CWE-89
20,864 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,864)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Online Leave Management System Project 1Online Leave Management System Jun 17, 2026 Sep 12, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /maintenance/manage_department.php. |
1Garage Management System Project 1Garage Management System Jun 17, 2026 Sep 12, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editclient.php. |
1Garage Management System Project 1Garage Management System Jun 17, 2026 Sep 12, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editcategory.php. |
1Church Management System Project 1Church Management System Jun 17, 2026 Sep 12, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_event.php. |
1Inventorymanagementsystem Project 1Inventorymanagementsystem Jun 17, 2026 Sep 12, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A SQL injection vulnerability in ConnectionFactory.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "username", "password", etc. |
1Inventorymanagementsystem Project 1Inventorymanagementsystem Jun 17, 2026 Sep 12, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "searchTxt". |
1Inventorymanagementsystem Project 1Inventorymanagementsystem Jun 17, 2026 Sep 12, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "users", "pass", etc. |
1Inventorymanagementsystem Project 1Inventorymanagementsystem Jun 17, 2026 Sep 12, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "productcode". |
1Inventorymanagementsystem Project 1Inventorymanagementsystem Jun 17, 2026 Sep 12, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "searchTxt". |
1Library Management System Project 1Library Management System Jun 17, 2026 Sep 12, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection. |
1Aivhub 1Active Intelligence Visualization Jun 17, 2026 Sep 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in Active Intelligent Visualization 5. The Vdc header is used in a SQL query without being sanitized. This causes SQL injection. |
SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/role/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/menu/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/department/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/video/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list. |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list. |