Export limit exceeded: 27709 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 20488 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (20488 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-28168 | 2 Imran Tauqeer, Wordpress | 2 Cubewp, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in CubeWP <= 1.1.30 versions. | ||||
| CVE-2026-66446 | 2 If-so Dynamic Content, Wordpress | 2 If-so Dynamic Content Personalization, Wordpress | 2026-08-14 | 9.3 Critical |
| Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. | ||||
| CVE-2024-58374 | 1 Hongjing Century | 1 E-hr | 2026-08-14 | 7.5 High |
| Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject UNION-based SQL payloads through the unsanitized codeitemid parameter into the underlying Microsoft SQL Server query to retrieve sensitive database contents including user credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30 (UTC). | ||||
| CVE-2026-73663 | 1 Freepbx | 1 Missedcall | 2026-08-14 | N/A |
| FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a monitored extension goes unanswered, corrupting the database and modifying FreePBX administrator accounts to obtain unauthorized remote access. This issue is fixed in versions 16.0.11 and 17.0.4. | ||||
| CVE-2026-72851 | 1 Budibase | 2 Budibase, Server | 2026-08-14 | 10 Critical |
| Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads that execute with builder-configured database credentials, enabling data exfiltration, modification, and persistence in connected datasources like Snowflake. | ||||
| CVE-2026-27851 | 2 Dovecot, Open-xchange | 3 Dovecot, Dovecot, Ox Dovecot Pro | 2026-08-14 | 7.4 High |
| When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known. | ||||
| CVE-2025-61848 | 1 Fortinet | 7 Fortianalyzer, Fortianalyzer-bigdata, Fortianalyzer Cloud and 4 more | 2026-08-14 | 6.5 Medium |
| An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2 through 7.6.3, FortiAnalyzer-BigData 7.6.0 through 7.6.1, FortiAnalyzer-BigData 7.4.0 through 7.4.5, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.2 through 7.6.4 may allow a privileged authenticated attacker to execute unauthorized code or commands via JSON RPC API | ||||
| CVE-2026-19351 | 1 Dresende | 1 Node-sql-query | 2026-08-13 | 7.3 High |
| A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended. | ||||
| CVE-2026-28001 | 2 Wordpress, Wpdirectorykit | 2 Wordpress, Wp Directory Kit | 2026-08-13 | 9.3 Critical |
| Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | ||||
| CVE-2026-16961 | 1 Ibm | 1 I | 2026-08-13 | 7.6 High |
| IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | ||||
| CVE-2026-61969 | 2 Webilia Inc., Wordpress | 2 Listdom, Wordpress | 2026-08-13 | 9.3 Critical |
| Unauthenticated SQL Injection in Listdom <= 5.6.0 versions. | ||||
| CVE-2026-28002 | 2 Arraytics, Wordpress | 2 Booktics, Wordpress | 2026-08-13 | 8.5 High |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22. | ||||
| CVE-2026-66458 | 2 Thimpress, Wordpress | 2 Realpress, Wordpress | 2026-08-13 | 9.3 Critical |
| Unauthenticated SQL Injection in RealPress <= 1.1.2 versions. | ||||
| CVE-2026-66478 | 2 Andymoyle, Wordpress | 2 Church Admin, Wordpress | 2026-08-13 | 9.3 Critical |
| Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. | ||||
| CVE-2026-66472 | 2 Everestthemes, Wordpress | 2 Everest Backup, Wordpress | 2026-08-13 | 9.3 Critical |
| Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. | ||||
| CVE-2026-17222 | 1 Ibm | 1 I | 2026-08-13 | 4.3 Medium |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify data in certain SQL tables due to improper neutralization of special elements used in an SQL command. | ||||
| CVE-2026-61966 | 2 Denishua, Wordpress | 2 Wpjam Basic, Wordpress | 2026-08-13 | 9.3 Critical |
| Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions. | ||||
| CVE-2026-17418 | 1 Ibm | 1 I | 2026-08-13 | 8.5 High |
| IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command. | ||||
| CVE-2026-66436 | 2 Realmag777, Wordpress | 2 Active Products Tables For Woocommerce, Wordpress | 2026-08-13 | 9.3 Critical |
| Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. | ||||
| CVE-2026-28142 | 2 Shamalli, Wordpress | 2 Web Directory Free, Wordpress | 2026-08-13 | 9.3 Critical |
| Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. | ||||