Export limit exceeded: 20027 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (20027 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-69944 | 1 Campcodes | 1 Hospital Management System | 2026-08-01 | N/A |
| kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter. | ||||
| CVE-2026-51992 | 1 Clickhouse | 1 Clickhouse | 2026-08-01 | 9.1 Critical |
| SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function. | ||||
| CVE-2025-69931 | 1 Codeastro | 1 Membership Management System | 2026-07-31 | N/A |
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1. | ||||
| CVE-2025-69938 | 2026-07-31 | 9.8 Critical | ||
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType. | ||||
| CVE-2025-65336 | 2026-07-31 | 9.8 Critical | ||
| Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. | ||||
| CVE-2025-69936 | 2026-07-31 | 9.8 Critical | ||
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. | ||||
| CVE-2025-69937 | 2026-07-31 | 9.8 Critical | ||
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id. | ||||
| CVE-2025-69941 | 2026-07-31 | 9.8 Critical | ||
| SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1. | ||||
| CVE-2025-69947 | 2026-07-31 | 9.8 Critical | ||
| SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1. | ||||
| CVE-2026-22620 | 1 Eaton | 1 Padm | 2026-07-31 | 8.6 High |
| Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device. | ||||
| CVE-2026-46593 | 1 Php Jabbers | 1 Php Poll Script | 2026-07-31 | N/A |
| A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1. | ||||
| CVE-2025-67650 | 1 Php Jabbers | 35 Appointment Scheduler, Auto Classifieds Script, Availability Booking Calendar and 32 more | 2026-07-31 | N/A |
| An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in the affected products list. | ||||
| CVE-2025-67649 | 2 Php Jabbers, Phpjabbers | 2 Car Rental Script, Car Rental Script | 2026-07-31 | N/A |
| A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1. | ||||
| CVE-2026-15258 | 2026-07-31 | 8.1 High | ||
| The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks. | ||||
| CVE-2026-14554 | 2026-07-31 | 6.5 Medium | ||
| The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with administrator privileges to perform SQL injection attacks. | ||||
| CVE-2026-58048 | 1 Webpros | 2 Cpanel, Wp Squared | 2026-07-31 | N/A |
| Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. | ||||
| CVE-2025-69933 | 1 Codeastro | 1 Membership Management System | 2026-07-31 | 9.8 Critical |
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. | ||||
| CVE-2025-69934 | 2026-07-31 | 9.8 Critical | ||
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. | ||||
| CVE-2025-69935 | 1 Codeastro | 1 Membership Management System | 2026-07-31 | 9.8 Critical |
| CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter. | ||||
| CVE-2025-69930 | 2026-07-31 | 9.8 Critical | ||
| CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. | ||||