Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 51/324
6.3
CVE-2026-14730

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this issue is some unkno

6.3
CVE-2026-14731

A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file

6.3
CVE-2026-14751

A weakness has been identified in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. The impacted eleme

6.3
CVE-2026-14766

A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unkn

6.3
CVE-2026-14767

A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecomme

6.3
CVE-2026-14773

A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /

6.3
CVE-2026-14774

A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the f

6.3
CVE-2026-14795

A vulnerability has been found in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unkn

6.3
CVE-2026-14796

A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. This affects an unknown part of the file

6.3
CVE-2026-14797

A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown

6.3
CVE-2026-14798

A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. This issue affects some unknown pro

6.3
CVE-2026-14799

A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /cus

6.3
CVE-2026-39178

A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via t

6.3
CVE-2026-39179

A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via t

6.3
CVE-2026-15477

A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /op

6.3
CVE-2026-15478

A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports

6.3
CVE-2026-15502

A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the function _rewardPurchase of the file /ipn.php o

6.3
CVE-2026-15523

A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some un

6.3
CVE-2026-15536

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file

6.3
CVE-2026-15558

A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issu

6.3
CVE-2026-15559

A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the

6.3
CVE-2026-15672

A vulnerability was determined in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the fil

6.3
CVE-2026-16009

A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file

6.3
CVE-2026-16131

A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the f

6.3
CVE-2026-16244

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerabilit

6.3
CVE-2026-16334

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code o

6.3
CVE-2026-16449

A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted elem

6.3
CVE-2026-61266

Vulnerability in the Oracle Supply Chain Globalization product of Oracle E-Business Suite (component: Copy Inventory Org

6.3
CVE-2026-61294

Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchro

6.3
CVE-2026-62527

Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Import And Export). Supp

6.3
CVE-2026-62528

Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Install). Suppor

6.3
CVE-2026-16490

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of t

6.3
CVE-2026-11391

Tanium addressed a SQL injection vulnerability in Patch.

6.3
CVE-2026-18719

A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the compo

6.3
CVE-2026-18766

A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affect

6.3
CVE-2026-18896

A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown fun

6.3
CVE-2026-19020

A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unkn

6.3
CVE-2026-19067

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown f

6.3
CVE-2026-19068

A weakness has been identified in itsourcecode Hospital Management System 1.0. The impacted element is an unknown functi

6.3
CVE-2026-19069

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This affects an unknown funct

6.3
CVE-2026-19070

A vulnerability was detected in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the fil

6.3
CVE-2026-19071

A flaw has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewa

6.3
CVE-2026-19347

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processin

6.3
CVE-2026-19354

A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an u

6.3
CVE-2026-19364

A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown functi

6.3
CVE-2026-66770

Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL

6.3
CVE-2026-19767

A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processin

6.3
CVE-2026-19785

A vulnerability has been found in francoisjacquet RosarioSIS up to 12.7.4. This vulnerability affects unknown code of th

6.3
CVE-2026-19894

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of t

6.3
CVE-2026-19917

A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started