Vulnerabilities (CVE)

Filtered by CWE-89
Total 14524 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-31768 1 Ibm 1 Infosphere Information Server 2024-11-21 7.5 HIGH 9.8 CRITICAL
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2022-31659 3 Linux, Microsoft, Vmware 6 Linux Kernel, Windows, Access Connector and 3 more 2024-11-21 N/A 7.2 HIGH
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.
CVE-2022-31489 1 Inoutscripts 1 Blockchain Altexchanger 2024-11-21 5.0 MEDIUM 7.5 HIGH
Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection.
CVE-2022-31488 1 Inoutscripts 1 Blockchain Altexchanger 2024-11-21 5.0 MEDIUM 7.5 HIGH
Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection.
CVE-2022-31487 1 Inoutscripts 2 Blockchain Altexchanger, Blockchain Fiatexchanger 2024-11-21 5.0 MEDIUM 7.5 HIGH
Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection.
CVE-2022-31415 1 Online Fire Reporting System Project 1 Online Fire Reporting System 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Online Fire Reporting System v1.0 was discovered to contain a SQL injection vulnerability via the GET parameter in /report/list.php.
CVE-2022-31384 1 Phpgurukul 1 Directory Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
CVE-2022-31383 1 Phpgurukul 1 Directory Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
CVE-2022-31382 1 Phpgurukul 1 Directory Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
CVE-2022-31367 1 Strapi 1 Strapi 2024-11-21 N/A 8.8 HIGH
Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.
CVE-2022-31361 1 Docebo 1 Docebo 2024-11-21 7.5 HIGH 9.8 CRITICAL
Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2022-31357 1 Online Ordering System Project 1 Online Ordering System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.
CVE-2022-31356 1 Online Ordering System Project 1 Online Ordering System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.
CVE-2022-31355 1 Online Ordering System Project 1 Online Ordering System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.
CVE-2022-31354 1 Online Car Wash Booking System Project 1 Online Car Wash Booking System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=get_vehicle_service.
CVE-2022-31353 1 Online Car Wash Booking System Project 1 Online Car Wash Booking System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/services/view_service.php?id=.
CVE-2022-31352 1 Online Car Wash Booking System Project 1 Online Car Wash Booking System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Online Car Wash Booking System v1.0 by oretnom23 has SQL injection in /ocwbs/admin/services/manage_service.php?id=.
CVE-2022-31351 1 Online Car Wash Booking System Project 1 Online Car Wash Booking System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Online Car Wash Booking System v1.0 by oretnom23 has SQL injection via /ocwbs/admin/services/manage_price.php?id=.
CVE-2022-31350 1 Online Car Wash Booking System Project 1 Online Car Wash Booking System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=.
CVE-2022-31348 1 Online Car Wash Booking System Project 1 Online Car Wash Booking System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/bookings/update_status.php?id=.