CWE-89
20,763 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,763)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 1Telecontrol Server Basic Jun 17, 2026 Apr 16, 2025 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateDatabaseSettings' method. This could a...Show more |
1Siemens 1Telecontrol Server Basic Jun 17, 2026 Apr 16, 2025 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateUsers' method. This could allow an aut...Show more |
1Siemens 1Telecontrol Server Basic Jun 17, 2026 Apr 16, 2025 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ImportDatabase' method. This could allow an...Show more |
1Siemens 1Telecontrol Server Basic Jun 17, 2026 Apr 16, 2025 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateProjectConnections' method. This could...Show more |
1Siemens 1Telecontrol Server Basic Jun 17, 2026 Apr 16, 2025 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateConnectionVariables' method. This coul...Show more |
1Siemens 1Telecontrol Server Basic Jun 17, 2026 Apr 16, 2025 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'RestoreFromBackup' method. This could allow...Show more |
1Siemens 1Telecontrol Server Basic Jun 17, 2026 Apr 16, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'Authenticate' method. This could allow an un...Show more |
1Siemens 1Telecontrol Server Basic Jun 17, 2026 Apr 16, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'VerifyUser' method. This could allow an unau...Show more |
1Siemens 1Telecontrol Server Basic Jun 17, 2026 Apr 16, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateTrace' method. This could allow an una...Show more |
1Oretnom23 1Online Id Generator System Jun 17, 2026 Apr 16, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4. |
1Oretnom23 1Online Id Generator System Jun 17, 2026 Apr 16, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1. |
1Oretnom23 1Online Id Generator System Jun 17, 2026 Apr 16, 2025 N/A· v4 5.9 MEDIUM· v3 N/A· v2 Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=templates/manage_template&id=1. |
1Senior Walter 1Web Based Pharmacy Product Management System Jun 17, 2026 Apr 16, 2025 5.3 MEDIUM· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some unknown processing of the file /edit-product.php. The manipula...Show more |
1Senior Walter 1Web Based Pharmacy Product Management System Jun 17, 2026 Apr 16, 2025 5.3 MEDIUM· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unknown code of the file /search/search_stock. php. The manipulation of the...Show more |
1Senior Walter 1Web Based Pharmacy Product Management System Jun 17, 2026 Apr 16, 2025 6.9 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability classified as critical has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the component Login Handler. The manipulation of the argument logi...Show more |
1Phpgurukul 1Men Salon Management System Jun 17, 2026 Apr 16, 2025 6.9 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit-services.php. The manipulation of the argument cost l...Show more |
1Phpgurukul 1Men Salon Management System Jun 17, 2026 Apr 16, 2025 6.9 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-customer-detailed.php. The manipulation of the argu...Show more |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Hostel hostel allows Blind SQL Injection.This issue affects Hostel: from n/a through <= 1.1.5.6. |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedefiningTheWeb BMA Lite bma-lite-appointment-booking-and-scheduling allows SQL Injection.This issue affects BMA Lite...Show more |
Improper neutralization of input provided by a low-privileged user into a file search functionality in Ready_'s Invoices module allows for SQL Injection attacks. |