CWE-89
20,740 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,740)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wanzhou 1Woes Intelligent Optimization Energy Saving System Jun 17, 2026 Aug 8, 2025 2.1 LOW· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. Affected is an unknown function of the file /WEAS_HomePage/GetTargetConfig of the component...Show more |
1Wanzhou 1Woes Intelligent Optimization Energy Saving System Jun 17, 2026 Aug 8, 2025 2.1 LOW· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This issue affects some unknown processing of the file /WEAS_AlarmResult/GetAlarmResult...Show more |
1Wanzhou 1Woes Intelligent Optimization Energy Saving System Jun 17, 2026 Aug 8, 2025 2.1 LOW· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability classified as critical was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This vulnerability affects unknown code of the file /WEAS_HomePage/GetAreaTrendChartData of the componen...Show more |
1Wanzhou 1Woes Intelligent Optimization Energy Saving System Jun 17, 2026 Aug 8, 2025 2.1 LOW· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability classified as critical has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This affects an unknown part of the file /CommonSolution/GetVariableByOneIDNew of the component His...Show more |
1Wanzhou 1Woes Intelligent Optimization Energy Saving System Jun 17, 2026 Aug 7, 2025 2.1 LOW· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /OL_OprationLog/GetPageList. Th...Show more |
1Kishan0725 1Hospital Management System Jun 17, 2026 Aug 7, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch.php. |
1Kishan0725 1Hospital Management System Jun 17, 2026 Aug 7, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameters. |
1Kishan0725 1Hospital Management System Jun 17, 2026 Aug 7, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php. |
1Kishan0725 1Hospital Management System Jun 17, 2026 Aug 7, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters. |
1Kishan0725 1Hospital Management System Jun 17, 2026 Aug 7, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php. |
1Kishan0725 1Hospital Management System Jun 17, 2026 Aug 7, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters. |
1Kishan0725 1Hospital Management System Jun 17, 2026 Aug 7, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php. |
1Student Attendance Management System Project 1Student Attendance Management System Jun 17, 2026 Aug 7, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index.php. |
1Student Attendance Management System Project 1Student Attendance Management System Jun 17, 2026 Aug 7, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher.php. |
1Student Attendance Management System Project 1Student Attendance Management System Jun 17, 2026 Aug 7, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents.php via the Id, firstname, and admissionNumber parameters. |
1Student Attendance Management System Project 1Student Attendance Management System Jun 17, 2026 Aug 7, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessionTerm.php via the id, termId, and sessionName parameters. |
1Student Attendance Management System Project 1Student Attendance Management System Jun 17, 2026 Aug 7, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassArms.php via the classId and classArmName parameters. |
1Kishan0725 1Hospital Management System Jun 17, 2026 Aug 7, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 parameter. |
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated users can exploit this. |
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in the backend database,...Show more |