CWE-89
20,860 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,860)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Inventorymanagementsystem Project 1Inventorymanagementsystem Jun 17, 2026 Aug 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter user. |
1Inventorymanagementsystem Project 1Inventorymanagementsystem Jun 17, 2026 Aug 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt. |
1Inventorymanagementsystem Project 1Inventorymanagementsystem Jun 17, 2026 Aug 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter productcode. |
1Inventorymanagementsystem Project 1Inventorymanagementsystem Jun 17, 2026 Aug 18, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A SQL injection vulnerability in ConnectionFactoryDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter username. |
maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html. |
Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java. |
1Guest Management System Project 1Guest Management System Jun 17, 2026 Aug 16, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability, which was classified as critical, has been found in SourceCodester Guest Management System. This issue affects some unknown processing of the file /guestmanagement/front.php. The manipulation of the argu...Show more |
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, wh...Show more |
1Oretnom23 1Clinic's Patient Management System Jun 17, 2026 Aug 16, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Clinic's Patient Management System v1.0 is vulnerable to SQL Injection via /pms/update_medicine.php?id=. |
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists. |
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter. |
1Guest Management System Project 1Guest Management System Jun 17, 2026 Aug 15, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability classified as critical was found in SourceCodester Guest Management System. This vulnerability affects unknown code of the file index.php. The manipulation of the argument username/pass leads to sql injec...Show more |
1Linuxfoundation 1Loopback Connector Postgresql Jun 17, 2026 Aug 12, 2022 N/A· v4 10.0 CRITICAL· v3 N/A· v2 Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended filter property `contains` is permitted to be interpreted by the Postgres connector, it is possible to...Show more |
1Update By Case Project 1Update By Case Jun 17, 2026 Aug 12, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This Rails gem adds two methods to the ActiveRecord::Base class that allow you to update many records on a single database hit, using a case sql statement for it. Before version 0.1.3 `update_by_case` gem used custom sql...Show more |
1Phpgurukul 1Zoo Management System Jun 17, 2026 Aug 12, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in SourceCodester Zoo Management System and classified as critical. This issue affects some unknown processing of the file /pages/animals.php. The manipulation of the argument class_id leads to...Show more |
1Gas Agency Management System Project 1Gas Agency Management System Jun 17, 2026 Aug 12, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability has been found in SourceCodester Gas Agency Management System and classified as critical. This vulnerability affects unknown code of the file gasmark/login.php. The manipulation of the argument username l...Show more |
1Automated Beer Parlour Billing System Project 1Automated Beer Parlour Billing System Jun 17, 2026 Aug 12, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability, which was classified as critical, was found in SourceCodester Automated Beer Parlour Billing System. This affects an unknown part of the component Login. The manipulation of the argument username leads t...Show more |
1Student Information System Project 1Student Information System Jun 17, 2026 Aug 12, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability classified as critical was found in SourceCodester Student Information System. Affected by this vulnerability is an unknown functionality of the file /admin/students/view_student.php. The manipulation of...Show more |
In MMSProvider, there is a possible read of protected data due to improper input validationSQL injection. This could lead to local information disclosure of sms/mms data with User execution privileges needed. User intera...Show more |
1Library Management System Project 1Library Management System Jun 17, 2026 Aug 11, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in SourceCodester Library Management System. It has been declared as critical. This vulnerability affects unknown code of the file librarian/student.php. The manipulation of the argument title l...Show more |