Vulnerabilities (CVE)

Filtered by CWE-89
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-42235 1 Enhancesoft 1 Osticket 2022-05-13 7.5 HIGH 9.8 CRITICAL
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.
CVE-2022-28461 1 Mingyuefusu Project 1 Mingyuefusu 2022-05-13 7.5 HIGH 9.8 CRITICAL
mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection.
CVE-2022-27360 1 Bladex 1 Springblade 2022-05-13 7.5 HIGH 9.8 CRITICAL
SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.
CVE-2022-25490 1 Hospital Management System Project 1 Hospital Management System 2022-05-12 7.5 HIGH 9.8 CRITICAL
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.
CVE-2022-25492 1 Hospital Management System Project 1 Hospital Management System 2022-05-12 7.5 HIGH 9.8 CRITICAL
HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.
CVE-2022-25004 1 Hospital\'s Patient Records Management System Project 1 Hospital\'s Patient Records Management System 2022-05-12 7.5 HIGH 9.8 CRITICAL
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php.
CVE-2022-27413 1 Hospital Management System Project 1 Hospital Management System 2022-05-12 7.5 HIGH 9.8 CRITICAL
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php.
CVE-2021-42185 1 Wdja 1 Wdja 2022-05-12 7.5 HIGH 9.8 CRITICAL
wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function.
CVE-2022-28512 1 Fantastic Blog Project 1 Fantastic Blog 2022-05-12 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters.
CVE-2022-0657 1 5 Stars Rating Funnel Project 1 5 Stars Rating Funnel 2022-05-12 7.5 HIGH 9.8 CRITICAL
The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an attempt to sanitise the input, using sanitize_text_field(), however such function is not intended to prevent SQL injections.
CVE-2022-28530 1 Covid-19 Directory On Vaccination System Project 1 Covid-19 Directory On Vaccination System 2022-05-11 7.5 HIGH 9.8 CRITICAL
Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory.
CVE-2022-28533 1 Medical Hub Directory Site Project 1 Medical Hub Directory Site 2022-05-11 7.5 HIGH 9.8 CRITICAL
Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php.
CVE-2022-27927 1 Microfinance Management System Project 1 Microfinance Management System 2022-05-11 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.
CVE-2021-43481 1 Webtareas Project 1 Webtareas 2022-05-11 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.
CVE-2022-27431 1 Wuzhicms 1 Wuzhi Cms 2022-05-11 7.5 HIGH 9.8 CRITICAL
Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php.
CVE-2022-27420 1 Hospital Management System Project 1 Hospital Management System 2022-05-11 7.5 HIGH 9.8 CRITICAL
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.
CVE-2022-1531 1 Rtx Project 1 Rtx 2022-05-11 10.0 HIGH 9.8 CRITICAL
SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint_2022-04-20 . This vulnerability is critical as it can lead to remote code execution and thus complete server takeover.
CVE-2022-1378 1 Deltaww 1 Diaenergie 2022-05-11 10.0 HIGH 9.8 CRITICAL
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
CVE-2022-1377 1 Deltaww 1 Diaenergie 2022-05-11 10.0 HIGH 9.8 CRITICAL
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
CVE-2022-1376 1 Deltaww 1 Diaenergie 2022-05-10 10.0 HIGH 9.8 CRITICAL
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_privgrpHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
CVE-2022-1375 1 Deltaww 1 Diaenergie 2022-05-10 10.0 HIGH 9.8 CRITICAL
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
CVE-2022-1374 1 Deltaww 1 Diaenergie 2022-05-10 10.0 HIGH 9.8 CRITICAL
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
CVE-2022-1372 1 Deltaww 1 Diaenergie 2022-05-10 10.0 HIGH 9.8 CRITICAL
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
CVE-2022-1371 1 Deltaww 1 Diaenergie 2022-05-10 10.0 HIGH 9.8 CRITICAL
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegf. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
CVE-2022-1370 1 Deltaww 1 Diaenergie 2022-05-10 10.0 HIGH 9.8 CRITICAL
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
CVE-2022-1369 1 Deltaww 1 Diaenergie 2022-05-10 10.0 HIGH 9.8 CRITICAL
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
CVE-2022-1367 1 Deltaww 1 Diaenergie 2022-05-10 10.0 HIGH 9.8 CRITICAL
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
CVE-2022-1366 1 Deltaww 1 Diaenergie 2022-05-10 10.0 HIGH 9.8 CRITICAL
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
CVE-2022-29904 1 Mediawiki 1 Mediawiki 2022-05-10 7.5 HIGH 9.8 CRITICAL
The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints.
