CWE-89
20,857 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,857)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Online Admission System Project 1Online Admission System Jun 17, 2026 Aug 4, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in SourceCodester Online Admission System and classified as critical. This issue affects some unknown processing of the component GET Parameter Handler. The manipulation of the argument eid lead...Show more |
1Online Admission System Project 1Online Admission System Jun 17, 2026 Aug 4, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability has been found in SourceCodester Online Admission System and classified as critical. This vulnerability affects unknown code of the component POST Parameter Handler. The manipulation of the argument shift...Show more |
3Debian FedoraprojectPostgresql3Debian Linux FedoraPostgresql Jdbc DriverJun 17, 2026 Aug 3, 2022 N/A· v4 8.0 HIGH· v3 N/A· v2 PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method...Show more |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication is required to exploit this vulnerability. The specific flaw exists wit...Show more |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing...Show more |
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of poll...Show more |
This vulnerability allows remote attackers to bypass authentication on affected installations of Sante PACS Server 3.0.4. Authentication is not required to exploit this vulnerability. The specific flaw exists within the...Show more |
An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query. |
JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user. |
1Quest 1Kace Systems Management Appliance Jun 17, 2026 Aug 2, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution via download_agent_installer.php. |
1Web Based Quiz System Project 1Web Based Quiz System Jun 17, 2026 Aug 2, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the qid parameter at update.php. |
1Online Tours And Travels Management System Project 1Online Tours And Travels Management System Jun 17, 2026 Aug 2, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the pname parameter at /admin/operations/packages.php. |
Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_groups.php. |
Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_topusers.php. |
1Phptpoint 1Pharmacy Management System Jun 17, 2026 Aug 2, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoiceprint.php. |
1Phptpoint 1Pharmacy Management System Jun 17, 2026 Aug 2, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getOrderReport.php. |
1Phptpoint 1Pharmacy Management System Jun 17, 2026 Aug 2, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php. |
1Phptpoint 1Pharmacy Management System Jun 17, 2026 Aug 2, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php. |
1Pharmacy Management System Project 1Pharmacy Management System Jun 17, 2026 Aug 2, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editproduct.php. |
1Pharmacy Management System Project 1Pharmacy Management System Jun 17, 2026 Aug 2, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or password parameter at login.php. |