Search Results (20488 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2017-20270 1 Raindropsinfotech 1 Twitch Tv 2026-08-21 8.2 High
Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username and id parameters. Attackers can send GET requests to index.php with option=com_twitchtv and view parameters containing SQL injection payloads to extract sensitive database information including credentials and configuration data.
CVE-2017-20269 1 Terrywcarter 1 Kissgallery 2026-08-21 8.2 High
Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply malicious SQL code in the kissgallery endpoint to execute arbitrary database queries and extract sensitive information.
CVE-2017-20268 2 Apereo, Zcontent 2 Bw-calendar-engine, Zap Calendar Lite 2026-08-21 8.2 High
Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' parameter. Attackers can send GET requests to the RSVP plugin endpoint with crafted SQL payloads to extract sensitive database information including database names and table structures.
CVE-2026-66593 2 Cleantalk, Wordpress 2 Security & Malware Scan, Wordpress 2026-08-21 9.3 Critical
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
CVE-2026-76990 1 Code-projects 1 Simple Inventory System 2026-08-21 7.3 High
A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2026-17227 1 Ibm 1 Db2 Mirror For I 2026-08-21 5.4 Medium
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command.
CVE-2026-32466 2 Wordpress, Wpexperts 2 Wordpress, Gravity Forms Bookings Premium 2026-08-21 8.5 High
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
CVE-2026-73392 2 Highwarden, Wordpress 2 Super Store Finder, Wordpress 2026-08-21 9.3 Critical
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
CVE-2026-74015 2 Merkulove, Wordpress 2 Readabler, Wordpress 2026-08-21 9.3 Critical
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
CVE-2026-32552 2 Wordpress, Yith 2 Wordpress, Yith Woocommerce Membership Premium 2026-08-21 8.5 High
Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.
CVE-2026-73183 2 Get Maps Marker Pro, Wordpress 2 Maps Marker Pro, Wordpress 2026-08-21 9.3 Critical
Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
CVE-2026-73391 2 Klbtheme, Wordpress 2 Total Donations, Wordpress 2026-08-21 9.3 Critical
Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
CVE-2026-66594 2 Lukeseager, Wordpress 2 Wordpress Persistent Login, Wordpress 2026-08-21 8.5 High
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
CVE-2026-66609 2 Codexthemes, Wordpress 2 Thegem (elementor), Wordpress 2026-08-21 9.3 Critical
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
CVE-2026-73998 2 Axew3, Wordpress 2 Wp W3all Phpbb, Wordpress 2026-08-21 8.5 High
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
CVE-2026-74013 2 Wordpress, Wordpress.com 2 Wordpress, Eshipper Commerce 2026-08-21 8.5 High
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
CVE-2026-77392 1 Sourcecodester 2 Dynamic Input Field Generator Using Html, Css, And Php, Dynamic Input Field Generator Using Html Css And Php 2026-08-21 6.3 Medium
A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2025-14603 1 Vsdesk 1 Vsdesk 2026-08-20 N/A
The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive.  Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
CVE-2026-77025 1 Itsourcecode 1 Hospital Management System 2026-08-20 6.3 Medium
A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentpending.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2026-76783 1 Dedecms 1 Dedecms 2026-08-20 7.3 High
A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /plus/advancedsearch.php. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.