Search Results (20483 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-17227 1 Ibm 1 Db2 Mirror For I 2026-08-21 5.4 Medium
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command.
CVE-2026-32466 2 Wordpress, Wpexperts 2 Wordpress, Gravity Forms Bookings Premium 2026-08-21 8.5 High
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
CVE-2026-73392 2 Highwarden, Wordpress 2 Super Store Finder, Wordpress 2026-08-21 9.3 Critical
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
CVE-2026-74015 2 Merkulove, Wordpress 2 Readabler, Wordpress 2026-08-21 9.3 Critical
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
CVE-2026-32552 2 Wordpress, Yith 2 Wordpress, Yith Woocommerce Membership Premium 2026-08-21 8.5 High
Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.
CVE-2026-73183 2 Get Maps Marker Pro, Wordpress 2 Maps Marker Pro, Wordpress 2026-08-21 9.3 Critical
Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
CVE-2026-73391 2 Klbtheme, Wordpress 2 Total Donations, Wordpress 2026-08-21 9.3 Critical
Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
CVE-2026-66594 2 Lukeseager, Wordpress 2 Wordpress Persistent Login, Wordpress 2026-08-21 8.5 High
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
CVE-2026-66609 2 Codexthemes, Wordpress 2 Thegem (elementor), Wordpress 2026-08-21 9.3 Critical
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
CVE-2026-73998 2 Axew3, Wordpress 2 Wp W3all Phpbb, Wordpress 2026-08-21 8.5 High
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
CVE-2026-74013 2 Wordpress, Wordpress.com 2 Wordpress, Eshipper Commerce 2026-08-21 8.5 High
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
CVE-2026-77392 1 Sourcecodester 2 Dynamic Input Field Generator Using Html, Css, And Php, Dynamic Input Field Generator Using Html Css And Php 2026-08-21 6.3 Medium
A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2025-14603 1 Vsdesk 1 Vsdesk 2026-08-20 N/A
The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive.  Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
CVE-2026-77025 1 Itsourcecode 1 Hospital Management System 2026-08-20 6.3 Medium
A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentpending.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2026-76783 1 Dedecms 1 Dedecms 2026-08-20 7.3 High
A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /plus/advancedsearch.php. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
CVE-2026-74011 2 Revmakx, Wordpress 2 Infinitewp Client, Wordpress 2026-08-20 7.6 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP Client: from n/a through 1.13.9.
CVE-2026-68566 2 Repute Infosystems, Wordpress 2 Bookingpress Appointment Booking Pro, Wordpress 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
CVE-2026-66649 2 E-plugins, Wordpress 2 Directory Pro, Wordpress 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
CVE-2025-15688 2 Themegoods, Wordpress 2 Capella, Wordpress 2026-08-20 9.3 Critical
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
CVE-2026-76785 1 Amirsanni 1 Mini-inventory-and-sales-management-system 2026-08-20 6.3 Medium
A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the function Transaction::getAll of the file application/models/Transaction.php. Performing a manipulation of the argument orderBy/orderFormat results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.