CWE-89
20,763 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,763)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary commands into the "typeid" variable of the "createfolderAjax" function in the "mode_worcAction.php" c...Show more |
1Dynamic Content Elements Project 1Dynamic Content Elements Jun 17, 2026 Apr 28, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allows SQL Injection via a backend user account. |
A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parameter in GetMesheryPatterns in models/mesh...Show more |
An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a crafted HTTP request to perform a blind time-based SQL Injection. The vulnerable parameter is param1. |
Magento-lts is a long-term support alternative to Magento Community Edition (CE). A vulnerability in magento-lts versions before 19.4.13 and 20.0.9 potentially allows an administrator unauthorized access to restricted re...Show more |
The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric,...Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Apr 19, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The serialnumber parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An attacker can mak...Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Apr 19, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The componentStatus parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection An attacker can m...Show more |
1Qnap 3Media Streaming Add On Multimedia ConsoleQtsJun 17, 2026 Apr 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNA...Show more |
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is accomplished via the `ID` input field of ajax.php in the `Pugin library - delete` module. |
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter...Show more |
SQL Injection in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to obtain sesnitive database information by injecting SQL commands into the "cID" parameter when crea...Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Apr 15, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The assetStatus parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection An attacker can make...Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Apr 15, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An attacker can make an aut...Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Apr 15, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the The nomenclature parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL inje...Show more |
1Phpgurukul 1Beauty Parlour Management System Jun 17, 2026 Apr 15, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to obtain sensitive database information by injecting SQL commands into the "sername" paramete...Show more |
1Devolutions 1Devolutions Server Jun 17, 2026 Apr 14, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete. |
1Jazzband 1Django Debug Toolbar Jun 17, 2026 Apr 14, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL expl...Show more |
2Janobe Online Reviewer System Project2Online Reviewer System Online Reviewer SystemJun 17, 2026 Apr 14, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a reverse shell upload. |
1Eaton 3Intelligent Power Manager Intelligent Power Manager Virtual ApplianceIntelligent Power ProtectorJun 17, 2026 Apr 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated SQL injection. A malicious user can send a specially crafted packet to exploit the vulnerability. Successful exploitation of this vulnera...Show more |