CWE-89
20,860 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,860)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Owasp2Debian Linux Owasp Modsecurity Core Rule SetJun 17, 2026 Sep 2, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF prot...Show more |
1Garage Management System Project 1Garage Management System Jun 17, 2026 Sep 2, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php. |
1Oretnom23 1Clinic's Patient Management System Jun 17, 2026 Sep 2, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php. |
Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds function. |
2Online Food Ordering System Project Oretnom232Online Food Ordering System Online Food Ordering SystemJun 17, 2026 Sep 2, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=. |
1Redhat 1Advanced Cluster Management For Kubernetes Jun 17, 2026 Sep 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific str...Show more |
1Simple Task Scheduling System Project 1Simple Task Scheduling System Jun 17, 2026 Sep 1, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/view_category.php. |
1Simple Task Scheduling System Project 1Simple Task Scheduling System Jun 17, 2026 Sep 1, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /schedules/manage_schedule.php. |
1Simple Task Scheduling System Project 1Simple Task Scheduling System Jun 17, 2026 Sep 1, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /schedules/view_schedule.php. |
1Doctor's Appointment System Project 1Doctor's Appointment System Jun 17, 2026 Aug 31, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php. |
1Online Ordering System Project 1Online Ordering System Jun 17, 2026 Aug 31, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php. |
AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter. |
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW,...Show more |
1Library Management System Project 1Library Management System Jun 17, 2026 Aug 30, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /admin/delete.php. |
1Library Management System Project 1Library Management System Jun 17, 2026 Aug 30, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /admin/delstu.php. |
1Library Management System Project 1Library Management System Jun 17, 2026 Aug 30, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /admin/del.php. |
1Library Management System Project 1Library Management System Jun 17, 2026 Aug 30, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /librarian/dele.php. |
1Library Management System Project 1Library Management System Jun 17, 2026 Aug 30, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /librarian/delstu.php. |
1Library Management System Project 1Library Management System Jun 17, 2026 Aug 30, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /librarian/delete.php. |
OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-injection to access, modify, delete database, perform system operations and...Show more |