Export limit exceeded: 20212 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (20212 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-19787 1 Sourcecodester 1 Air Cargo Management System 2026-08-14 4.7 Medium
A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_cargo_type. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-19785 1 Rosariosis 1 Rosariosis 2026-08-14 6.3 Medium
A vulnerability has been found in francoisjacquet RosarioSIS up to 12.7.4. This vulnerability affects unknown code of the file modules/Students/includes/Medical.inc.php of the component Student Medical Module. Such manipulation of the argument table leads to sql injection. The attack may be launched remotely. Upgrading to version 12.8 is able to resolve this issue. The name of the patch is 6234a0ee0124c0667c824693ac77164f18946ddf. Upgrading the affected component is recommended.
CVE-2026-19767 1 Itsourcecode 1 Hospital Management System 2026-08-14 6.3 Medium
A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. Executing a manipulation of the argument delid can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
CVE-2026-19764 1 Raisecom 1 Communication Command And Dispatch Management Platform 2026-08-14 7.3 High
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-73408 1 Budibase 1 Budibase 2026-08-14 7.6 High
Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to create a MySQL table with a backtick and stacked statement in its name could wait for a Budibase administrator to run schema discovery, causing the second statement to execute. The fix applies quoteMySqlIdentifier before constructing the query. This issue is fixed in version 3.39.18.
CVE-2026-72853 1 Budibase 1 Budibase 2026-08-13 7.6 High
Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers with write permission on a table with a double-quote in its name can inject SQL that executes as the datasource's database user to read or modify arbitrary data.
CVE-2026-72851 1 Budibase 1 Budibase 2026-08-13 10 Critical
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads that execute with builder-configured database credentials, enabling data exfiltration, modification, and persistence in connected datasources like Snowflake.
CVE-2026-73663 2026-08-13 N/A
FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a monitored extension goes unanswered, corrupting the database and modifying FreePBX administrator accounts to obtain unauthorized remote access. This issue is fixed in versions 16.0.11 and 17.0.4.
CVE-2026-19351 1 Dresende 1 Node-sql-query 2026-08-13 7.3 High
A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended.
CVE-2026-28001 2 Wordpress, Wpdirectorykit 2 Wordpress, Wp Directory Kit 2026-08-13 9.3 Critical
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
CVE-2026-16961 1 Ibm 1 I 2026-08-13 7.6 High
IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVE-2026-61969 2 Webilia Inc., Wordpress 2 Listdom, Wordpress 2026-08-13 9.3 Critical
Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
CVE-2026-28002 2 Arraytics, Wordpress 2 Booktics, Wordpress 2026-08-13 8.5 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22.
CVE-2026-66458 2 Thimpress, Wordpress 2 Realpress, Wordpress 2026-08-13 9.3 Critical
Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
CVE-2019-25765 2026-08-13 7.5 High
ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass the application's keyword blocklist by interleaving the string 'master' within blocked SQL terms to extract sensitive database contents. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18 (UTC).
CVE-2024-58374 2026-08-13 7.5 High
Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject UNION-based SQL payloads through the unsanitized codeitemid parameter into the underlying Microsoft SQL Server query to retrieve sensitive database contents including user credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30 (UTC).
CVE-2026-66478 2 Andymoyle, Wordpress 2 Church Admin, Wordpress 2026-08-13 9.3 Critical
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
CVE-2026-66472 2 Everestthemes, Wordpress 2 Everest Backup, Wordpress 2026-08-13 9.3 Critical
Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
CVE-2026-28184 2 10web, Wordpress 2 Form Maker By 10web, Wordpress 2026-08-13 8.5 High
Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions.
CVE-2026-59109 2026-08-13 8.8 High
SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement text using string concatenation, with neither parameterised queries nor escaping. The application's own escaping helper, Dazadi.sql_txt(), is not invoked on these code paths, so a party that sends an invoice can break out of the string literal and alter the query logic. This issue affects Zalktis: before 2026.1.586 and before 2026.2.592.