Export limit exceeded: 20261 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (20261 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-4978 | 1 Umai Vision | 1 Traffic Analysis System | 2026-07-30 | 9.8 Critical |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection. This issue affects Traffic Analysis System: from 30 before 34. | ||||
| CVE-2026-15153 | 2 Wordpress, Wp Hotel Booking | 2 Wordpress, Wp Hotel Booking | 2026-07-30 | 6.8 Medium |
| The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL injection attacks. | ||||
| CVE-2026-48448 | 3 Adobe, Linux, Microsoft | 4 Campaign, Campaign Classic, Linux Kernel and 1 more | 2026-07-30 | 8.6 High |
| Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed. | ||||
| CVE-2026-13395 | 2 Bookly, Wordpress | 2 Bookly, Wordpress | 2026-07-30 | 8.6 High |
| The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database. | ||||
| CVE-2026-8339 | 1 Black Duck | 1 Coverity | 2026-07-30 | N/A |
| A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends a specially crafted payload can achieve full read access to database contents and other unauthorized commands. | ||||
| CVE-2026-16092 | 2 Labelblanc, Wordpress | 2 Improved Save Button, Wordpress | 2026-07-30 | 6.5 Medium |
| The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field via 'Save and Duplicate' Action in all versions up to, and including, 1.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-5490 | 1 Drivelock | 1 Drivelock | 2026-07-30 | N/A |
| DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. . Was ZDI-CAN-28726. | ||||
| CVE-2026-2395 | 1 Xpoda Turkiye Information Technology | 1 No Code Platform | 2026-07-30 | 9.8 Critical |
| Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform: from 4.1.3 before 4.1.4. | ||||
| CVE-2026-60137 | 1 Wordpress | 1 Wordpress | 2026-07-29 | 5.9 Medium |
| WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. | ||||
| CVE-2026-63229 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 9.1 Critical |
| A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover. | ||||
| CVE-2026-65890 | 2 Balbooa, Balbooa.com | 2 Gridbox, Gridbox Extension For Joomla | 2026-07-29 | 9.8 Critical |
| Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries. | ||||
| CVE-2026-63230 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 9.1 Critical |
| A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover, via the SCORM report endpoint. | ||||
| CVE-2026-63231 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 8.1 High |
| A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to read the entire application database and obtain valid JWT tokens for account takeover. | ||||
| CVE-2026-63232 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 9.9 Critical |
| A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. | ||||
| CVE-2026-63233 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 9.9 Critical |
| A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. | ||||
| CVE-2026-63234 | 1 Three Learning | 1 Koollab Lms | 2026-07-29 | 9.9 Critical |
| A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server. | ||||
| CVE-2026-14754 | 1 Code-projects | 2 Hotel And Tourism Reservation, Hotel And Tourism Reservation System | 2026-07-29 | 7.3 High |
| A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. Affected is an unknown function of the file /admin/add_room.php. Executing a manipulation of the argument delete_image/edit/description/number/price/rooms/type can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. | ||||
| CVE-2026-14755 | 1 Code-projects | 2 Hotel And Tourism Reservation, Hotel And Tourism Reservation System | 2026-07-29 | 7.3 High |
| A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/reservations.php of the component Reservations Management Page. The manipulation of the argument delete leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2026-14756 | 1 Code-projects | 2 Hotel And Tourism Reservation, Hotel And Tourism Reservation System | 2026-07-29 | 7.3 High |
| A vulnerability was found in code-projects Hotel and Tourism Reservation 1.0. Affected by this issue is some unknown functionality of the file /admin/add_tour.php of the component Tour Management Page. The manipulation of the argument delete_image results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. | ||||
| CVE-2026-12741 | 2 Epsiloncool, Wordpress | 2 Wp Fast Total Search – The Power Of Indexed Search, Wordpress | 2026-07-29 | 7.5 High |
| The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in all versions up to, and including, 1.80.280 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||