Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 193/324
4.7
CVE-2024-10301

A vulnerability, which was classified as critical, was found in PHPGurukul Medical Card Generation System 1.0. Affected

4.7
CVE-2024-10337

A vulnerability classified as critical has been found in SourceCodeHero Clothes Recommendation System 1.0. Affected is a

4.7
CVE-2024-10338

A vulnerability classified as critical was found in SourceCodeHero Clothes Recommendation System 1.0. Affected by this v

4.7
CVE-2024-10350

A vulnerability was found in code-projects Hospital Management System 1.0. It has been declared as critical. This vulner

4.7
CVE-2024-10354

A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. Affected by this

4.7
CVE-2024-10355

A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0.

4.7
CVE-2024-48238

WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the paren

4.7
CVE-2024-10946

A vulnerability classified as critical has been found in Guangzhou Tuchuang Computer Software Development Interlib Libra

4.7
CVE-2024-10947

A vulnerability classified as critical was found in Guangzhou Tuchuang Computer Software Development Interlib Library Cl

4.7
CVE-2024-11058

A vulnerability was found in CodeAstro Real Estate Management System up to 1.0. It has been declared as critical. This v

4.7
CVE-2024-11101

A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Aff

4.7
CVE-2024-11124

A vulnerability has been found in TimGeyssens UIOMatic 5 and classified as critical. This vulnerability affects unknown

4.7
CVE-2024-11213

A vulnerability, which was classified as critical, was found in SourceCodester Best Employee Management System 1.0. This

4.7
CVE-2024-11242

A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functiona

4.6
CVE-2024-31458

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data store

4.6
CVE-2023-3938

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZkTeco-based OEM

4.6
CVE-2024-1153

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talya Informatics

4.5
CVE-2024-22221

Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An authenticated attacker could potentially ex

4.5
CVE-2024-3060

The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL stat

4.4
CVE-2024-29174

Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection vulnerability. A loca

4.4
CVE-2024-50584

An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_i

4.3
CVE-2023-41287

A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow use

4.3
CVE-2024-24772

A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information

4.3
CVE-2023-49969

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_sup

4.3
CVE-2024-32369

SQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to ob

4.3
CVE-2024-4945

A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as problematic. A

4.3
CVE-2024-31495

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions

4.3
CVE-2024-39887

An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL

4.3
CVE-2024-45767

Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used

4.3
CVE-2024-40443

SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to

4.2
CVE-2024-33009

SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted input

4.2
CVE-2024-40637

dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to

4.2
CVE-2024-7009

Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL in

4.1
CVE-2024-9828

The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it

3.9
CVE-2024-1784

A vulnerability classified as problematic was found in Limbas 5.2.14. Affected by this vulnerability is an unknown funct

3.8
CVE-2020-26623

SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web

3.8
CVE-2020-26624

A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute ar

3.8
CVE-2020-26625

A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute ar

3.8
CVE-2024-23603

An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. Note: Software v

3.8
CVE-2024-25351

SQL Injection vulnerability in /zms/admin/changeimage.php in PHPGurukul Zoo Management System 1.0 allows attackers to ru

3.8
CVE-2024-53502

Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.

3.7
CVE-2023-50347

HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability

3.5
CVE-2023-47219

A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authentic

3.5
CVE-2024-6212

A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. Affected

2.9
CVE-2024-47483

Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in a

2.7
CVE-2022-46498

Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at h

2.7
CVE-2024-22261

SQL-Injection in Harbor allows priviledge users to leak the task IDs

2.2
CVE-2024-23843

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Genians Genian NAC

CVE-2024-0851

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Grup Arge Energy a

CVE-2024-6160

SQL Injection vulnerability in MegaBIP software allows attacker to disclose the contents of the database, obtain session

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started