Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 166/324
7.3
CVE-2024-5894

A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects u

7.3
CVE-2024-5896

A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging Sy

7.3
CVE-2024-5976

A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been classified as

7.3
CVE-2024-5983

A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been declared as critical. Affected by this vulne

7.3
CVE-2024-5984

A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. Affected by this issue is

7.3
CVE-2024-6003

A vulnerability was found in Guangdong Baolun Electronics IP Network Broadcasting Service Platform 2.0. It has been clas

7.3
CVE-2024-6042

A vulnerability was found in itsourcecode Real Estate Management System 1.0. It has been rated as critical. Affected by

7.3
CVE-2024-6043

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This af

7.3
CVE-2024-6065

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. This issue a

7.3
CVE-2024-6111

A vulnerability classified as critical has been found in itsourcecode Pool of Bethesda Online Reservation System 1.0. Th

7.3
CVE-2024-6112

A vulnerability classified as critical was found in itsourcecode Pool of Bethesda Online Reservation System 1.0. This vu

7.3
CVE-2024-6113

A vulnerability was found in itsourcecode Monbela Tourist Inn Online Reservation System 1.0. It has been rated as critic

7.3
CVE-2024-6190

A vulnerability was found in itsourcecode Farm Management System 1.0. It has been rated as critical. Affected by this is

7.3
CVE-2024-6191

A vulnerability classified as critical has been found in itsourcecode Student Management System 1.0. This affects an unk

7.3
CVE-2024-6192

A vulnerability classified as critical was found in itsourcecode Loan Management System 1.0. This vulnerability affects

7.3
CVE-2024-6193

A vulnerability, which was classified as critical, has been found in itsourcecode Vehicle Management System 1.0. This is

7.3
CVE-2024-6196

A vulnerability was found in itsourcecode Banking Management System 1.0 and classified as critical. Affected by this iss

7.3
CVE-2024-29390

Daily Expenses Management System version 1.0, developed by PHP Gurukul, contains a time-based blind SQL injection vulner

7.3
CVE-2024-6213

A vulnerability was found in SourceCodester Food Ordering Management System up to 1.0. It has been classified as critica

7.3
CVE-2024-6218

A vulnerability, which was classified as critical, has been found in itsourcecode Vehicle Management System 1.0. Affecte

7.3
CVE-2024-6253

A vulnerability was found in itsourcecode Online Food Ordering System 1.0 and classified as critical. Affected by this i

7.3
CVE-2024-6268

A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1

7.3
CVE-2024-36683

SQL injection vulnerability in the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaSho

7.3
CVE-2024-6308

A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical.

7.3
CVE-2024-6371

A vulnerability, which was classified as critical, has been found in itsourcecode Pool of Bethesda Online Reservation Sy

7.3
CVE-2024-6418

A vulnerability classified as critical has been found in SourceCodester Medicine Tracker System 1.0. This affects an unk

7.3
CVE-2024-6653

A vulnerability was found in code-projects Simple Task List 1.0. It has been declared as critical. This vulnerability af

7.3
CVE-2024-6745

A vulnerability classified as critical has been found in code-projects Simple Ticket Booking 1.0. Affected is an unknown

7.3
CVE-2024-40560

Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.

7.3
CVE-2024-6808

A vulnerability was found in itsourcecode Simple Task List 1.0. It has been classified as critical. This affects the fun

7.3
CVE-2024-6898

A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as critical. This affec

7.3
CVE-2024-6957

A vulnerability classified as critical has been found in itsourcecode University Management System 1.0. This affects an

7.3
CVE-2024-6966

A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0 and classified as critical. Affected b

7.3
CVE-2024-7101

A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue

7.3
CVE-2024-7164

A vulnerability has been found in SourceCodester School Fees Payment System 1.0 and classified as critical. This vulnera

7.3
CVE-2024-7188

A vulnerability was found in Bylancer Quicklancer 2.4. It has been rated as critical. This issue affects some unknown pr

7.3
CVE-2024-7196

A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been declared as critical. A

7.3
CVE-2024-7219

A vulnerability has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this vulnerabil

7.3
CVE-2024-7279

A vulnerability was found in SourceCodester Lot Reservation Management System 1.0. It has been declared as critical. Thi

7.3
CVE-2024-7286

A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. This

7.3
CVE-2024-7311

A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been rated as critical. This issue af

7.3
CVE-2024-7320

A vulnerability classified as critical has been found in itsourcecode Online Blood Bank Management System 1.0. This affe

7.3
CVE-2024-7366

A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been classified as critica

7.3
CVE-2024-7369

A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. This issue affec

7.3
CVE-2024-7444

A vulnerability classified as critical was found in itsourcecode Ticket Reservation System 1.0. Affected by this vulnera

7.3
CVE-2024-7449

A vulnerability, which was classified as critical, was found in itsourcecode Placement Management System 1.0. Affected i

7.3
CVE-2024-7461

A vulnerability was found in ForIP Tecnologia Administração PABX 1.x. It has been rated as critical. Affected by this is

7.3
CVE-2024-7498

A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been classified as critical. Affected i

7.3
CVE-2024-7505

A vulnerability, which was classified as critical, was found in itsourcecode Bike Delivery System 1.0. Affected is an un

7.3
CVE-2024-42005

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started