CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,654 vulnerabilities with CWE-89
CVE-2024-12745 HIGH
Amazon Redshift Python Connector 2.1.4 - SQL Injection via Metadata API
CVSS 8.0
CVE-2024-12744 HIGH
Amazon Redshift JDBC Driver 2.1.0.31 - SQL Injection via Metadata API
CVSS 8.0
CVE-2024-11726 MEDIUM
BookingPress <1.1.21 - SQL Injection
CVSS 6.5
CVE-2024-10856 MEDIUM
Booking Calendar WpDevArt <= 3.2.19 - Authenticated Time-Based Blind SQL Injection via Shortcode id Parameter
CVSS 6.5
CVE-2024-12031 MEDIUM
Advanced Floating Content <3.8.2 - SQL Injection
CVSS 6.5
CVE-2024-45387 CRITICAL
Apache Traffic Control <=8.0.1, >=8.0.0 - SQL Injection
CVSS 9.9
CVE-2024-12899 HIGH
1000 Projects Attendance Tracking Management System 1.0 - SQL Injection via course_code Parameter
CVSS 7.3
CVE-2024-12898 MEDIUM
1000 Projects Attendance Tracking Management System 1.0 - SQL Injection via faculty_course_id Parameter
CVSS 6.3
CVE-2024-12895 MEDIUM
TreasureHuntGame TreasureHunt < 2024-05-04 - SQL Injection via console_log Function
CVSS 6.3
CVE-2024-12894 MEDIUM
TreasureHuntGame TreasureHunt < 2024-05-04 - SQL Injection via usuario Parameter
CVSS 6.3
CVE-2024-12891 MEDIUM
Online Exam Mastering System 1.0 - SQL Injection via eid Parameter in account.php
CVSS 6.3
CVE-2024-12890 MEDIUM
Online Exam Mastering System 1.0 - SQL Injection via eid Parameter in update.php
CVSS 6.3
CVE-2024-12884 HIGH
Codezips E-Commerce Website 1.0 - SQL Injection via Login Email Parameter
CVSS 7.3
CVE-2024-11722 MEDIUM
Frontend Admin by DynamiApps <3.25.1 - SQL Injection
CVSS 5.9
CVE-2024-12635 MEDIUM
WP Docs <= 2.2.0 - Authenticated Time-Based SQL Injection via dir_id Parameter
CVSS 6.5
CVE-2024-55509 CRITICAL
CodeAstro Complaint Management System 1.0 - SQL Injection via delete.php id Parameter
CVSS 9.8
CVE-2024-12832 MEDIUM
Arista NG Firewall - Authenticated SQL Injection and Arbitrary File Read/Write via ReportEntry Class
CVSS 6.3
CVE-2024-12727 CRITICAL
Sophos Firewall < 21.0.1 - Unauthenticated SQL Injection in Email Protection Feature
CVSS 9.8
CVE-2024-12794 MEDIUM
Codezips E-Commerce Site 1.0 - SQL Injection via dstatus/quantity/ddate Parameters
CVSS 6.3
CVE-2024-12792 HIGH
Codezips E-Commerce Site 1.0 - SQL Injection via newadmin.php Email Parameter
CVSS 7.3
CVE-2024-12791 HIGH
Codezips E-Commerce Site 1.0 - SQL Injection via Email Parameter in signin.php
CVSS 7.3
CVE-2024-12788 HIGH
Codezips Technical Discussion Forum 1.0 - SQL Injection via signinpost.php Username Parameter
CVSS 7.3
CVE-2024-12787 HIGH
1000 Projects Attendance Tracking Management System 1.0 - SQL Injection via student_emailid Parameter
CVSS 7.3
CVE-2024-54790 HIGH
PHPGurukul Pre-School Enrollment System 1.0 - SQL Injection via visittime Parameter
CVSS 7.5
CVE-2024-12785 MEDIUM
Vehicle Management System 1.0 - SQL Injection via sendmail.php id Parameter
CVSS 6.3
Details
Vulnerabilities 19,654
Exploit Likelihood High