Export limit exceeded: 20241 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (20241 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-10105 | 2 Agno, Agno-agi | 2 Agno, Agno | 2026-08-14 | 8.3 High |
| agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values to the delete_by_metadata() method. Attackers can exploit the unsafe f-string interpolation in clickhousedb.py to delete all rows, target specific rows, or extract information through error-based or blind SQL injection techniques. | ||||
| CVE-2024-58276 | 1 Enrollment System Project | 1 Enrollment System | 2026-08-14 | N/A |
| Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can use UNION-based injection to extract sensitive information from the users table including usernames and passwords. | ||||
| CVE-2022-50997 | 1 Weaver | 3 E-cology, E-cology 8.0, E-cology 9.0 | 2026-08-14 | 7.5 High |
| Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. Attackers can send a single crafted GET request with UNION-based injection payloads through the unsanitized id parameter to retrieve arbitrary data from the Microsoft SQL Server backend. This vulnerability is potentially remediated in software version 10.53 or 10.54. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18 (UTC). | ||||
| CVE-2026-15205 | 2026-08-14 | 8.6 High | ||
| The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to perform SQL injection and read arbitrary data from the database — including user credentials and other secrets — through both in-band (reflected) and time-based blind extraction. | ||||
| CVE-2026-19764 | 1 Raisecom | 1 Communication Command And Dispatch Management Platform | 2026-08-14 | 7.3 High |
| A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-19825 | 1 Sourcecodester | 1 Simple Client Management System | 2026-08-14 | 7.3 High |
| A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. | ||||
| CVE-2026-19767 | 1 Itsourcecode | 1 Hospital Management System | 2026-08-14 | 6.3 Medium |
| A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. Executing a manipulation of the argument delid can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. | ||||
| CVE-2026-12743 | 2 Cservit, Wordpress | 2 Affiliate-toolkit – Multi-network Affiliate & Amazon Product Display, Wordpress | 2026-08-14 | 4.9 Medium |
| The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-66430 | 2 Codepress It Solutions Llc, Wordpress | 2 Visitor Traffic Real Time Statistics Pro, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | ||||
| CVE-2026-66658 | 2 Mvp Themes, Wordpress | 2 Reviewer, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in Reviewer <= 3.14.2 versions. | ||||
| CVE-2026-73346 | 2 Mailchimp, Wordpress | 2 Mailchimp For Woocommerce, Wordpress | 2026-08-14 | 7.6 High |
| Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. | ||||
| CVE-2026-19787 | 1 Sourcecodester | 1 Air Cargo Management System | 2026-08-14 | 4.7 Medium |
| A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_cargo_type. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. | ||||
| CVE-2026-16810 | 2 Bitpressadmin, Wordpress | 2 Bit Form, Wordpress | 2026-08-14 | 6.5 Medium |
| The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'data[queryCondition]' parameter in all versions up to, and including, 3.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-28156 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in Do Lasso <= 358 versions. | ||||
| CVE-2026-28168 | 2 Imran Tauqeer, Wordpress | 2 Cubewp, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in CubeWP <= 1.1.30 versions. | ||||
| CVE-2026-66446 | 2 If-so Dynamic Content, Wordpress | 2 If-so Dynamic Content Personalization, Wordpress | 2026-08-14 | 9.3 Critical |
| Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. | ||||
| CVE-2024-58374 | 1 Hongjing Century | 1 E-hr | 2026-08-14 | 7.5 High |
| Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject UNION-based SQL payloads through the unsanitized codeitemid parameter into the underlying Microsoft SQL Server query to retrieve sensitive database contents including user credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30 (UTC). | ||||
| CVE-2026-73663 | 1 Freepbx | 1 Missedcall | 2026-08-14 | N/A |
| FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a monitored extension goes unanswered, corrupting the database and modifying FreePBX administrator accounts to obtain unauthorized remote access. This issue is fixed in versions 16.0.11 and 17.0.4. | ||||
| CVE-2026-72851 | 1 Budibase | 2 Budibase, Server | 2026-08-14 | 10 Critical |
| Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads that execute with builder-configured database credentials, enabling data exfiltration, modification, and persistence in connected datasources like Snowflake. | ||||
| CVE-2026-19785 | 2 Francoisjacquet, Rosariosis | 2 Rosariosis, Rosariosis | 2026-08-14 | 6.3 Medium |
| A vulnerability has been found in francoisjacquet RosarioSIS up to 12.7.4. This vulnerability affects unknown code of the file modules/Students/includes/Medical.inc.php of the component Student Medical Module. Such manipulation of the argument table leads to sql injection. The attack may be launched remotely. Upgrading to version 12.8 is able to resolve this issue. The name of the patch is 6234a0ee0124c0667c824693ac77164f18946ddf. Upgrading the affected component is recommended. | ||||