CWE-89
20,849 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,849)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may terminate abnormally when executing specially crafted SQL statements by an authenticated user. IB...Show more |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/view_prison.php:4 |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_inmate.php:3 |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_record.php:4 |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/manage_prison.php:4 |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_privilege.php:4 |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Jun 24, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/user/manage_user.php:4. |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/view_crime.php:4 |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/manage_cell.php:4 |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/view_visit.php:4 |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/manage_visit.php:4 |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/manage_crime.php:4 |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/view_inmate.php:3 |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/view_cell.php:4 |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/manage_action.php:4 |
1Prison Management System Project 1Prison Management System Jun 17, 2026 Jun 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/view_action.php:4 |
Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list. |
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job. |
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index. |
74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist. |