Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 267/324
6.3
CVE-2022-3012

A vulnerability was found in oretnom23 Fast Food Ordering System. It has been rated as critical. Affected by this issue

6.3
CVE-2022-3013

A vulnerability classified as critical has been found in SourceCodester Simple Task Managing System. This affects an unk

6.3
CVE-2022-3122

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. Affect

6.3
CVE-2022-3470

A vulnerability was found in SourceCodester Human Resource Management System. It has been classified as critical. Affect

6.3
CVE-2022-3471

A vulnerability was found in SourceCodester Human Resource Management System. It has been declared as critical. Affected

6.3
CVE-2022-3472

A vulnerability was found in SourceCodester Human Resource Management System. It has been rated as critical. Affected by

6.3
CVE-2022-3473

A vulnerability classified as critical has been found in SourceCodester Human Resource Management System. This affects a

6.3
CVE-2022-3504

A vulnerability was found in SourceCodester Sanitization Management System and classified as critical. This issue affect

6.3
CVE-2022-3579

A vulnerability classified as critical was found in SourceCodester Cashier Queuing System 1.0. This vulnerability affect

6.3
CVE-2022-3671

A vulnerability classified as critical was found in SourceCodester eLearning System 1.0. This vulnerability affects unkn

6.3
CVE-2022-3729

A vulnerability, which was classified as critical, has been found in seccome Ehoney. This issue affects some unknown pro

6.3
CVE-2022-3732

A vulnerability was found in seccome Ehoney and classified as critical. Affected by this issue is some unknown functiona

6.3
CVE-2022-3798

A vulnerability classified as critical has been found in IBAX go-ibax. Affected is an unknown function of the file /api/

6.3
CVE-2022-3799

A vulnerability classified as critical was found in IBAX go-ibax. Affected by this vulnerability is an unknown functiona

6.3
CVE-2022-3800

A vulnerability, which was classified as critical, has been found in IBAX go-ibax. Affected by this issue is some unknow

6.3
CVE-2022-3801

A vulnerability, which was classified as critical, was found in IBAX go-ibax. This affects an unknown part of the file /

6.3
CVE-2022-3802

A vulnerability has been found in IBAX go-ibax and classified as critical. This vulnerability affects unknown code of th

6.3
CVE-2022-3947

A vulnerability classified as critical has been found in eolinker goku_lite. This affects an unknown part of the file /b

6.3
CVE-2022-3948

A vulnerability classified as critical was found in eolinker goku_lite. This vulnerability affects unknown code of the f

6.3
CVE-2022-3956

A vulnerability classified as critical has been found in tsruban HHIMS 2.1. Affected is an unknown function of the compo

6.3
CVE-2022-4012

A vulnerability classified as critical has been found in Hospital Management Center. Affected is an unknown function of

6.3
CVE-2022-4051

A vulnerability has been found in Hostel Searching Project and classified as critical. This vulnerability affects unknow

6.3
CVE-2022-4274

A vulnerability, which was classified as critical, was found in House Rental System. Affected is an unknown function of

6.3
CVE-2022-4275

A vulnerability has been found in House Rental System and classified as critical. Affected by this vulnerability is an u

6.3
CVE-2022-4277

A vulnerability was found in Shaoxing Background Management System. It has been declared as critical. This vulnerability

6.3
CVE-2022-4322

A vulnerability, which was classified as critical, was found in maku-boot up to 2.2.0. This affects the function doExecu

6.3
CVE-2022-4375

A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown funct

6.3
CVE-2022-4403

A vulnerability classified as critical was found in SourceCodester Canteen Management System. This vulnerability affects

6.3
CVE-2022-4416

A vulnerability was found in RainyGao DocSys. It has been declared as critical. This vulnerability affects the function

6.3
CVE-2021-4246

A vulnerability was found in roxlukas LMeve and classified as critical. Affected by this issue is some unknown functiona

6.3
CVE-2022-4592

A vulnerability was found in luckyshot CRMx and classified as critical. This issue affects the function get/save/delete/

6.3
CVE-2021-4261

A vulnerability classified as critical has been found in pacman-canvas up to 1.0.5. Affected is the function addHighscor

6.3
CVE-2022-43859

IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object th

6.3
CVE-2020-36631

A vulnerability was found in barronwaffles dwc_network_server_emulator. It has been declared as critical. This vulnerabi

6.3
CVE-2022-4726

A vulnerability classified as critical was found in SourceCodester Sanitization Management System 1.0. Affected by this

6.1
CVE-2022-29652

Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=save_client.

6.0
CVE-2022-29419

SQL Injection (SQLi) vulnerability in Don Crowther's 3xSocializer plugin <= 0.98.22 at WordPress possible for users with

5.9
CVE-2022-1358

The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in a

5.9
CVE-2022-23168

The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: userna

5.9
CVE-2022-23169

attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel.

5.9
CVE-2022-30619

Editable SQL Queries behind Base64 encoding sending from the Client-Side to The Server-Side for a particular API used in

5.9
CVE-2022-36839

SQL injection vulnerability via IAPService in Samsung Checkout prior to version 5.0.53.1 allows attackers to access IAP

5.8
CVE-2022-0507

Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG

5.8
CVE-2022-31082

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an

5.8
CVE-2022-35956

This Rails gem adds two methods to the ActiveRecord::Base class that allow you to update many records on a single databa

5.5
CVE-2022-0757

Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search opera

5.5
CVE-2022-34876

SQL Injection vulnerability in admin interface (/vicidial/admin.php) of VICIdial via modify_email_accounts, access_recor

5.5
CVE-2022-34878

SQL Injection vulnerability in User Stats interface (/vicidial/user_stats.php) of VICIdial via the file_download paramet

5.5
CVE-2022-2644

A vulnerability was found in SourceCodester Online Admission System and classified as critical. This issue affects some

5.5
CVE-2022-2708

A vulnerability, which was classified as critical, was found in SourceCodester Gym Management System. This affects an un

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started