Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 268/324
5.5
CVE-2022-35946

GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro

5.5
CVE-2022-20351

In queryInternal of CallLogProvider.java, there is a possible access to voicemail information due to SQL injection. This

5.5
CVE-2022-3789

A vulnerability has been found in Tim Campus Confession Wall and classified as critical. Affected by this vulnerability

5.5
CVE-2022-4399

A vulnerability was found in TicklishHoneyBee nodau. It has been rated as critical. Affected by this issue is some unkno

5.5
CVE-2022-4454

A vulnerability, which was classified as critical, has been found in m0ver bible-online. Affected by this issue is the f

5.5
CVE-2022-20517

In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection

5.5
CVE-2022-20518

In query of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead t

5.5
CVE-2022-42535

In a query in MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead

5.5
CVE-2022-4566

A vulnerability, which was classified as critical, has been found in y_project RuoYi 4.7.5. This issue affects some unkn

5.5
CVE-2021-4262

A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRo

5.5
CVE-2020-36630

A vulnerability was found in FreePBX cdr 14.0. It has been classified as critical. This affects the function ajaxHandler

5.5
CVE-2021-4290

A vulnerability was found in DHBW Fallstudie. It has been declared as critical. Affected by this vulnerability is an unk

5.5
CVE-2017-20150

A vulnerability was found in challenge website. It has been rated as critical. This issue affects some unknown processin

5.5
CVE-2018-25057

A vulnerability was found in simple_php_link_shortener. It has been classified as critical. Affected is an unknown funct

5.5
CVE-2022-4860

A vulnerability was found in KBase Metrics. It has been classified as critical. This affects the function upload_user_da

5.4
CVE-2022-0842

A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a rem

5.4
CVE-2022-20786

A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service

5.4
CVE-2022-26120

Multiple improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabilities [CWE-89] i

5.4
CVE-2022-20867

A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and We

5.4
CVE-2022-33875

An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability in Fortinet FortiA

5.3
CVE-2021-42633

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to

5.3
CVE-2020-15333

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_

5.3
CVE-2022-39069

There is a SQL injection vulnerability in ZTE ZAIP-AIE. Due to lack of input verification by the server, an attacker cou

5.3
CVE-2022-45205

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.

5.0
CVE-2022-3714

A vulnerability classified as critical has been found in SourceCodester Online Medicine Ordering System 1.0. Affected is

5.0
CVE-2022-4222

A vulnerability was found in SourceCodester Canteen Management System. It has been rated as critical. This issue affects

4.9
CVE-2022-21720

GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of r

4.9
CVE-2020-19212

SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.

4.9
CVE-2022-1685

The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter bef

4.9
CVE-2022-1691

The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using

4.9
CVE-2022-2137

The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an

4.9
CVE-2022-43086

Restaurant POS System v1.0 was discovered to contain a SQL injection vulnerability via update_customer.php.

4.9
CVE-2021-37823

OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the backgroun

4.9
CVE-2022-43709

MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify

4.9
CVE-2022-45529

AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\incl

4.9
CVE-2022-45535

AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php.

4.9
CVE-2022-45536

AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php.

4.9
CVE-2022-46047

AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter.

4.7
CVE-2021-43925

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management fun

4.7
CVE-2021-43926

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management fun

4.7
CVE-2021-43927

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Managemen

4.7
CVE-2022-1838

A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unkn

4.7
CVE-2022-2017

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affe

4.7
CVE-2022-2018

A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. Affected is an unk

4.7
CVE-2017-20030

A vulnerability was found in PHPList 3.2.6. It has been classified as critical. Affected is an unknown function of the f

4.7
CVE-2022-2262

A vulnerability has been found in Online Hotel Booking System 1.0 and classified as critical. Affected by this vulnerabi

4.7
CVE-2022-2263

A vulnerability was found in Online Hotel Booking System 1.0 and classified as critical. Affected by this issue is some

4.7
CVE-2022-2700

A vulnerability classified as critical has been found in SourceCodester Gym Management System. This affects an unknown p

4.7
CVE-2022-4015

A vulnerability, which was classified as critical, was found in Sports Club Management System 119. This affects an unkno

4.7
CVE-2022-4052

A vulnerability was found in Student Attendance Management System and classified as critical. This issue affects some un

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started