Vulnerabilities (CVE)

Filtered by CWE-89
Total 19951 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-44291 1 Webtareas Project 1 Webtareas 2026-07-09 N/A 9.8 CRITICAL
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
CVE-2022-44290 1 Webtareas Project 1 Webtareas 2026-07-09 N/A 9.8 CRITICAL
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
CVE-2022-42122 1 Liferay 2 Dxp, Liferay Portal 2026-07-09 N/A 9.8 CRITICAL
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.
CVE-2022-42121 1 Liferay 3 Digital Experience Platform, Dxp, Liferay Portal 2026-07-09 N/A 8.8 HIGH
A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field.
CVE-2022-42120 1 Liferay 2 Dxp, Liferay Portal 2026-07-09 N/A 9.8 CRITICAL
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
CVE-2022-40839 1 Ndk-design 1 Ndkadvancedcustomizationfields 2026-07-09 N/A 7.5 HIGH
A SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers to exfiltrate database data.
CVE-2022-40030 1 Simple Task Managing System Project 1 Simple Task Managing System 2026-07-09 N/A 9.8 CRITICAL
SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.
CVE-2022-38619 1 Bpcbt 1 Smartvista Front-end 2026-07-09 N/A 9.8 CRITICAL
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.
CVE-2022-38618 1 Bpcbt 1 Smartvista 2026-07-09 N/A 8.8 HIGH
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/country_group.jsf.
CVE-2022-38617 1 Bpcbt 1 Smartvista 2026-07-09 N/A 8.8 HIGH
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/voiceaudit.jsf.
CVE-2022-38616 1 Bpcbt 1 Smartvista Front-end 2026-07-09 N/A 8.8 HIGH
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.jsf.
CVE-2022-38615 1 Bpcbt 1 Smartvista Front-end 2026-07-09 N/A 8.8 HIGH
SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf.
CVE-2022-37773 1 Maarch 1 Maarch Rm 2026-07-09 N/A 6.5 MEDIUM
An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allows the complete disclosure of all databases.
CVE-2022-36635 1 Zkteco 1 Zkbiosecurity V5000 2026-07-09 N/A 8.8 HIGH
ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.
CVE-2022-35156 1 Phpgurukul 1 Bus Pass Management System 2026-07-09 N/A 9.8 CRITICAL
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..
CVE-2022-31384 1 Phpgurukul 1 Directory Management System 2026-07-09 7.5 HIGH 9.8 CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
CVE-2022-31383 1 Phpgurukul 1 Directory Management System 2026-07-09 7.5 HIGH 9.8 CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
CVE-2022-31382 1 Phpgurukul 1 Directory Management System 2026-07-09 7.5 HIGH 9.8 CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
CVE-2022-30490 1 Badminton Center Management System Project 1 Badminton Center Management System 2026-07-09 7.5 HIGH 9.8 CRITICAL
Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.
CVE-2022-29709 1 Communilink 1 Clink Office 2026-07-09 N/A 7.5 HIGH
CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.