Filtered by CWE-89
Filtered by vendor Subscriptions
Total 18426 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-1854 1 Codezips 1 Gym Management System 2025-06-24 6.3 Medium
A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/del_member.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2021-1470 1 Cisco 1 Catalyst Sd-wan Manager 2025-06-24 4.9 Medium
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper input validation of SQL queries to an affected system. An attacker could exploit this vulnerability by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on or return values from the vManage database or the underlying operating system.Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
CVE-2025-5913 2 Anujk305, Phpgurukul 2 Vehicle Record Management System, Vehicle Record Management System 2025-06-24 7.3 High
A vulnerability was found in PHPGurukul Vehicle Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/search-vehicle.php. The manipulation of the argument searchinputdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-3003 1 Esafenet 1 Cdg 2025-06-24 6.3 Medium
A vulnerability, which was classified as critical, was found in ESAFENET CDG 3. Affected is an unknown function of the file /CDGServer3/UserAjax. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-4778 1 Phpgurukul 1 Park Ticketing Management System 2025-06-24 6.3 Medium
A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been declared as critical. This vulnerability affects unknown code of the file /normal-search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-5433 1 Fengoffice 1 Feng Office 2025-06-24 6.3 Medium
A vulnerability was found in Fengoffice Feng Office 3.5.1.5 and classified as critical. Affected by this issue is some unknown functionality of the file /index.php?c=account&a=set_timezone. The manipulation of the argument tz_offset leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-36528 2 Manageengine, Zohocorp 2 Adaudit Plus, Manageengine Adaudit Plus 2025-06-24 8.3 High
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports.
CVE-2025-26136 2 Mysiteforme, Wangl1989 2 Mysiteforme, Mysiteforme 2025-06-24 9.8 Critical
A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1.
CVE-2024-51165 1 Ketr 1 Jepaas 2025-06-24 7.5 High
SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.
CVE-2024-57430 1 Phpjabbers 1 Cinema Booking System 2025-06-24 9.8 Critical
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.
CVE-2025-4738 2025-06-23 9.8 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yirmibes Software MY ERP allows SQL Injection.This issue affects MY ERP: before 1.170.
CVE-2025-3893 1 Jan Syski 1 Megabip 2025-06-23 N/A
While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this action. Input provided by the the user is not sanitized, leading to SQL Injection vulnerability.  Version 5.20 of MegaBIP fixes this issue.
CVE-2024-36428 1 Orangehrm 1 Orangehrm 2025-06-23 8.1 High
OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection.
CVE-2025-28056 1 Ruifang-tech 1 Rebuild 2025-06-23 9.8 Critical
rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.
CVE-2024-40570 1 Seacms 1 Seacms 2025-06-23 6.5 Medium
SQL Injection vulnerability in SeaCMS v.12.9 allows a remote attacker to obtain sensitive information via the admin_datarelate.php component.
CVE-2025-0404 1 Liujianview 1 Gymxmjpa 2025-06-23 6.3 Medium
A vulnerability has been found in liujianview gymxmjpa 1.0 and classified as critical. This vulnerability affects the function CoachController of the file src/main/java/com/liujian/gymxmjpa/controller/CoachController.java. The manipulation of the argument coachName leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-25312 1 Code-projects 1 Simple School Management System 2025-06-21 8.8 High
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5."
CVE-2024-25310 1 Code-projects 1 Simple School Management System 2025-06-21 8.8 High
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5."
CVE-2024-25307 1 Code-projects 1 Cinema Seat Reservation System 2025-06-21 9.8 Critical
Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1."
CVE-2024-24015 1 Xxyopen 1 Novel-plus 2025-06-21 9.8 Critical
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL via /sys/user/exit