Vulnerabilities (CVE)

Filtered by CWE-89
Total 19946 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-30242 1 Netentsec 1 Application Security Gateway 2026-07-09 N/A 9.8 CRITICAL
NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php.
CVE-2023-29863 1 Medisys 1 Weblab 2026-07-09 N/A 9.8 CRITICAL
Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files.
CVE-2023-27779 1 Amsystem 1 Am Presencia 2026-07-09 N/A 9.8 CRITICAL
AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.
CVE-2023-27667 1 Auto Dealer Management System Project 1 Auto Dealer Management System 2026-07-09 N/A 9.8 CRITICAL
Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability.
CVE-2023-27167 1 Supremainc 1 Biostar 2 2026-07-09 N/A 6.5 MEDIUM
Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1.
CVE-2022-47770 1 Serinf 1 Fast Checkin 2026-07-09 N/A 9.8 CRITICAL
Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticated SQL Injection.
CVE-2022-46965 1 202-ecommerce 1 Administrative Mandate 2026-07-09 N/A 8.1 HIGH
PrestaShop module, totadministrativemandate before v1.7.1 was discovered to contain a SQL injection vulnerability.
CVE-2022-46501 1 Accruent 1 Maintenance Connection 2026-07-09 N/A 9.8 CRITICAL
Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function.
CVE-2022-45589 1 Talend 1 Esb Runtime 2026-07-09 N/A 7.2 HIGH
All versions before 8.0.1-R2022-10-RT and 7.3.1-R2022-09-RT of the Talend ESB Runtime are potentially vulnerable to SQL Injection attacks in the provisioning service only. Users of the provisioning service should upgrade to either 8.0.1-R2022-10-RT or 7.3.1-R2022-09-RT or a later release and use it in place of the previous version.
CVE-2022-45210 1 Jeecg 1 Jeecg Boot 2026-07-09 N/A 4.3 MEDIUM
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.
CVE-2022-45208 1 Jeecg 1 Jeecg Boot 2026-07-09 N/A 4.3 MEDIUM
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.
CVE-2022-45207 1 Jeecg 1 Jeecg Boot 2026-07-09 N/A 9.8 CRITICAL
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
CVE-2022-45206 1 Jeecg 1 Jeecg Boot 2026-07-09 N/A 9.8 CRITICAL
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
CVE-2022-45205 1 Jeecg 1 Jeecg Boot 2026-07-09 N/A 5.3 MEDIUM
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
CVE-2022-44945 1 Rukovoditel 1 Rukovoditel 2026-07-09 N/A 9.8 CRITICAL
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.
CVE-2022-44291 1 Webtareas Project 1 Webtareas 2026-07-09 N/A 9.8 CRITICAL
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
CVE-2022-44290 1 Webtareas Project 1 Webtareas 2026-07-09 N/A 9.8 CRITICAL
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
CVE-2022-42122 1 Liferay 2 Dxp, Liferay Portal 2026-07-09 N/A 9.8 CRITICAL
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.
CVE-2022-42121 1 Liferay 3 Digital Experience Platform, Dxp, Liferay Portal 2026-07-09 N/A 8.8 HIGH
A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field.
CVE-2022-42120 1 Liferay 2 Dxp, Liferay Portal 2026-07-09 N/A 9.8 CRITICAL
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.