CWE-89
20,927 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,927)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Arubanetworks 1Edgeconnect Sd Wan Orchestrator Jun 17, 2026 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator...Show more |
1Arubanetworks 1Edgeconnect Sd Wan Orchestrator Jun 17, 2026 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator...Show more |
1Arubanetworks 1Edgeconnect Sd Wan Orchestrator Jun 17, 2026 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator...Show more |
1Arubanetworks 1Edgeconnect Sd Wan Orchestrator Jun 17, 2026 Aug 22, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator...Show more |
1Arubanetworks 1Edgeconnect Sd Wan Orchestrator Jun 17, 2026 Aug 22, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator...Show more |
1Arubanetworks 1Edgeconnect Sd Wan Orchestrator Jun 17, 2026 Aug 22, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator...Show more |
1Arubanetworks 1Edgeconnect Sd Wan Orchestrator Jun 17, 2026 Aug 22, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator...Show more |
1Arubanetworks 1Edgeconnect Sd Wan Orchestrator Jun 17, 2026 Aug 22, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator...Show more |
1Arubanetworks 1Edgeconnect Sd Wan Orchestrator Jun 17, 2026 Aug 22, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator...Show more |
1Arubanetworks 1Edgeconnect Sd Wan Orchestrator Jun 17, 2026 Aug 22, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator...Show more |
An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to obtain sensitive database content via SQL Injection. |
SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component. |
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against th...Show more |
1Inventory Management System Project 1Inventory Management System Jun 17, 2026 Aug 21, 2023 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /index.php?page=member. The manipulation o...Show more |
A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. This vulnerability affects unknown code of the file admin/article-chat.php. The manipulation of the argument id leads to sql injectio...Show more |
A vulnerability, which was classified as critical, was found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file template/default/category.php. The manipulation of the argument id leads to sql injection...Show more |
A vulnerability, which was classified as critical, has been found in Mini-Tmall up to 20230811. Affected by this issue is some unknown functionality of the file product/1/1?test=1&test2=2&. The manipulation of the argume...Show more |
1Free Hospital Management System For Small Practices Project 1Free Hospital Management System For Small Practices Jun 17, 2026 Aug 21, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability classified as critical was found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this vulnerability is an unknown functionality of the file vm\patient\edit-user.php....Show more |
1Free Hospital Management System For Small Practices Project 1Free Hospital Management System For Small Practices Jun 17, 2026 Aug 21, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability classified as critical has been found in SourceCodester Free Hospital Management System for Small Practices 1.0/5.0.12. Affected is an unknown function of the file vm\doctor\edit-doc.php. The manipulation...Show more |
1Nvki 1Intelligent Broadband Subscriber Gateway Jul 9, 2026 Aug 21, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php. |