CWE-89
20,857 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,857)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Simple E Learning System Project 1Simple E Learning System Jun 17, 2026 Aug 8, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file search.php. The manipulation of the argument...Show more |
1Simple E Learning System Project 1Simple E Learning System Jun 17, 2026 Aug 8, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in SourceCodester Simple E-Learning System. It has been classified as critical. Affected is an unknown function of the file comment_frame.php. The manipulation of the argument post_id leads to s...Show more |
1Electronic Medical Records System Project 1Electronic Medical Records System Jun 17, 2026 Aug 6, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability has been found in SourceCodester Electronic Medical Records System and classified as critical. This vulnerability affects unknown code of the file register.php of the component UPDATE Statement Handler. T...Show more |
1Expense Management System Project 1Expense Management System Jun 17, 2026 Aug 6, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in SourceCodester Expense Management System. It has been rated as critical. This issue affects the function fetch_report_credit of the file report.php of the component POST Parameter Handler. Th...Show more |
1Gym Management System Project 1Gym Management System Jun 17, 2026 Aug 6, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability, which was classified as critical, was found in SourceCodester Gym Management System. Affected is an unknown function. The manipulation of the argument user_pass leads to sql injection. It is possible to...Show more |
1Church Management System Project 1Church Management System Jun 17, 2026 Aug 5, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability classified as critical has been found in SourceCodester Church Management System 1.0. Affected is an unknown function of the file /login.php. The manipulation of the argument username with the input ' OR...Show more |
1Janobe 1Interview Management System Jun 17, 2026 Aug 5, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in SourceCodester Interview Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /viewReport.php. The manipulation of the argument id with...Show more |
1Apartment Visitors Management System Project 1Apartment Visitors Management System Jun 17, 2026 Aug 5, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been classified as critical. This affects an unknown part of the file index.php. The manipulation of the argument username with...Show more |
1Electronic Medical Records System Project 1Electronic Medical Records System Jun 17, 2026 Aug 5, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in SourceCodester Electronic Medical Records System and classified as critical. Affected by this issue is some unknown functionality of the component POST Request Handler. The manipulation of th...Show more |
SQL injection vulnerability via IAPService in Samsung Checkout prior to version 5.0.53.1 allows attackers to access IAP information. |
1Vmware 4Access Connector Identity ManagerIdentity Manager Connector+1 moreJun 17, 2026 Aug 5, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution. |
1Best Fee Management System Project 1Best Fee Management System Jun 17, 2026 Aug 5, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in SourceCodester Best Fee Management System. It has been rated as critical. Affected by this issue is the function login of the file admin_class.php. The manipulation of the argument username l...Show more |
1Rigatur 1Online Booking And Hotel Management System Jun 17, 2026 Aug 5, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in Rigatur Online Booking and Hotel Management System aff6409. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.php of the component...Show more |
1Garage Management System Project 1Garage Management System Jun 17, 2026 Aug 5, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in SourceCodester Garage Management System. It has been classified as critical. Affected is an unknown function of the file createUser.php. The manipulation of the argument userName/uemail leads...Show more |
1Garage Management System Project 1Garage Management System Jun 17, 2026 Aug 5, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in SourceCodester Garage Management System and classified as critical. This issue affects some unknown processing of the file removeUser.php. The manipulation of the argument id leads to sql inj...Show more |
A vulnerability was found in SourceCodester Loan Management System and classified as critical. This issue affects some unknown processing of the file delete_lplan.php. The manipulation of the argument lplan_id leads to s...Show more |
1Simple E Learning System Project 1Simple E Learning System Jun 17, 2026 Aug 5, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability classified as critical was found in SourceCodester Simple E-Learning System. Affected by this vulnerability is an unknown functionality of the file classroom.php. The manipulation of the argument post_id...Show more |
1Multi Language Hotel Management Software Project 1Multi Language Hotel Management Software Jun 17, 2026 Aug 4, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability classified as critical has been found in SourceCodester Multi Language Hotel Management Software. Affected is an unknown function. The manipulation of the argument email leads to sql injection. It is poss...Show more |
OMICARD EDM’s API function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to access, modify, delete database or disrupt service. |
1Multi Language Hotel Management Software Project 1Multi Language Hotel Management Software Jun 17, 2026 Aug 4, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in SourceCodester Multi Language Hotel Management Software. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument room_id leads to sql injec...Show more |