CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,510 vulnerabilities with CWE-89
CVE-2025-15441
MEDIUM
Form Maker < 1.15.38 - SQL Injection
CVSS 6.8
CVE-2025-13855
HIGH
IBM Storage Protect Server is affected by a vulnerability that could allow authenticated users to access administrative metadata through the JSON-RPC endpoint .
CVSS 7.6
CVE-2025-55262
HIGH
HCL Aftermarket DPC is affected by SQL Injection
CVSS 8.3
CVE-2025-41008
CRITICAL
SQL Injection in Sinturno
CVE-2025-41007
CRITICAL
SQL Injection in Cuantis
CVE-2025-62846
MEDIUM
QNAP QuRouter < 2.6.2.007 - Local Admin SQL Injection
CVSS 6.7
CVE-2025-58112
HIGH
Microsoft Dynamics 365 9.0.2.3034 - SQL Injection
CVSS 8.8
CVE-2025-67830
CRITICAL
Mura CMS < 10.1.4 - SQL Injection via beanFeed.cfc getQuery sortby
CVSS 9.8
CVE-2025-67829
CRITICAL
Mura CMS < 10.1.4 - SQL Injection via beanFeed.cfc getQuery sortDirection
CVSS 9.8
CVE-2025-69768
HIGH
chyrp < 2.5.2 - SQL Injection via Admin.php
CVSS 7.5
CVE-2025-62319
CRITICAL
Boolean-Based SQL Injection in Multiple Unica Components
CVSS 9.8
CVE-2025-52646
LOW
HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries.
CVSS 2.2
CVE-2025-52637
MEDIUM
Multiple security vulnerabilities affect HCL AION
CVSS 4.5
CVE-2025-36368
MEDIUM
IBM Sterling B2B Integrator 6.1.0.0-6.1.2.7_2 - SQL Injection
CVSS 6.5
CVE-2025-70024
CRITICAL
benkeen generatedata 4.0.14 - SQL Injection
CVSS 9.8
CVE-2025-56421
HIGH
LimeSurvey <6.15.4+250710 - SQL Injection
CVSS 7.5
CVE-2025-49784
MEDIUM
Fortinet FortiAnalyzer - SQL Injection
CVSS 6.0
CVE-2025-40639
CRITICAL
Eventobot - SQL Injection via Promo Send Parameter
CVSS 9.8
CVE-2025-14353
HIGH
WordPress ZIP Code Based Content Protection <=1.0.2 - SQL Injection
CVSS 7.5
CVE-2025-69338
CRITICAL
Riode Core <=1.6.26 - SQL Injection
CVSS 9.3
CVE-2025-66944
CRITICAL
vran-dev databaseir <=1.0.7 - SQL Injection
CVSS 9.8
CVE-2025-66678
CRITICAL
Nil Hardware Editor <1.25.11.26 - Memory Corruption
CVSS 9.8
CVE-2025-70821
CRITICAL
renren-security <5.5.0 - SQL Injection
CVSS 9.8
CVE-2025-48650
HIGH
Android - SQL Injection Leading to Local Privilege Escalation
CVSS 8.4
CVE-2025-50192
CRITICAL
Chamilo < 1.11.30 - Time-Based SQL Injection via Registration SOAP Endpoint
CVSS 9.8
Details
Vulnerabilities
19,510
Exploit Likelihood
High