Vulnerabilities (CVE)

Filtered by CWE-89
Total 14524 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-32301 1 Youdiancms 1 Youdiancms 2024-11-21 7.5 HIGH 9.8 CRITICAL
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Home/ApiAction.class.php.
CVE-2022-32300 1 Youdiancms 1 Youdiancms 2024-11-21 6.5 MEDIUM 8.8 HIGH
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the MailSendID parameter at /App/Lib/Action/Admin/MailAction.class.php.
CVE-2022-32299 1 Youdiancms 1 Youdiancms 2024-11-21 6.5 MEDIUM 8.8 HIGH
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the id parameter at /App/Lib/Action/Admin/SiteAction.class.php.
CVE-2022-32297 1 Piwigo 1 Piwigo 2024-11-21 5.1 MEDIUM 7.5 HIGH
Piwigo v12.2.0 was discovered to contain SQL injection vulnerability via the Search function.
CVE-2022-32246 1 Sap 1 Business Objects Business Intelligence Platform 2024-11-21 4.9 MEDIUM 4.6 MEDIUM
SAP Busines Objects Business Intelligence Platform (Visual Difference Application) - versions 420, 430, allows an authenticated attacker who has access to BI admin console to send crafted queries and extract data from the SQL backend. On successful exploitation, the attacker can cause limited impact on confidentiality and integrity of the application
CVE-2022-32211 1 Rocket.chat 1 Rocket.chat 2024-11-21 N/A 8.8 HIGH
A SQL injection vulnerability exists in Rocket.Chat <v3.18.6, <v4.4.4 and <v4.7.3 which can allow an attacker to retrieve a reset password token through or a 2fa secret.
CVE-2022-32101 1 Kkcms Project 1 Kkcms 2024-11-21 7.5 HIGH 9.8 CRITICAL
kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php.
CVE-2022-32095 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at orders.php.
CVE-2022-32094 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php.
CVE-2022-32093 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adminlogin.php.
CVE-2022-32056 1 Online Accreditation Management System Project 1 Online Accreditation Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Online Accreditation Management v1.0 was discovered to contain a SQL injection vulnerability via the USERNAME parameter at process.php.
CVE-2022-32055 1 Nesote 1 Inout Homestay 2024-11-21 5.0 MEDIUM 7.5 HIGH
Inout Homestay v2.2 was discovered to contain a SQL injection vulnerability via the guests parameter at /index.php?page=search/rentals.
CVE-2022-32028 1 Car Rental Management System Project 1 Car Rental Management System 2024-11-21 6.5 MEDIUM 7.2 HIGH
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=.
CVE-2022-32027 1 Car Rental Management System Project 1 Car Rental Management System 2024-11-21 6.5 MEDIUM 7.2 HIGH
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/index.php?page=manage_car&id=.
CVE-2022-32026 1 Car Rental Management System Project 1 Car Rental Management System 2024-11-21 6.5 MEDIUM 7.2 HIGH
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.php?id=.
CVE-2022-32025 1 Car Rental Management System Project 1 Car Rental Management System 2024-11-21 6.5 MEDIUM 7.2 HIGH
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id=.
CVE-2022-32024 1 Car Rental Management System Project 1 Car Rental Management System 2024-11-21 6.5 MEDIUM 7.2 HIGH
Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.
CVE-2022-32022 1 Car Rental Management System Project 1 Car Rental Management System 2024-11-21 6.5 MEDIUM 7.2 HIGH
Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?action=login.
CVE-2022-32021 1 Car Rental Management System Project 1 Car Rental Management System 2024-11-21 6.5 MEDIUM 7.2 HIGH
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_movement.php?id=.
CVE-2022-32018 1 Complete Online Job Search System Project 1 Complete Online Job Search System 2024-11-21 6.5 MEDIUM 7.2 HIGH
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=.