Vulnerabilities (CVE)

Filtered by CWE-89
Total 16069 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-46459 1 Victor Cms Project 1 Victor Cms 2024-11-21 5.0 MEDIUM 7.5 HIGH
Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source=add_user. These vulnerabilities can be exploited through a crafted POST request via the user_name, user_firstname,user_lastname, or user_email parameters.
CVE-2021-46458 1 Victor Cms Project 1 Victor Cms 2024-11-21 5.0 MEDIUM 7.5 HIGH
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post. This vulnerability can be exploited through a crafted POST request via the post_title parameter.
CVE-2021-46451 1 Online Project Time Management System Project 1 Online Project Time Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerabilty exists in Sourcecodester Online Project Time Management System 1.0 via the pid parameter in the load_file function.
CVE-2021-46448 1 Hhg-multistore 1 Multistore 2024-11-21 7.5 HIGH 9.8 CRITICAL
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=1&cID.
CVE-2021-46446 1 Hhg-multistore 1 Multistore 2024-11-21 7.5 HIGH 9.8 CRITICAL
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_access_group_edit&aagID.
CVE-2021-46445 1 Hhg-multistore 1 Multistore 2024-11-21 7.5 HIGH 9.8 CRITICAL
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/categories.php?box_group_id.
CVE-2021-46444 1 Hhg-multistore 1 Multistore 2024-11-21 7.5 HIGH 9.8 CRITICAL
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_group_edit&agID.
CVE-2021-46436 1 Zzcms 1 Zzcms 2024-11-21 6.8 MEDIUM 7.2 HIGH
An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php.
CVE-2021-46427 1 Simple Chatbot Application Project 1 Simple Chatbot Application 2024-11-21 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.
CVE-2021-46385 1 Mingsoft 1 Mcms 2024-11-21 5.0 MEDIUM 7.5 HIGH
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive information from the database.
CVE-2021-46383 1 Mingsoft 1 Mcms 2024-11-21 5.0 MEDIUM 7.5 HIGH
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive information from the database.
CVE-2021-46377 1 Cskaza 1 Cszcms 2024-11-21 7.5 HIGH 9.8 CRITICAL
There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser
CVE-2021-46309 1 Oretnom23 1 Employee And Visitor Gate Pass Logging System 2024-11-21 10.0 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.
CVE-2021-46308 1 Online Railway Reservation System Project 1 Online Railway Reservation System 2024-11-21 10.0 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter.
CVE-2021-46307 1 Projectworlds 1 Online Examination System 2024-11-21 10.0 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.
CVE-2021-46204 1 Taogogo 1 Taocms 2024-11-21 7.5 HIGH 9.8 CRITICAL
Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. SQL injection vulnerability via taocms\include\Model\Article.php.
CVE-2021-46201 1 Online Resort Management System Project 1 Online Resort Management System 2024-11-21 10.0 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node.
CVE-2021-46198 1 Courier Management System Project 1 Courier Management System 2024-11-21 10.0 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app.
CVE-2021-46110 1 Phpgurukul 1 Online Shopping Portal 2024-11-21 7.5 HIGH 9.8 CRITICAL
Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.
CVE-2021-46089 1 Jeecg 1 Jeecg Boot 2024-11-21 10.0 HIGH 9.8 CRITICAL
In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.