Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 252/324
8.8
CVE-2022-32401

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm

8.8
CVE-2022-32402

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm

8.8
CVE-2022-32403

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm

8.8
CVE-2022-32404

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm

8.8
CVE-2022-32405

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm

8.8
CVE-2022-32415

Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/?p=products/view_product&id=.

8.8
CVE-2022-34586

itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/vi

8.8
CVE-2022-34588

itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/vi

8.8
CVE-2022-2136

The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow

8.8
CVE-2022-34114

Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.

8.8
CVE-2022-31879

Online Fire Reporting System 1.0 is vulnerable to SQL Injection via the date parameter.

8.8
CVE-2022-34557

Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /

8.8
CVE-2022-34928

JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.

8.8
CVE-2022-33147

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.

8.8
CVE-2022-33148

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.

8.8
CVE-2022-33149

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.

8.8
CVE-2022-34652

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364.

8.8
CVE-2022-37333

SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0

8.8
CVE-2022-37178

An issue was discovered in 72crm 9.0. There is a SQL Injection vulnerability in View the task calendar.

8.8
CVE-2022-36698

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

8.8
CVE-2022-36699

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

8.8
CVE-2022-36700

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

8.8
CVE-2022-36701

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

8.8
CVE-2022-36703

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

8.8
CVE-2022-36720

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/mo

8.8
CVE-2022-36721

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Textbook parameter at /ad

8.8
CVE-2022-36529

Kensite CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities via the name and oldname parameters at

8.8
CVE-2022-36704

Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /libraria

8.8
CVE-2022-36686

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter

8.8
CVE-2022-36688

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter

8.8
CVE-2022-36689

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter

8.8
CVE-2022-36690

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at

8.8
CVE-2022-38118

OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user p

8.8
CVE-2022-1552

A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is ma

8.8
CVE-2022-36636

Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php

8.8
CVE-2022-38615

SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserF

8.8
CVE-2022-38616

SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /f

8.8
CVE-2022-34700

Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability

8.8
CVE-2022-39817

In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker.

8.8
CVE-2022-37207

JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters

8.8
CVE-2022-37201

JFinal CMS 5.1.0 is vulnerable to SQL Injection.

8.8
CVE-2022-38808

ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface.

8.8
CVE-2022-38617

SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at

8.8
CVE-2022-2958

The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements

8.8
CVE-2022-3141

The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By addin

8.8
CVE-2022-3142

The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL stat

8.8
CVE-2022-38618

SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id9

8.8
CVE-2022-23767

This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also i

8.8
CVE-2022-37205

JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters

8.8
CVE-2022-23692

Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote at

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started