Export limit exceeded: 20489 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (20489 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2017-20271 | 1 Nordmograph | 1 Streetguessr Game | 2026-08-21 | 8.2 High |
| Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter. Attackers can send GET requests to index.php with the option=com_streetguess&view=maps parameters and inject SQL code in the catid parameter to extract sensitive database information including version and database names. | ||||
| CVE-2017-20270 | 1 Raindropsinfotech | 1 Twitch Tv | 2026-08-21 | 8.2 High |
| Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username and id parameters. Attackers can send GET requests to index.php with option=com_twitchtv and view parameters containing SQL injection payloads to extract sensitive database information including credentials and configuration data. | ||||
| CVE-2017-20269 | 1 Terrywcarter | 1 Kissgallery | 2026-08-21 | 8.2 High |
| Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply malicious SQL code in the kissgallery endpoint to execute arbitrary database queries and extract sensitive information. | ||||
| CVE-2017-20268 | 2 Apereo, Zcontent | 2 Bw-calendar-engine, Zap Calendar Lite | 2026-08-21 | 8.2 High |
| Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' parameter. Attackers can send GET requests to the RSVP plugin endpoint with crafted SQL payloads to extract sensitive database information including database names and table structures. | ||||
| CVE-2026-66593 | 2 Cleantalk, Wordpress | 2 Security & Malware Scan, Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. | ||||
| CVE-2026-76990 | 1 Code-projects | 1 Simple Inventory System | 2026-08-21 | 7.3 High |
| A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2026-17227 | 1 Ibm | 1 Db2 Mirror For I | 2026-08-21 | 5.4 Medium |
| IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command. | ||||
| CVE-2026-32466 | 2 Wordpress, Wpexperts | 2 Wordpress, Gravity Forms Bookings Premium | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. | ||||
| CVE-2026-73392 | 2 Highwarden, Wordpress | 2 Super Store Finder, Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions. | ||||
| CVE-2026-74015 | 2 Merkulove, Wordpress | 2 Readabler, Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in Readabler < 2.0.18 versions. | ||||
| CVE-2026-32552 | 2 Wordpress, Yith | 2 Wordpress, Yith Woocommerce Membership Premium | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. | ||||
| CVE-2026-73183 | 2 Get Maps Marker Pro, Wordpress | 2 Maps Marker Pro, Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. | ||||
| CVE-2026-73391 | 2 Klbtheme, Wordpress | 2 Total Donations, Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | ||||
| CVE-2026-66594 | 2 Lukeseager, Wordpress | 2 Wordpress Persistent Login, Wordpress | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. | ||||
| CVE-2026-66609 | 2 Codexthemes, Wordpress | 2 Thegem (elementor), Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. | ||||
| CVE-2026-73998 | 2 Axew3, Wordpress | 2 Wp W3all Phpbb, Wordpress | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. | ||||
| CVE-2026-74013 | 2 Wordpress, Wordpress.com | 2 Wordpress, Eshipper Commerce | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. | ||||
| CVE-2026-77392 | 1 Sourcecodester | 2 Dynamic Input Field Generator Using Html, Css, And Php, Dynamic Input Field Generator Using Html Css And Php | 2026-08-21 | 6.3 Medium |
| A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. | ||||
| CVE-2025-14603 | 1 Vsdesk | 1 Vsdesk | 2026-08-20 | N/A |
| The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch. | ||||
| CVE-2026-77025 | 1 Itsourcecode | 1 Hospital Management System | 2026-08-20 | 6.3 Medium |
| A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentpending.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. | ||||