CWE-943
66 CVEs • Abstraction: Class
Improper Neutralization of Special Elements in Data Query Logic
The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.
CVEs (66)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qnap 3Media Streaming Add On Multimedia ConsoleQtsJun 17, 2026 Apr 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNA...Show more |
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct Cypher query language injection attacks on an affected system. The vulnerabi...Show more |
If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versio...Show more |
In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard, the direction parameter was not validated before being interpolated into the SQL query. This could present a SQL injection if th...Show more |
1Schneider Electric 59D6220 Firmware D6220l FirmwareD6230 Firmware+56 moreJun 17, 2026 May 22, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An Improper Neutralization of Special Elements in Query vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which allows an attacker to execute arbitrary system commands. |
2Debian Newsbeuter2Debian Linux NewsbeuterMay 13, 2026 Aug 23, 2017 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item tha...Show more |