE-2024-53502 1 Sem-cms 1 Semcms 2025-04-04 N/A 3.8 LOW
Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.
CVE-2024-30870 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2025-04-04 N/A 8.8 HIGH
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/address_interpret.php.
CVE-2024-30871 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2025-04-04 N/A 8.8 HIGH
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/applyhardware.php.
CVE-2024-30872 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2025-04-04 N/A 5.1 MEDIUM
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php.
CVE-2024-30864 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2025-04-04 N/A 6.3 MEDIUM
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupTimePolicy.php.
CVE-2024-30865 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2025-04-04 N/A 9.8 CRITICAL
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php.
CVE-2024-30866 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2025-04-04 N/A 5.4 MEDIUM
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/menu.php.
CVE-2024-48283 1 Phpgurukul 1 User Registration \& Login And User Management System 2025-04-04 N/A 9.8 CRITICAL
Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter.
CVE-2024-46531 1 Phpgurukul 1 Vehicle Record System 2025-04-04 N/A 6.3 MEDIUM
phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchinputdata parameter at /index.php.
CVE-2024-34955 1 Code-projects 1 Budget Management 2025-04-04 N/A 9.8 CRITICAL
Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.
CVE-2022-47745 1 Easycorp 1 Zentao 2025-04-04 N/A 8.8 HIGH
ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.
CVE-2022-47740 1 Seltmann-webdesign 1 Content Management System 2025-04-04 N/A 9.8 CRITICAL
Seltmann GmbH Content Management System 6 is vulnerable to SQL Injection via /index.php.
CVE-2024-30938 1 Sem-cms 1 Semcms 2025-04-04 N/A 9.8 CRITICAL
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component.
CVE-2024-31077 1 Incsub 1 Forminator 2025-04-04 N/A 7.2 HIGH
Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain and alter any information in the database and cause a denial-of-service (DoS) condition.