Fallos del tipo CWE-89

11.590 resultados
CVE-2025-3836HIGHSQL InjectionEPSS 4.6%CVE-2024-39911CRITICAL1Panel SQL injectionEPSS 4.6%CVE-2020-27660CRITICALSQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commandEPSS 4.6%CVE-2024-5467HIGHSQL InjectionEPSS 4.5%CVE-2024-32738HIGHCyberPower PowerPanel Enterprise SQL InjectionEPSS 4.5%CVE-2024-36515HIGHSQL InjectionEPSS 4.5%CVE-2024-5556HIGHSQL InjectionEPSS 4.5%CVE-2023-46748HIGHBIG-IP Configuration utility authenticated SQL injection vulnerabilityEPSS 4.5%KEVCVE-2024-47062CRITICALMultiple SQL Injections and ORM Leak in navidromeEPSS 4.5%CVE-2024-39887MEDIUMApache Superset: Improper SQL authorisation, parse not checking for specific engine functionsEPSS 4.4%CVE-2024-36516HIGHSQL InjectionEPSS 4.4%CVE-2018-5384Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injectionEPSS 4.4%CVE-2026-48134MEDIUMSQL injection issue in UserCheck Portal when DLP Software Blade is activeEPSS 4.4%CVE-2024-7854CRITICALWoo Inquiry <= 0.1 - Unauthenticated SQL InjectionEPSS 4.3%CVE-2023-31702HIGHSQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire database EPSS 4.3%CVE-2022-46071CRITICALThere is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.EPSS 4.3%CVE-2025-53475HIGHAdvantech iView SQL InjectionEPSS 4.3%CVE-2022-38627CRITICALNortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injEPSS 4.3%CVE-2022-45808CRITICALWordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL InjectionEPSS 4.3%CVE-2023-34756CRITICALbloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charsetEPSS 4.2%