CWE-89
20,740 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,740)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
There is a time-based blind SQL injection vulnerability in the Access Manager component before 9.18.040 and 10.x before 10.18.040 in ELO ELOenterprise 9 and 10 and ELOprofessional 9 and 10 that makes it possible to read...Show more |
1Icanstudioz 1Firebase Push Notification On Ios / Fcm + Advance Admin Panel Nov 21, 2024 Jul 10, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The "Firebase Cloud Messaging (FCM) + Advance Admin Panel" component supporting Firebase Push Notification on iOS (through 2017-10-26) allows SQL injection via the /advance_push/public/login username parameter. |
A SQL injection vulnerability in the SoftExpert (SE) Excellence Suite 2.0 allows remote authenticated users to perform SQL heuristics by pulling information from the database with the "cddocument" parameter in the "Downl...Show more |
1Ibm 1Infosphere Data Replication Dashboard Nov 21, 2024 Jul 9, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. IBM X-Force ID: 84116. |
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the status_batch parameter. |
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statut_buy parameter. |
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the country_id parameter. |
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statut parameter. |
1Qualcomm 14Msm8909w Firmware Msm8996au FirmwareSd 205 Firmware+11 moreNov 21, 2024 Jul 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Improper Input Validation in Linux io-prefetch in Snapdragon Mobile and Snapdragon Wear, A SQL injection vulnerability exists in versions MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 430, SD 450, SD 617, SD 625, SD 650/...Show more |
1Query Mysql Project 1Query Mysql Nov 21, 2024 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Node.js third-party module query-mysql versions 0.0.0, 0.0.1, and 0.0.2 are vulnerable to an SQL injection vulnerability due to lack of user input sanitization. This may allow an attacker to run arbitrary SQL queries whe...Show more |
/user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table. |
SQL injection vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to execute arbitrary SQL commands via the filterPattern parameter. |
1Schneider Electric 1U.motion Builder Jun 17, 2026 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the username input...Show more |
1Schneider Electric 1U.motion Builder Jun 17, 2026 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the sessionid inpu...Show more |
1Schneider Electric 1U.motion Builder Jun 17, 2026 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The vulnerability exists within processing of applets which are exposed on the web service in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query to determine wheth...Show more |
1Schneider Electric 1U.motion Builder Jun 17, 2026 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input param...Show more |
1Schneider Electric 1U.motion Builder Jun 17, 2026 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The vulnerability exists within processing of loadtemplate.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the tpl input p...Show more |
1Schneider Electric 1U.motion Builder Jun 17, 2026 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the type input pa...Show more |
1Schneider Electric 1U.motion Builder Jun 17, 2026 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The vulnerability exists within processing of track_getdata.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input p...Show more |
1Schneider Electric 1U.motion Builder Jun 17, 2026 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the obje...Show more |