CWE-89
20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,759)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Eyesofnetwork 1Eyesofnetwork Jun 17, 2026 Oct 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to exploit the username_available function of the includes/f...Show more |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Oct 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter. |
1Victor Cms Project 1Victor Cms Jun 17, 2026 Oct 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by sqlmap to obtain data information in the database. |
1Fireeye 1Email Malware Protection System Jun 17, 2026 Oct 26, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sort_by, search{URL], or search[attachment] parameter to the email search feature. |
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip. |
1Tipsandtricks Hq 1Simple Download Monitor Jun 17, 2026 Oct 21, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 SQL injection vulnerability in Simple Download Monitor 3.8.8 and earlier allows remote attackers to execute arbitrary SQL commands via a specially crafted URL. |
The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve sensitive information. |
1Tibco 3Foresight Archive And Retrieval System Foresight Operational MonitorForesight Transaction InsightJun 17, 2026 Oct 20, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Transaction Insight reporting component of TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIB...Show more |
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.2.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or d...Show more |
1Aptean 1Product Configurator Jun 17, 2026 Oct 16, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the nameTxt parameter on the main login page (aka cse?cmd=LOGIN). This can be exploited directly, and remote...Show more |
A vulnerability has been identified in Desigo Insight (All versions). The web service does not properly apply input validation for some query parameters in a reserved area. This could allow an authenticated attacker to r...Show more |
A SQL Injection issue in Rapid7 Nexpose version prior to 6.6.49 that may have allowed an authenticated user with a low permission level to access resources & make changes they should not have been able to access. |
An issue was discovered in HelpDeskZ 1.0.2. The feature to auto-login a user, via the RememberMe functionality, is prone to SQL injection. NOTE: This vulnerability only affects products that are no longer supported by th...Show more |
4Debian FedoraprojectOpensuse+1 more5Backports Sle Debian LinuxFedora+2 moreJun 17, 2026 Oct 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker coul...Show more |
1Online Bus Booking System Project 1Online Bus Booking System Jun 17, 2026 Oct 8, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection. |
In GLPI before version 9.5.2, there is a SQL Injection in the API's search function. Not only is it possible to break the SQL syntax, but it is also possible to utilise a UNION SELECT query to reflect sensitive informati...Show more |
In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing for SQL Injection to occur. Leveraging this vulnerability an attacker...Show more |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Oct 6, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Oct 6, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module. |
1Damstratechnology 1Smart Asset Jun 17, 2026 Oct 2, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remote connections to third party DNS servers. |