CWE-89
20,763 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,763)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Apr 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the compnomenclature parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Apr 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the description parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Apr 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the serviceUID parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Apr 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the supplierUID parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
2Open Emr Phpgacl Project2Openemr PhpgaclJun 17, 2026 Apr 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SQL injection vulnerability exists in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability in admin/edit_group.php, when the POST...Show more |
2Open Emr Phpgacl Project2Openemr PhpgaclJun 17, 2026 Apr 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability In admin/edit_group.php, when the POS...Show more |
The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint. |
ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page. |
1Expresstech 1Quiz And Survey Master Jun 17, 2026 Apr 12, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating...Show more |
1Tms Outsource 1Wpdatatables Jun 17, 2026 Apr 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin...Show more |
1Tms Outsource 1Wpdatatables Jun 17, 2026 Apr 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin...Show more |
1Online Book Store Project 1Online Book Store Jun 17, 2026 Apr 9, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication. |
An exploitable SQL injection vulnerability exists in "global_lists/choices" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authen...Show more |
An exploitable SQL injection vulnerability exists in the "access_rules/rules_form" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make an...Show more |
An exploitable SQL injection vulnerability exists in the "forms_fields_rules/rules" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make a...Show more |
SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/. |
1Cisco 3Unified Communications Manager Unified Communications Manager Im & Presence ServiceUnity ConnectionJun 17, 2026 Apr 8, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Com...Show more |
1Cisco 1Unified Communications Manager Jun 17, 2026 Apr 8, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Com...Show more |
1Cisco 1Unified Communications Manager Jun 17, 2026 Apr 8, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Com...Show more |
1Cisco 3Unified Communications Manager Unified Communications Manager Im & Presence ServiceUnity ConnectionJun 17, 2026 Apr 8, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Com...Show more |