CWE-89
20,898 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,898)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Sante PACS Server Token Endpoint SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante PACS Server. Authentication is n...Show more |
Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploi...Show more |
1Oretnom23 1Computer Laboratory Management System Jun 17, 2026 Apr 1, 2024 N/A· v4 6.5 MEDIUM· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /classes/Master.php?f=save_category. The manipu...Show more |
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_virtual_site_info.php. |
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/history.php. |
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/index.php. |
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/configguide/ipsec_guide_1.php. |
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/export_excel_user.php. |
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupSSLCert.php. |
SQL injection vulnerability exists in GetDIAE_usListParameters.
|
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/menu.php. |
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php. |
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupTimePolicy.php. |
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php. |
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/applyhardware.php. |
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/address_interpret.php. |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web 10Web Map Builder for Google Maps.This issue affects 10Web Map Builder for Google Maps: from n/a through 1.0.74. |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WhiteStudio Easy Form Builder.This issue affects Easy Form Builder: from n/a through 3.7.4. |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Cost Estimation & Payment Forms Builder.This issue affects WP Cost Estimation & Payment Forms Builder: from...Show more |
1Phpgurukul 1Emergency Ambulance Hiring Portal Jun 17, 2026 Mar 30, 2024 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. This affects an unknown part of the file /admin/forgot-password.php of the component Forgot Password Page....Show more |