Vulnerabilities (CVE)

Filtered by CWE-89
Angry Yack Logo
Total 18012 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-25388 1 Phpgurukul 1 Land Record System 2025-03-28 N/A 9.8 CRITICAL
A SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the editid GET request parameter.
CVE-2025-25387 1 Phpgurukul 1 Land Record System 2025-03-28 N/A 7.2 HIGH
A SQL Injection vulnerability was found in /admin/manage-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the propertytype POST request parameter.
CVE-2025-2074 2025-03-28 N/A 5.3 MEDIUM
The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to generic SQL Injection via the ‘sSearch’ parameter in all versions up to, and including, 1.29 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries, particularly when the plugin’s settings page hasn’t been vis ...

Show More

CVE-2025-31099 2025-03-28 N/A 7.6 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bestwebsoft Slider by BestWebSoft allows SQL Injection. This issue affects Slider by BestWebSoft: from n/a through 1.1.0.
CVE-2025-22523 2025-03-28 N/A 9.3 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Schedule allows Blind SQL Injection. This issue affects Schedule: from n/a through 1.0.0.
CVE-2025-31466 2025-03-28 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Falcon Solutions Duplicate Page and Post allows Blind SQL Injection. This issue affects Duplicate Page and Post: from n/a through 1.0.
CVE-2024-11504 2025-03-28 N/A N/A
Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, which might be exploited by an authenticated remote attacker.  This issue was fixed in 18.1.376.37 version of the software.
CVE-2025-26898 2025-03-28 N/A 9.3 CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler.This issue affects Traveler: from n/a through 3.1.8.
CVE-2022-46499 1 Phpgurukul 1 Hospital Management System 2025-03-28 N/A 8.8 HIGH
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php.
CVE-2022-46498 1 Phpgurukul 1 Hospital Management System 2025-03-28 N/A 2.7 LOW
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php.
CVE-2022-46497 1 Phpgurukul 1 Hospital Management System 2025-03-28 N/A 8.1 HIGH
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php.
CVE-2022-48011 1 Opencats 1 Opencats 2025-03-28 N/A 9.8 CRITICAL
Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.
CVE-2025-25514 1 Seacms 1 Seacms 2025-03-28 N/A 6.5 MEDIUM
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.
CVE-2025-25515 1 Seacms 1 Seacms 2025-03-28 N/A 8.8 HIGH
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.
CVE-2025-25516 1 Seacms 1 Seacms 2025-03-28 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.
CVE-2025-25517 1 Seacms 1 Seacms 2025-03-28 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.
CVE-2025-25519 1 Seacms 1 Seacms 2025-03-28 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.
CVE-2025-25520 1 Seacms 1 Seacms 2025-03-28 N/A 9.8 CRITICAL
Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.
CVE-2025-25521 1 Seacms 1 Seacms 2025-03-28 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.
CVE-2024-29275 1 Seacms 1 Seacms 2025-03-28 N/A 9.8 CRITICAL
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php.
CVE-2024-53438 1 Churchcrm 1 Churchcrm 2025-03-28 N/A 9.8 CRITICAL
EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands.
CVE-2024-55104 1 Phpgurukul 1 Online Nurse Hiring System 2025-03-28 N/A 7.2 HIGH
Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters.
CVE-2024-55103 1 Phpgurukul 1 Online Nurse Hiring System 2025-03-28 N/A 7.2 HIGH
Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter.
CVE-2023-22324 1 Contec 1 Conprosys Hmi System 2025-03-28 N/A 6.5 MEDIUM
SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in the database may be obtained.
CVE-2022-44298 1 Sscms 1 Siteserver Cms 2025-03-28 N/A 9.8 CRITICAL
SiteServer CMS 7.1.3 is vulnerable to SQL Injection.
CVE-2024-27746 1 Mayurik 1 Petrol Pump Management 2025-03-28 N/A 9.8 CRITICAL
SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component.
CVE-2023-49546 1 Oretnom23 1 Customer Support System 2025-03-28 N/A 8.8 HIGH
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.
CVE-2023-49547 1 Oretnom23 1 Customer Support System 2025-03-28 N/A 9.8 CRITICAL
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login.
CVE-2023-49548 1 Oretnom23 1 Customer Support System 2025-03-28 N/A 8.8 HIGH
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.
CVE-2023-49968 1 Oretnom23 1 Customer Support System 2025-03-28 N/A 7.3 HIGH
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php.
CVE-2023-49969 1 Oretnom23 1 Customer Support System 2025-03-28 N/A 4.3 MEDIUM
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer.
CVE-2023-49970 1 Oretnom23 1 Customer Support System 2025-03-28 N/A 9.8 CRITICAL
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket.
CVE-2023-49544 1 Oretnom23 1 Customer Support System 2025-03-28 N/A 4.9 MEDIUM
A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.
CVE-2024-28613 1 Mayurik 1 Php Task Management System 2025-03-27 N/A 9.8 CRITICAL
SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component.
CVE-2024-25248 1 Niushop 1 B2b2c Multi-business 2025-03-27 N/A 9.8 CRITICAL
SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.
CVE-2023-23331 1 Amano 1 Xoffice 2025-03-27 N/A 9.8 CRITICAL
Amano Xoffice parking solutions 7.1.3879 is vulnerable to SQL Injection.
CVE-2024-28558 1 Mayurik 1 Petrol Pump Management 2025-03-27 N/A 8.8 HIGH
SQL Injection vulnerability in sourcecodester Petrol pump management software v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin/app/web_crud.php.
CVE-2024-25217 1 Oretnom23 1 Online Medicine Ordering System 2025-03-27 N/A 9.8 CRITICAL
Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product.
CVE-2024-24105 1 Carmelo 1 Computer Science Time Table System 2025-03-27 N/A 7.8 HIGH
SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via adminFormvalidation.php.
CVE-2022-45297 1 Eq Project 1 Eq 2025-03-27 N/A 9.8 CRITICAL
EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.