← Back
CWE-89

20,927 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,927)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Code Projects
1Simple Admin Panel
Jun 17, 2026
Feb 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php.
1Code Projects
1Task Manager
Jun 17, 2026
Feb 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php.
1Code Projects
1Task Manager
Jun 17, 2026
Feb 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/EditTask.php.
1Oretnom23
1Online Medicine Ordering System
Jun 17, 2026
Feb 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product.
1Sherlock
1Employee Management System
Jun 17, 2026
Feb 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php.
1Sherlock
1Employee Management System
Jun 17, 2026
Feb 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.
1Sherlock
1Employee Management System
Jun 17, 2026
Feb 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html.
1Sherlock
1Employee Management System
Jun 17, 2026
Feb 14, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php.
1Sherlock
1Employee Management System
Jun 17, 2026
Feb 14, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php.
1Rems
1Simple Expense Tracker App
Jun 17, 2026
Feb 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php.
1Rems
1Simple Expense Tracker App
Jun 17, 2026
Feb 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php.
1Rems
1Barangay Population Monitoring System
Jun 17, 2026
Feb 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php.
1Unipa
1University Information System
Jun 17, 2026
Feb 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UNI-PA University Marketing & Computer Internet Trade Inc. University Information System allows SQL Injection. This i...Show more
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UNI-PA University Marketing & Computer Internet Trade Inc. University Information System allows SQL Injection. This issue affects University Information System: before 12.12.2023.Show less
1Cusg
1Content Management System
Jun 17, 2026
Feb 14, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a...Show more
Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the pages.php component.Show less
1Dell
1Secure Connect Gateway
Jun 17, 2026
Feb 14, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject...Show more
In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of Collection Rest API. This issue may potentially lead to unintentional information disclosure from the product database. Show less
1Dell
1Secure Connect Gateway
Jun 17, 2026
Feb 14, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject...Show more
In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of IP Range Rest API. This issue may potentially lead to unintentional information disclosure from the product database. Show less
1Rems
1School Task Manager
Jun 17, 2026
Feb 13, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.
1Advradius
1Adv Radius
Jun 17, 2026
Feb 13, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection vulnerability in adv radius v.2.2.5 allows a local attacker to execute arbitrary code via a crafted script.
1Siemens
1Sinec Nms
Jun 17, 2026
Feb 13, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application is vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries on...Show more
A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application is vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database.Show less
1Gambio
1Gambio
Jun 17, 2026
Feb 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET request using modifiers[attribute][] parameter.