Vulnerabilities (CVE)

Filtered by CWE-89
Total 11593 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-36675 1 Simple Task Scheduling System Project 1 Simple Task Scheduling System 2022-09-02 N/A 7.2 HIGH
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /schedules/manage_schedule.php.
CVE-2022-36674 1 Simple Task Scheduling System Project 1 Simple Task Scheduling System 2022-09-02 N/A 7.2 HIGH
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /schedules/view_schedule.php.
CVE-2020-35846 1 Agentejo 1 Cockpit 2022-09-02 7.5 HIGH 9.8 CRITICAL
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
CVE-2022-36705 1 Ingredients Stock Management System Project 1 Ingredients Stock Management System 2022-09-01 N/A 9.8 CRITICAL
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_waste.php.
CVE-2022-36704 1 Library Management System Project 1 Library Management System 2022-09-01 N/A 8.8 HIGH
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /librarian/studentdetails.php.
CVE-2022-36708 1 Library Management System Project 1 Library Management System 2022-09-01 N/A 9.8 CRITICAL
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /student/bookdetails.php.
CVE-2022-36706 1 Ingredients Stock Management System Project 1 Ingredients Stock Management System 2022-09-01 N/A 9.8 CRITICAL
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_stockout.php.
CVE-2022-36735 1 Library Management System Project 1 Library Management System 2022-09-01 N/A 9.8 CRITICAL
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /admin/delete.php.
CVE-2022-36734 1 Library Management System Project 1 Library Management System 2022-09-01 N/A 9.8 CRITICAL
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /admin/delstu.php.
CVE-2022-36733 1 Library Management System Project 1 Library Management System 2022-09-01 N/A 9.8 CRITICAL
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /admin/del.php.
CVE-2022-36732 1 Library Management System Project 1 Library Management System 2022-09-01 N/A 9.8 CRITICAL
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /librarian/dele.php.
CVE-2022-36731 1 Library Management System Project 1 Library Management System 2022-09-01 N/A 9.8 CRITICAL
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /librarian/delstu.php.
CVE-2022-36730 1 Library Management System Project 1 Library Management System 2022-09-01 N/A 9.8 CRITICAL
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /librarian/delete.php.
CVE-2022-36714 1 Library Management System Project 1 Library Management System 2022-09-01 N/A 9.8 CRITICAL
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /staff/lab.php.
CVE-2022-36713 1 Library Management System Project 1 Library Management System 2022-09-01 N/A 9.8 CRITICAL
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /librarian/lab.php.
CVE-2022-36712 1 Library Management System Project 1 Library Management System 2022-09-01 N/A 9.8 CRITICAL
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/studentdetails.php.
CVE-2022-36711 1 Library Management System Project 1 Library Management System 2022-09-01 N/A 9.8 CRITICAL
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/bookdetails.php.
CVE-2022-36709 1 Library Management System Project 1 Library Management System 2022-09-01 N/A 9.8 CRITICAL
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/edit_book_details.php.
CVE-2022-2559 1 Wpmanageninja 1 Fluent Support 2022-09-01 N/A 7.2 HIGH
The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection vulnerability exploitable by high privilege users
CVE-2022-1123 1 Mapsmarker 1 Leaflet Maps Marker 2022-09-01 N/A 7.2 HIGH
The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitize some parameters before inserting them into SQL queries. As a result, high privilege users could perform SQL injection attacks.