CVE-2022-27466 1 Mingsoft 1 Mcms 2022-05-10 7.5 HIGH 9.8 CRITICAL
MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.
CVE-2022-28585 1 Phome 1 Empirecms 2022-05-09 7.5 HIGH 9.8 CRITICAL
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
CVE-2022-27962 1 Bluecms Project 1 Bluecms 2022-05-09 7.5 HIGH 9.8 CRITICAL
Bluecms 1.6 has a SQL injection vulnerability at cooike.
CVE-2022-0771 1 Marketingheroes 1 Sitesupercharger 2022-05-09 7.5 HIGH 9.8 CRITICAL
The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections
CVE-2022-0773 1 Documentor Project 1 Documentor 2022-05-09 7.5 HIGH 9.8 CRITICAL
The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.
CVE-2022-1281 1 10web 1 Photo Gallery 2022-05-09 7.5 HIGH 9.8 CRITICAL
The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.
CVE-2022-27299 1 Hospital Management System Project 1 Hospital Management System 2022-05-05 7.5 HIGH 9.8 CRITICAL
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.
CVE-2022-27985 1 Cuppacms 1 Cuppacms 2022-05-05 7.5 HIGH 9.8 CRITICAL
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
CVE-2022-27984 1 Cuppacms 1 Cuppacms 2022-05-05 7.5 HIGH 9.8 CRITICAL
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
CVE-2022-28524 1 Ed01-cms Project 1 Ed01-cms 2022-05-04 7.5 HIGH 9.8 CRITICAL
ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php.
CVE-2022-0693 1 Devbunch 1 Master Elements 2022-05-04 7.5 HIGH 9.8 CRITICAL
The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL Injection
CVE-2022-0769 1 Usersultra 1 Users Ultra 2022-05-04 7.5 HIGH 9.8 CRITICAL
The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users), leading to an SQL Injection.
CVE-2022-0782 1 Donations Project 1 Donations 2022-05-03 7.5 HIGH 9.8 CRITICAL
The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an unauthenticated SQL Injection
CVE-2021-34166 1 Simple Food Website Project 1 Simple Food Website 2022-05-03 7.5 HIGH 9.8 CRITICAL
A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin.
CVE-2019-10692 1 Codecabin 1 Wp Google Maps 2022-05-03 7.5 HIGH 9.8 CRITICAL
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.
CVE-2022-27342 1 Link-admin Project 1 Link-admin 2022-04-29 7.5 HIGH 9.8 CRITICAL
Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest.ResponseResult().
CVE-2022-27341 1 Jfinalcms Project 1 Jfinalcms 2022-04-29 7.5 HIGH 9.8 CRITICAL
JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function.
CVE-2022-28421 1 Baby Care System Project 1 Baby Care System 2022-04-29 7.5 HIGH 9.8 CRITICAL
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=posts&action=display&value=1&postid=.
CVE-2022-28422 1 Baby Care System Project 1 Baby Care System 2022-04-29 7.5 HIGH 9.8 CRITICAL
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&action=edit.
CVE-2022-28423 1 Baby Care System Project 1 Baby Care System 2022-04-29 7.5 HIGH 9.8 CRITICAL
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&action=delete.
CVE-2022-28426 1 Baby Care System Project 1 Baby Care System 2022-04-29 7.5 HIGH 9.8 CRITICAL
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/pagerole.php&action=edit&roleid=.