Vulnerabilities (CVE)

Filtered by CWE-89
Total 15623 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-46499 1 Phpgurukul 1 Hospital Management System 2025-03-28 N/A 8.8 HIGH
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php.
CVE-2022-46498 1 Phpgurukul 1 Hospital Management System 2025-03-28 N/A 2.7 LOW
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php.
CVE-2022-46497 1 Phpgurukul 1 Hospital Management System 2025-03-28 N/A 8.1 HIGH
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php.
CVE-2022-48011 1 Opencats 1 Opencats 2025-03-28 N/A 9.8 CRITICAL
Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.
CVE-2025-25514 1 Seacms 1 Seacms 2025-03-28 N/A 6.5 MEDIUM
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.
CVE-2025-25515 1 Seacms 1 Seacms 2025-03-28 N/A 8.8 HIGH
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.
CVE-2025-25516 1 Seacms 1 Seacms 2025-03-28 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.
CVE-2025-25517 1 Seacms 1 Seacms 2025-03-28 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.
CVE-2025-25519 1 Seacms 1 Seacms 2025-03-28 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.
CVE-2025-25520 1 Seacms 1 Seacms 2025-03-28 N/A 9.8 CRITICAL
Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.
CVE-2025-25521 1 Seacms 1 Seacms 2025-03-28 N/A 9.8 CRITICAL
Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.
CVE-2024-12969 1 Fabianros 1 Hospital Management System 2025-03-28 7.5 HIGH 7.3 HIGH
A vulnerability, which was classified as critical, has been found in code-projects Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/index.php of the component Login. The manipulation of the argument username/password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-29275 1 Seacms 1 Seacms 2025-03-28 N/A 9.8 CRITICAL
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php.
CVE-2024-53438 1 Churchcrm 1 Churchcrm 2025-03-28 N/A 9.8 CRITICAL
EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands.
CVE-2024-55104 1 Phpgurukul 1 Online Nurse Hiring System 2025-03-28 N/A 7.2 HIGH
Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters.
CVE-2024-55103 1 Phpgurukul 1 Online Nurse Hiring System 2025-03-28 N/A 7.2 HIGH
Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter.
CVE-2023-22324 1 Contec 1 Conprosys Hmi System 2025-03-28 N/A 6.5 MEDIUM
SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in the database may be obtained.
CVE-2022-44298 1 Sscms 1 Siteserver Cms 2025-03-28 N/A 9.8 CRITICAL
SiteServer CMS 7.1.3 is vulnerable to SQL Injection.
CVE-2024-27746 1 Mayurik 1 Petrol Pump Management 2025-03-28 N/A 9.8 CRITICAL
SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component.
CVE-2023-49546 1 Oretnom23 1 Customer Support System 2025-03-28 N/A 8.8 HIGH
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.