CWE-89
20,759 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,759)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection. |
Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/attackers can execute arbitrary SQL queries negatively affecting the confidentiality, integrity, and av...Show more |
1Grandstream 3Ucm6202 Firmware Ucm6204 FirmwareUcm6208 FirmwareJun 17, 2026 Mar 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover us...Show more |
1Grandstream 3Ucm6202 Firmware Ucm6204 FirmwareUcm6208 FirmwareJun 17, 2026 Mar 30, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, thro...Show more |
1Grandstream 3Ucm6202 Firmware Ucm6204 FirmwareUcm6208 FirmwareJun 17, 2026 Mar 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the challenge action with a crafted username and d...Show more |
odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued. |
odata4j 0.7.0 allows ExecuteCountQueryCommand.java SQL injection. NOTE: this product is apparently discontinued. |
In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection. |
1Custom Searchable Data Entry System Project 1Custom Searchable Data Entry System Jun 17, 2026 Mar 27, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress allows SQL Injection. NOTE: this product is discontinued. |
1Unisoon 1Ultralog Express Firmware Jun 17, 2026 Mar 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command. |
1Microfocus 1Service Manager Automation Jun 17, 2026 Mar 26, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.08, 2019.05, 2019.02, 2018.08, 2018.05, 2018.02. The vulnerability could allow for the improper neutr...Show more |
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is time-based SQL injection in Contacts. The Samsung ID is SVE-2018-13452 (March 2019). |
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Story Video Editor Content Provider. The Samsung ID is SVE-2019-14062 (July 2019). |
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Gear VR Service Content Provider. The Samsung ID is SVE-2019-14058 (July 2019). |
An issue was discovered on Samsung mobile devices with P(9.0) software. The MemorySaver Content Provider allows SQL injection. The Samsung ID is SVE-2019-14365 (August 2019). |
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Wi-Fi history Content Provider. The Samsung ID is SVE-2019-14061 (August 2019). |
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the RCS Content Provider. The Samsung IDs are SVE-2019-14059, SVE-2019-14685 (August 2019). |
1Grandstream 1Ucm6200 Firmware Jun 17, 2026 Mar 23, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions...Show more |
5Debian FedoraprojectOpensuse+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 Mar 22, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.ph...Show more |
5Debian FedoraprojectOpensuse+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 Mar 22, 2020 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/cla...Show more |