CWE-943
Improper Neutralization of Special Elements in Data Query Logic
The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.
56 vulnerabilities with CWE-943
CVE-2026-32247
HIGH
graphiti-core < 0.28.2 - Cypher Injection via SearchFilters.node_labels
CVSS 8.1
CVE-2026-31825
MEDIUM
Sylius SQL Injection via Order Direction Parameter
CVSS 5.3
CVE-2026-29793
CRITICAL
Feathersjs 5.0.0-5.0.41 - Command Injection
CVSS 9.8
CVE-2026-30941
HIGH
Parse Server <8.6.14/9.5.2-alpha.1 - NoSQL Injection
CVSS 7.5
CVE-2026-30833
MEDIUM
Rocket.Chat <8.2.0 - NoSQL Injection
CVSS 5.3
CVE-2026-28211
HIGH
NVDA Dev & Test Toolbox 2.0-8.0 - Code Injection
CVSS 7.8
CVE-2026-25591
MEDIUM
New API <0.10.8-alpha.10 - SQL Injection
CVSS 6.5
CVE-2026-25514
HIGH
FacturaScripts < 2025.81 - Authenticated SQL Injection via Autocomplete CodeModel::all() Method
CVSS 8.8
CVE-2026-25513
HIGH
FacturaScripts < 2025.81 - Authenticated SQL Injection via REST API Sort Parameter
CVSS 8.8
CVE-2026-0504
LOW
SAP Identity Management - Info Disclosure
CVSS 3.8
CVE-2025-36442
MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.3 - Denial of Service via Crafted Query with XML Columns
CVSS 6.5
CVE-2025-36366
MEDIUM
IBM Db2 11.5.0-11.5.8 - Denial of Service via JSON_Object Scalar Function
CVSS 6.5
CVE-2025-36353
MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.3 - Denial of Service via Data Query Logic
CVSS 6.2
CVE-2025-42884
MEDIUM
SAP NetWeaver Enterprise Portal - Info Disclosure
CVSS 6.5
CVE-2025-36185
MEDIUM
IBM Db2 12.1.0-12.1.2 - Denial of Service via Data Query Logic
CVSS 6.2
CVE-2025-23292
MEDIUM
NVIDIA Delegated Licensing Service - SQL Injection
CVSS 4.6
CVE-2025-33114
MEDIUM
IBM Db2 12.1.0-12.1.2 - Denial of Service via Specially Crafted Query
CVSS 5.3
CVE-2025-24787
HIGH
WhoDB < 0.45.0 - Parameter Injection in Database Connection String
CVSS 8.6
CVE-2024-4872
CRITICAL
MicroSCADA Pro/X SYS600 - Code Injection
CVSS 9.9
CVE-2024-35136
MEDIUM
IBM Db2 10.5-11.5 - Denial of Service via Specially Crafted Query
CVSS 5.3
CVE-2024-31882
MEDIUM
IBM Db2 11.1-11.5 - Authenticated Denial of Service via Crafted SQL Statement
CVSS 5.3
CVE-2024-28192
MEDIUM
your_spotify < 1.8.0 - Unauthenticated NoSQL Injection in Public Access Token Processing
CVSS 5.3
CVE-2022-36084
CRITICAL
cruddl <2.7.0-3.0.2 - Code Injection
CVSS 9.9
CVE-2021-1481
MEDIUM
Cisco SD-WAN vManage Software - SQL Injection
CVSS 4.3
CVE-2021-34712
MEDIUM
Cisco SD-WAN vManage Software - SQL Injection
CVSS 5.4
Details
Vulnerabilities
56