Vulnerabilities (CVE)

Filtered by CWE-89
Total 15274 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-42242 1 Seling 1 Visual Access Manager 2025-04-17 N/A 3.8 LOW
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /monitor/s_terminal.php.
CVE-2023-42243 1 Seling 1 Visual Access Manager 2025-04-17 N/A 5.4 MEDIUM
In Selesta Visual Access Manager < 4.42.2, an authenticated user can access the administrative page /common/vam_Sql.php, which allows for arbitrary SQL queries.
CVE-2023-42244 1 Seling 1 Visual Access Manager 2025-04-17 N/A 8.8 HIGH
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_visits.php.
CVE-2024-57660 1 Openlinksw 1 Virtuoso 2025-04-17 N/A 7.5 HIGH
An issue in the sqlo_expand_jts component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2022-45041 1 Rockoa 1 Xinhu 2025-04-17 N/A 7.5 HIGH
SQL Injection exits in xinhu < 2.5.0
CVE-2025-0297 1 Code-projects 1 Online Book Shop 2025-04-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in code-projects Online Book Shop 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /detail.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-12936 1 Code-projects 1 Simple Admin Panel 2025-04-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability, which was classified as critical, has been found in code-projects Simple Admin Panel 1.0. This issue affects some unknown processing of the file catDeleteController.php. The manipulation of the argument record leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-12946 1 1000projects 1 Attendance Tracking Management System 2025-04-17 7.5 HIGH 7.3 HIGH
A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System 1.0. This issue affects some unknown processing of the file /admin/admin_action.php. The manipulation of the argument admin_user_name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-12927 1 1000projects 1 Attendance Tracking Management System 2025-04-17 7.5 HIGH 7.3 HIGH
A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System 1.0. Affected by this issue is some unknown functionality of the file /faculty/check_faculty_login.php. The manipulation of the argument faculty_emailid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-12935 1 Code-projects 1 Simple Admin Panel 2025-04-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical was found in code-projects Simple Admin Panel 1.0. This vulnerability affects unknown code of the file editItemForm.php. The manipulation of the argument record leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-46374 1 Mayurik 1 Best House Rental Management System 2025-04-16 N/A 9.8 CRITICAL
Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the file rental/admin_class.php.
CVE-2024-25507 1 Ruvar 1 Ruvaroa 2025-04-16 N/A 9.4 CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the email_attach_id parameter at /LHMail/AttachDown.aspx.
CVE-2024-25508 1 Ruvar 1 Ruvaroa 2025-04-16 N/A 9.8 CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /bulletin/bulletin_template_show.aspx.
CVE-2024-25512 1 Ruvar 1 Ruvaroa 2025-04-16 N/A 8.1 HIGH
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the attach_id parameter at /Bulletin/AttachDownLoad.aspx.
CVE-2024-25509 1 Ruvar 1 Ruvaroa 2025-04-16 N/A 9.4 CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_file_download.aspx.
CVE-2024-25510 1 Ruvar 1 Ruvaroa 2025-04-16 N/A 9.8 CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_show.aspx.
CVE-2024-25511 1 Ruvar 1 Ruvaroa 2025-04-16 N/A 9.4 CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_new.aspx.
CVE-2024-25513 1 Ruvar 1 Ruvaroa 2025-04-16 N/A 7.8 HIGH
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /CorporateCulture/kaizen_download.aspx.
CVE-2024-25514 1 Ruvar 1 Ruvaroa 2025-04-16 N/A 9.4 CRITICAL
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /SysManage/wf_template_child_field_list.aspx.
CVE-2024-25515 1 Ruvar 1 Ruvaroa 2025-04-16 N/A 7.3 HIGH
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkFlow/wf_work_finish_file_down.aspx.