CWE-89
20,873 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,873)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SQL Injection in
AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network |
SQL Injection in
Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network |
1College Management System Project 1College Management System Jun 17, 2026 Nov 17, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2
College Management System v1.0 - SQL Injection (SQLi).
By inserting SQL commands to the username and password fields in the login.php page
|
1College Management System Project 1College Management System Jun 17, 2026 Nov 17, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious...Show more |
webvendome - webvendome SQL Injection.
SQL Injection in the Parameter " DocNumber"
Request :
Get Request :
/webvendome/showfiles.aspx?jobnumber=nullDoc Number=HERE.
|
1Online Leave Management System Project 1Online Leave Management System Jun 17, 2026 Nov 17, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/?page=user/manage_user&id=. |
1Online Diagnostic Lab Management System Project 1Online Diagnostic Lab Management System Jun 17, 2026 Nov 17, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clients/view_client.php. |
1Online Diagnostic Lab Management System Project 1Online Diagnostic Lab Management System Jun 17, 2026 Nov 17, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/view_test.php. |
1Automotive Shop Management System Project 1Automotive Shop Management System Jun 17, 2026 Nov 17, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=user/manage_user&id=. |
1Automotive Shop Management System Project 1Automotive Shop Management System Jun 17, 2026 Nov 17, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_transaction. |
1Student Attendance Management System Project 1Student Attendance Management System Jun 17, 2026 Nov 17, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 A vulnerability was found in Student Attendance Management System and classified as critical. This issue affects some unknown processing of the file /Admin/createClass.php. The manipulation of the argument Id leads to sq...Show more |
1Hostel Searching Project 1Hostel Searching Project Jun 17, 2026 Nov 17, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability has been found in Hostel Searching Project and classified as critical. This vulnerability affects unknown code of the file view-property.php. The manipulation of the argument property_id leads to sql inje...Show more |
1Dreamer Cms Project 1Dreamer Cms Jun 17, 2026 Nov 17, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Dreamer CMS 4.0.01 is vulnerable to SQL Injection. |
1Simple Image Gallery Web App Project 1Simple Image Gallery Web App Jun 17, 2026 Nov 17, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A SQL injection vulnerability exits on the Simple Image Gallery System 1.0 application through "id" parameter on the album page. |
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations. |
1Online Diagnostic Lab Management System Project 1Online Diagnostic Lab Management System Jun 17, 2026 Nov 16, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php. |
1Oretnom23 1Human Resource Management System Jun 17, 2026 Nov 16, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /hrm/controller/login.php. |
SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php. |
1Sports Club Management System Project 1Sports Club Management System Jun 17, 2026 Nov 16, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability, which was classified as critical, was found in Sports Club Management System 119. This affects an unknown part of the file admin/make_payments.php. The manipulation of the argument m_id/plan leads to sql...Show more |
1Hospital Management Center Project 1Hospital Management Center Jun 17, 2026 Nov 16, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability classified as critical has been found in Hospital Management Center. Affected is an unknown function of the file patient-info.php. The manipulation of the argument pt_id leads to sql injection. It is poss...Show more |