Vulnerabilities (CVE)

Filtered by CWE-89
Total 16118 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-30798 1 Online Ordering System Project 1 Online Ordering System 2024-11-21 6.5 MEDIUM 7.2 HIGH
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.
CVE-2022-30797 1 Online Ordering System Project 1 Online Ordering System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.
CVE-2022-30795 1 Online Ordering System Project 1 Online Ordering System 2024-11-21 6.5 MEDIUM 7.2 HIGH
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php.
CVE-2022-30794 1 Online Ordering System Project 1 Online Ordering System 2024-11-21 6.5 MEDIUM 7.2 HIGH
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php.
CVE-2022-30765 1 Janeczku 1 Calibre-web 2024-11-21 7.5 HIGH 9.8 CRITICAL
Calibre-Web before 0.6.18 allows user table SQL Injection.
CVE-2022-30619 1 Agilepoint 1 Agilepoint Nx 2024-11-21 6.5 MEDIUM 5.9 MEDIUM
Editable SQL Queries behind Base64 encoding sending from the Client-Side to The Server-Side for a particular API used in legacy Work Center module. He attack is available for any authenticated user, in any kind of rule. under the function : /AgilePointServer/Extension/FetchUsingEncodedData in the parameter: EncodedData
CVE-2022-30599 3 Fedoraproject, Moodle, Redhat 3 Fedora, Moodle, Enterprise Linux 2024-11-21 7.5 HIGH 9.8 CRITICAL
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
CVE-2022-30518 1 Chatbot Application With A Suggestion Feature Project 1 Chatbot Application With A Suggestion Feature 2024-11-21 7.5 HIGH 9.8 CRITICAL
ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /simple_chat_bot/admin/responses/view_response.php.
CVE-2022-30516 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
In Hospital-Management-System v1.0, the editid parameter in the doctor.php page is vulnerable to SQL injection attacks.
CVE-2022-30512 1 School Dormitory Management System Project 1 School Dormitory Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31.
CVE-2022-30511 1 School Dormitory Management System Project 1 School Dormitory Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4.
CVE-2022-30510 1 School Dormitory Management System Project 1 School Dormitory Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59.
CVE-2022-30500 1 Jflyfox 1 Jfinal Cms 2024-11-21 7.5 HIGH 9.8 CRITICAL
Jfinal cms 5.1.0 is vulnerable to SQL Injection.
CVE-2022-30496 1 Mv 1 Idce 2024-11-21 5.0 MEDIUM 7.5 HIGH
SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user field, connecting to a database to access enterprise's private and sensitive information.
CVE-2022-30493 1 Automotive Shop Management System Project 1 Automotive Shop Management System 2024-11-21 10.0 HIGH 9.8 CRITICAL
In oretnom23 Automotive Shop Management System v1.0, the product id parameter suffers from a blind SQL Injection Vulnerability allowing remote attackers to dump all database credential and gain admin access(privilege escalation).
CVE-2022-30490 1 Badminton Center Management System Project 1 Badminton Center Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.
CVE-2022-30481 1 Food-order-and-table-reservation-system Project 1 Food-order-and-table-reservation-system 2024-11-21 7.5 HIGH 9.8 CRITICAL
Food-order-and-table-reservation-system- 1.0 is vulnerable to SQL Injection in categorywise-menu.php via the catid parameters.
CVE-2022-30478 1 Ecommerce-project-with-php-and-mysqli-fruits-bazar Project 1 Ecommerce-project-with-php-and-mysqli-fruits-bazar 2024-11-21 7.5 HIGH 9.8 CRITICAL
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters.
CVE-2022-30469 1 Afian 1 Filerun 2024-11-21 6.5 MEDIUM 8.8 HIGH
In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman&section=get&page=grid` leads to SQL injection.
CVE-2022-30463 1 Automotive Shop Management System Project 1 Automotive Shop Management System 2024-11-21 6.5 MEDIUM 8.8 HIGH
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_product.