CWE-89
20,927 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,927)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Code Projects 1Simple Admin Panel Jun 17, 2026 Feb 14, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php. |
Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php. |
Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/EditTask.php. |
1Oretnom23 1Online Medicine Ordering System Jun 17, 2026 Feb 14, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product. |
1Sherlock 1Employee Management System Jun 17, 2026 Feb 14, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php. |
1Sherlock 1Employee Management System Jun 17, 2026 Feb 14, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php. |
1Sherlock 1Employee Management System Jun 17, 2026 Feb 14, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html. |
1Sherlock 1Employee Management System Jun 17, 2026 Feb 14, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php. |
1Sherlock 1Employee Management System Jun 17, 2026 Feb 14, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php. |
1Rems 1Simple Expense Tracker App Jun 17, 2026 Feb 14, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php. |
1Rems 1Simple Expense Tracker App Jun 17, 2026 Feb 14, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php. |
1Rems 1Barangay Population Monitoring System Jun 17, 2026 Feb 14, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php. |
1Unipa 1University Information System Jun 17, 2026 Feb 14, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UNI-PA University Marketing & Computer Internet Trade Inc. University Information System allows SQL Injection. This i...Show more |
Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a...Show more |
In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject...Show more |
In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject...Show more |
Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter. |
SQL injection vulnerability in adv radius v.2.2.5 allows a local attacker to execute arbitrary code via a crafted script. |
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application is vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries on...Show more |
SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET request using modifiers[attribute][] parameter. |